Repository files navigation

RedotP2PNetwork

RedotP2PNetwork is a security-first Redot adaptation of DawnGroveStudios/GodotP2PNetwork. It provides a transport-neutral multiplayer service, compatibility facades for the original P2PNetwork and P2PLobby names, bounded lobby chat, replicated state, explicit entity replication, capability checks, and optional IP or identity bans.

This repository is an alpha implementation for Redot 26.2. It is suitable for development and local integration testing, not a claim that every planned transport or production deployment profile is certified.

Current capability status

SurfaceStatusEvidence and limits
Secure protocol coreImplementedStrict binary envelope, registered message allowlist, sender direction, channel/delivery checks, replay rejection, per-peer rate limits, bounded work, and violation disconnects are unit tested.
ENetImplementedNative two-process core and facade fixtures pass on Windows with Redot 26.2.
WebSocketImplementedNative two-process core and facade fixtures pass on loopback. Plain ws:// is loopback-only and opt-in; production requires TLS/WSS and deployment qualification.
SteamProvider-gated alphaAdapter and dynamic dominicbytes/redot-steam provider compile without making RedotSteam mandatory. A live private-App-ID authentication fixture is not yet certified.
WebRTCProvider-gated alphaAuthority-star adapter and replaceable signaling, ICE, and peer-factory contracts are present. The installed Redot build has no usable default WebRTC backend, so a real provider fixture is still required.
Lobby discovery directoryNot implementedDirect/current-lobby behavior works. Public discovery and the optional self-hostable directory remain later milestones.
Persistent moderationNot implementedIn-memory exact address, identity, and guarded CIDR bans are implemented. Persistence and report storage require future provider contracts.

See transport status, the upstream compatibility matrix, and the threat model before adopting the alpha.

Install

  1. Copy addons/redot_p2p_network into the target Redot project's addons/ directory.
  2. Enable RedotP2PNetwork in Project Settings > Plugins.
  3. Confirm the plugin registered the P2PNetwork and P2PLobby autoloads. It will not overwrite autoloads that already use those names.

The development project in this repository opens a keyboard-operable quickstart scene with ENet and explicit loopback WebSocket controls.

Minimal ENet session

# Listen host.varerror: Error=P2PNetwork.host_enet(7777, 16, "*")
# Client.varerror: Error=P2PNetwork.join_enet("127.0.0.1", 7777)

Register messages explicitly

Remote peers cannot select a NodePath, method, signal, property, or scene. A game registers every accepted message and its limits locally:

func_ready() ->void:
P2PNetwork.register_message(
"game.chat",
_on_chat,
512, # payload bytestrue, # accepted from clients by the authorityfalse, # not accepted from the authority by clients1,
RedotP2PTransportAdapter.Delivery.RELIABLE,
2.0, # messages per second per peer4, # burst"chat.send"
)
func_on_chat(peer_id: int, payload: PackedByteArray) ->void:
# Decode and validate the game's own bounded payload here.pass

The authority assigns roles or scoped capabilities through P2PNetwork.access_control. Client input still needs game-specific semantic validation; this addon supplies the trust boundary, not game rules.

Secure defaults

  • Incoming message types are deny-by-default.
  • Raw Variant/object deserialization is not used on network frames.
  • Client messages cannot invoke arbitrary methods, signals, properties, or scene creation.
  • The listen host or dedicated server is authoritative.
  • Frames, payloads, channels, packets per tick, bytes per tick, chat, lobby state, entity state, and intent rates are bounded.
  • Replayed or reordered sequence numbers are rejected per peer/channel.
  • Plain WebSocket is rejected except for explicitly enabled loopback development.
  • Moderation enforcement and CIDR banning are optional and off by default.
  • Address bans use only the authority-observed transport address. Relay-hidden transports return no address rather than trusting a client claim.
  • Exact address bans are the normal mode. CIDR requires explicit enablement; ranges broader than IPv4 /24 or IPv6 /64 require high-risk confirmation, and /16 or /48 are absolute limits.

JSON-backed compatibility state accepts only bounded JSON-safe values. Store network IDs and revision-like integers as canonical decimal strings when exact integer fidelity matters, because JSON numbers are decoded as floating-point values by the engine.

Upstream compatibility

The familiar classes and facade names remain where they can be made safe. Legacy arbitrary rpc_method, remote signal emission, arbitrary node removal, and free-form node synchronization are rejected while online with the stable status UNSAFE_LEGACY_API_REJECTED. Use registered messages, P2PNode, or the replication services instead. Wire compatibility with the upstream addon is not provided.

Development and tests

Set REDOT_BIN to the Redot 26.2 console executable, then run:

./tools/run_tests.ps1 -RedotBin $env:REDOT_BIN

Build a reviewable addon archive without publishing it:

./tools/package_addon.ps1

Generated test artifacts and packages are ignored by Git. See CONTRIBUTING.md and SECURITY.md.

Fork provenance

  • Upstream: DawnGroveStudios/GodotP2PNetwork
  • Upstream baseline: 54256e434c4735f38bbfbaae7d01fb6a47bc0c8b
  • Intended downstream: dominicbytes/RedotP2PNetwork
  • License: MIT; see LICENSE and NOTICE.md

The repository retains upstream Git ancestry. The addon path and protocol were changed intentionally for Redot and for safer defaults.

Notes

I vibe coded this in GPT Sol 5.6. Use at your own risk. Actual programmers are welcome to submit PR's and feedback.

About Dominic Bytes

Greetings! I am Dominic Bytes, the synth walker. I hail from the distant future. Where brains occupy robot bodies, time travel is a trip to the corner store, and the neon glow of our attire is powered by the light of our souls. Join me on a 1.21 gigawatt powered journey of chill vibes with gaming, anime, movies, and more!

About

Secure, transport-agnostic P2P networking plugin for Redot 26.2 (alpha).

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

RedotP2PNetwork

RedotP2PNetwork is a security-first Redot adaptation of DawnGroveStudios/GodotP2PNetwork. It provides a transport-neutral multiplayer service, compatibility facades for the original P2PNetwork and P2PLobby names, bounded lobby chat, replicated state, explicit entity replication, capability checks, and optional IP or identity bans.

This repository is an alpha implementation for Redot 26.2. It is suitable for development and local integration testing, not a claim that every planned transport or production deployment profile is certified.

Current capability status

SurfaceStatusEvidence and limits
Secure protocol coreImplementedStrict binary envelope, registered message allowlist, sender direction, channel/delivery checks, replay rejection, per-peer rate limits, bounded work, and violation disconnects are unit tested.
ENetImplementedNative two-process core and facade fixtures pass on Windows with Redot 26.2.
WebSocketImplementedNative two-process core and facade fixtures pass on loopback. Plain ws:// is loopback-only and opt-in; production requires TLS/WSS and deployment qualification.
SteamProvider-gated alphaAdapter and dynamic dominicbytes/redot-steam provider compile without making RedotSteam mandatory. A live private-App-ID authentication fixture is not yet certified.
WebRTCProvider-gated alphaAuthority-star adapter and replaceable signaling, ICE, and peer-factory contracts are present. The installed Redot build has no usable default WebRTC backend, so a real provider fixture is still required.
Lobby discovery directoryNot implementedDirect/current-lobby behavior works. Public discovery and the optional self-hostable directory remain later milestones.
Persistent moderationNot implementedIn-memory exact address, identity, and guarded CIDR bans are implemented. Persistence and report storage require future provider contracts.

See transport status, the upstream compatibility matrix, and the threat model before adopting the alpha.

Install

  1. Copy addons/redot_p2p_network into the target Redot project's addons/ directory.
  2. Enable RedotP2PNetwork in Project Settings > Plugins.
  3. Confirm the plugin registered the P2PNetwork and P2PLobby autoloads. It will not overwrite autoloads that already use those names.

The development project in this repository opens a keyboard-operable quickstart scene with ENet and explicit loopback WebSocket controls.

Minimal ENet session

# Listen host.varerror: Error=P2PNetwork.host_enet(7777, 16, "*")
# Client.varerror: Error=P2PNetwork.join_enet("127.0.0.1", 7777)

Register messages explicitly

Remote peers cannot select a NodePath, method, signal, property, or scene. A game registers every accepted message and its limits locally:

func_ready() ->void:
P2PNetwork.register_message(
"game.chat",
_on_chat,
512, # payload bytestrue, # accepted from clients by the authorityfalse, # not accepted from the authority by clients1,
RedotP2PTransportAdapter.Delivery.RELIABLE,
2.0, # messages per second per peer4, # burst"chat.send"
)
func_on_chat(peer_id: int, payload: PackedByteArray) ->void:
# Decode and validate the game's own bounded payload here.pass

The authority assigns roles or scoped capabilities through P2PNetwork.access_control. Client input still needs game-specific semantic validation; this addon supplies the trust boundary, not game rules.

Secure defaults

  • Incoming message types are deny-by-default.
  • Raw Variant/object deserialization is not used on network frames.
  • Client messages cannot invoke arbitrary methods, signals, properties, or scene creation.
  • The listen host or dedicated server is authoritative.
  • Frames, payloads, channels, packets per tick, bytes per tick, chat, lobby state, entity state, and intent rates are bounded.
  • Replayed or reordered sequence numbers are rejected per peer/channel.
  • Plain WebSocket is rejected except for explicitly enabled loopback development.
  • Moderation enforcement and CIDR banning are optional and off by default.
  • Address bans use only the authority-observed transport address. Relay-hidden transports return no address rather than trusting a client claim.
  • Exact address bans are the normal mode. CIDR requires explicit enablement; ranges broader than IPv4 /24 or IPv6 /64 require high-risk confirmation, and /16 or /48 are absolute limits.

JSON-backed compatibility state accepts only bounded JSON-safe values. Store network IDs and revision-like integers as canonical decimal strings when exact integer fidelity matters, because JSON numbers are decoded as floating-point values by the engine.

Upstream compatibility

The familiar classes and facade names remain where they can be made safe. Legacy arbitrary rpc_method, remote signal emission, arbitrary node removal, and free-form node synchronization are rejected while online with the stable status UNSAFE_LEGACY_API_REJECTED. Use registered messages, P2PNode, or the replication services instead. Wire compatibility with the upstream addon is not provided.

Development and tests

Set REDOT_BIN to the Redot 26.2 console executable, then run:

./tools/run_tests.ps1 -RedotBin $env:REDOT_BIN

Build a reviewable addon archive without publishing it:

./tools/package_addon.ps1

Generated test artifacts and packages are ignored by Git. See CONTRIBUTING.md and SECURITY.md.

Fork provenance

  • Upstream: DawnGroveStudios/GodotP2PNetwork
  • Upstream baseline: 54256e434c4735f38bbfbaae7d01fb6a47bc0c8b
  • Intended downstream: dominicbytes/RedotP2PNetwork
  • License: MIT; see LICENSE and NOTICE.md

The repository retains upstream Git ancestry. The addon path and protocol were changed intentionally for Redot and for safer defaults.

Notes

I vibe coded this in GPT Sol 5.6. Use at your own risk. Actual programmers are welcome to submit PR's and feedback.

About Dominic Bytes

Greetings! I am Dominic Bytes, the synth walker. I hail from the distant future. Where brains occupy robot bodies, time travel is a trip to the corner store, and the neon glow of our attire is powered by the light of our souls. Join me on a 1.21 gigawatt powered journey of chill vibes with gaming, anime, movies, and more!

About

Secure, transport-agnostic P2P networking plugin for Redot 26.2 (alpha).

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

RedotP2PNetwork

RedotP2PNetwork is a security-first Redot adaptation of DawnGroveStudios/GodotP2PNetwork. It provides a transport-neutral multiplayer service, compatibility facades for the original P2PNetwork and P2PLobby names, bounded lobby chat, replicated state, explicit entity replication, capability checks, and optional IP or identity bans.

This repository is an alpha implementation for Redot 26.2. It is suitable for development and local integration testing, not a claim that every planned transport or production deployment profile is certified.

Current capability status

SurfaceStatusEvidence and limits
Secure protocol coreImplementedStrict binary envelope, registered message allowlist, sender direction, channel/delivery checks, replay rejection, per-peer rate limits, bounded work, and violation disconnects are unit tested.
ENetImplementedNative two-process core and facade fixtures pass on Windows with Redot 26.2.
WebSocketImplementedNative two-process core and facade fixtures pass on loopback. Plain ws:// is loopback-only and opt-in; production requires TLS/WSS and deployment qualification.
SteamProvider-gated alphaAdapter and dynamic dominicbytes/redot-steam provider compile without making RedotSteam mandatory. A live private-App-ID authentication fixture is not yet certified.
WebRTCProvider-gated alphaAuthority-star adapter and replaceable signaling, ICE, and peer-factory contracts are present. The installed Redot build has no usable default WebRTC backend, so a real provider fixture is still required.
Lobby discovery directoryNot implementedDirect/current-lobby behavior works. Public discovery and the optional self-hostable directory remain later milestones.
Persistent moderationNot implementedIn-memory exact address, identity, and guarded CIDR bans are implemented. Persistence and report storage require future provider contracts.

See transport status, the upstream compatibility matrix, and the threat model before adopting the alpha.

Install

  1. Copy addons/redot_p2p_network into the target Redot project's addons/ directory.
  2. Enable RedotP2PNetwork in Project Settings > Plugins.
  3. Confirm the plugin registered the P2PNetwork and P2PLobby autoloads. It will not overwrite autoloads that already use those names.

The development project in this repository opens a keyboard-operable quickstart scene with ENet and explicit loopback WebSocket controls.

Minimal ENet session

# Listen host.varerror: Error=P2PNetwork.host_enet(7777, 16, "*")
# Client.varerror: Error=P2PNetwork.join_enet("127.0.0.1", 7777)

Register messages explicitly

Remote peers cannot select a NodePath, method, signal, property, or scene. A game registers every accepted message and its limits locally:

func_ready() ->void:
P2PNetwork.register_message(
"game.chat",
_on_chat,
512, # payload bytestrue, # accepted from clients by the authorityfalse, # not accepted from the authority by clients1,
RedotP2PTransportAdapter.Delivery.RELIABLE,
2.0, # messages per second per peer4, # burst"chat.send"
)
func_on_chat(peer_id: int, payload: PackedByteArray) ->void:
# Decode and validate the game's own bounded payload here.pass

The authority assigns roles or scoped capabilities through P2PNetwork.access_control. Client input still needs game-specific semantic validation; this addon supplies the trust boundary, not game rules.

Secure defaults

  • Incoming message types are deny-by-default.
  • Raw Variant/object deserialization is not used on network frames.
  • Client messages cannot invoke arbitrary methods, signals, properties, or scene creation.
  • The listen host or dedicated server is authoritative.
  • Frames, payloads, channels, packets per tick, bytes per tick, chat, lobby state, entity state, and intent rates are bounded.
  • Replayed or reordered sequence numbers are rejected per peer/channel.
  • Plain WebSocket is rejected except for explicitly enabled loopback development.
  • Moderation enforcement and CIDR banning are optional and off by default.
  • Address bans use only the authority-observed transport address. Relay-hidden transports return no address rather than trusting a client claim.
  • Exact address bans are the normal mode. CIDR requires explicit enablement; ranges broader than IPv4 /24 or IPv6 /64 require high-risk confirmation, and /16 or /48 are absolute limits.

JSON-backed compatibility state accepts only bounded JSON-safe values. Store network IDs and revision-like integers as canonical decimal strings when exact integer fidelity matters, because JSON numbers are decoded as floating-point values by the engine.

Upstream compatibility

The familiar classes and facade names remain where they can be made safe. Legacy arbitrary rpc_method, remote signal emission, arbitrary node removal, and free-form node synchronization are rejected while online with the stable status UNSAFE_LEGACY_API_REJECTED. Use registered messages, P2PNode, or the replication services instead. Wire compatibility with the upstream addon is not provided.

Development and tests

Set REDOT_BIN to the Redot 26.2 console executable, then run:

./tools/run_tests.ps1 -RedotBin $env:REDOT_BIN

Build a reviewable addon archive without publishing it:

./tools/package_addon.ps1

Generated test artifacts and packages are ignored by Git. See CONTRIBUTING.md and SECURITY.md.

Fork provenance

  • Upstream: DawnGroveStudios/GodotP2PNetwork
  • Upstream baseline: 54256e434c4735f38bbfbaae7d01fb6a47bc0c8b
  • Intended downstream: dominicbytes/RedotP2PNetwork
  • License: MIT; see LICENSE and NOTICE.md

The repository retains upstream Git ancestry. The addon path and protocol were changed intentionally for Redot and for safer defaults.

Notes

I vibe coded this in GPT Sol 5.6. Use at your own risk. Actual programmers are welcome to submit PR's and feedback.

About Dominic Bytes

Greetings! I am Dominic Bytes, the synth walker. I hail from the distant future. Where brains occupy robot bodies, time travel is a trip to the corner store, and the neon glow of our attire is powered by the light of our souls. Join me on a 1.21 gigawatt powered journey of chill vibes with gaming, anime, movies, and more!

About

Secure, transport-agnostic P2P networking plugin for Redot 26.2 (alpha).

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

RedotP2PNetwork

RedotP2PNetwork is a security-first Redot adaptation of DawnGroveStudios/GodotP2PNetwork. It provides a transport-neutral multiplayer service, compatibility facades for the original P2PNetwork and P2PLobby names, bounded lobby chat, replicated state, explicit entity replication, capability checks, and optional IP or identity bans.

This repository is an alpha implementation for Redot 26.2. It is suitable for development and local integration testing, not a claim that every planned transport or production deployment profile is certified.

Current capability status

SurfaceStatusEvidence and limits
Secure protocol coreImplementedStrict binary envelope, registered message allowlist, sender direction, channel/delivery checks, replay rejection, per-peer rate limits, bounded work, and violation disconnects are unit tested.
ENetImplementedNative two-process core and facade fixtures pass on Windows with Redot 26.2.
WebSocketImplementedNative two-process core and facade fixtures pass on loopback. Plain ws:// is loopback-only and opt-in; production requires TLS/WSS and deployment qualification.
SteamProvider-gated alphaAdapter and dynamic dominicbytes/redot-steam provider compile without making RedotSteam mandatory. A live private-App-ID authentication fixture is not yet certified.
WebRTCProvider-gated alphaAuthority-star adapter and replaceable signaling, ICE, and peer-factory contracts are present. The installed Redot build has no usable default WebRTC backend, so a real provider fixture is still required.
Lobby discovery directoryNot implementedDirect/current-lobby behavior works. Public discovery and the optional self-hostable directory remain later milestones.
Persistent moderationNot implementedIn-memory exact address, identity, and guarded CIDR bans are implemented. Persistence and report storage require future provider contracts.

See transport status, the upstream compatibility matrix, and the threat model before adopting the alpha.

Install

  1. Copy addons/redot_p2p_network into the target Redot project's addons/ directory.
  2. Enable RedotP2PNetwork in Project Settings > Plugins.
  3. Confirm the plugin registered the P2PNetwork and P2PLobby autoloads. It will not overwrite autoloads that already use those names.

The development project in this repository opens a keyboard-operable quickstart scene with ENet and explicit loopback WebSocket controls.

Minimal ENet session

# Listen host.varerror: Error=P2PNetwork.host_enet(7777, 16, "*")
# Client.varerror: Error=P2PNetwork.join_enet("127.0.0.1", 7777)

Register messages explicitly

Remote peers cannot select a NodePath, method, signal, property, or scene. A game registers every accepted message and its limits locally:

func_ready() ->void:
P2PNetwork.register_message(
"game.chat",
_on_chat,
512, # payload bytestrue, # accepted from clients by the authorityfalse, # not accepted from the authority by clients1,
RedotP2PTransportAdapter.Delivery.RELIABLE,
2.0, # messages per second per peer4, # burst"chat.send"
)
func_on_chat(peer_id: int, payload: PackedByteArray) ->void:
# Decode and validate the game's own bounded payload here.pass

The authority assigns roles or scoped capabilities through P2PNetwork.access_control. Client input still needs game-specific semantic validation; this addon supplies the trust boundary, not game rules.

Secure defaults

  • Incoming message types are deny-by-default.
  • Raw Variant/object deserialization is not used on network frames.
  • Client messages cannot invoke arbitrary methods, signals, properties, or scene creation.
  • The listen host or dedicated server is authoritative.
  • Frames, payloads, channels, packets per tick, bytes per tick, chat, lobby state, entity state, and intent rates are bounded.
  • Replayed or reordered sequence numbers are rejected per peer/channel.
  • Plain WebSocket is rejected except for explicitly enabled loopback development.
  • Moderation enforcement and CIDR banning are optional and off by default.
  • Address bans use only the authority-observed transport address. Relay-hidden transports return no address rather than trusting a client claim.
  • Exact address bans are the normal mode. CIDR requires explicit enablement; ranges broader than IPv4 /24 or IPv6 /64 require high-risk confirmation, and /16 or /48 are absolute limits.

JSON-backed compatibility state accepts only bounded JSON-safe values. Store network IDs and revision-like integers as canonical decimal strings when exact integer fidelity matters, because JSON numbers are decoded as floating-point values by the engine.

Upstream compatibility

The familiar classes and facade names remain where they can be made safe. Legacy arbitrary rpc_method, remote signal emission, arbitrary node removal, and free-form node synchronization are rejected while online with the stable status UNSAFE_LEGACY_API_REJECTED. Use registered messages, P2PNode, or the replication services instead. Wire compatibility with the upstream addon is not provided.

Development and tests

Set REDOT_BIN to the Redot 26.2 console executable, then run:

./tools/run_tests.ps1 -RedotBin $env:REDOT_BIN

Build a reviewable addon archive without publishing it:

./tools/package_addon.ps1

Generated test artifacts and packages are ignored by Git. See CONTRIBUTING.md and SECURITY.md.

Fork provenance

  • Upstream: DawnGroveStudios/GodotP2PNetwork
  • Upstream baseline: 54256e434c4735f38bbfbaae7d01fb6a47bc0c8b
  • Intended downstream: dominicbytes/RedotP2PNetwork
  • License: MIT; see LICENSE and NOTICE.md

The repository retains upstream Git ancestry. The addon path and protocol were changed intentionally for Redot and for safer defaults.

Notes

I vibe coded this in GPT Sol 5.6. Use at your own risk. Actual programmers are welcome to submit PR's and feedback.

About Dominic Bytes

Greetings! I am Dominic Bytes, the synth walker. I hail from the distant future. Where brains occupy robot bodies, time travel is a trip to the corner store, and the neon glow of our attire is powered by the light of our souls. Join me on a 1.21 gigawatt powered journey of chill vibes with gaming, anime, movies, and more!

About

Secure, transport-agnostic P2P networking plugin for Redot 26.2 (alpha).

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

RedotP2PNetwork

RedotP2PNetwork is a security-first Redot adaptation of DawnGroveStudios/GodotP2PNetwork. It provides a transport-neutral multiplayer service, compatibility facades for the original P2PNetwork and P2PLobby names, bounded lobby chat, replicated state, explicit entity replication, capability checks, and optional IP or identity bans.

This repository is an alpha implementation for Redot 26.2. It is suitable for development and local integration testing, not a claim that every planned transport or production deployment profile is certified.

Current capability status

SurfaceStatusEvidence and limits
Secure protocol coreImplementedStrict binary envelope, registered message allowlist, sender direction, channel/delivery checks, replay rejection, per-peer rate limits, bounded work, and violation disconnects are unit tested.
ENetImplementedNative two-process core and facade fixtures pass on Windows with Redot 26.2.
WebSocketImplementedNative two-process core and facade fixtures pass on loopback. Plain ws:// is loopback-only and opt-in; production requires TLS/WSS and deployment qualification.
SteamProvider-gated alphaAdapter and dynamic dominicbytes/redot-steam provider compile without making RedotSteam mandatory. A live private-App-ID authentication fixture is not yet certified.
WebRTCProvider-gated alphaAuthority-star adapter and replaceable signaling, ICE, and peer-factory contracts are present. The installed Redot build has no usable default WebRTC backend, so a real provider fixture is still required.
Lobby discovery directoryNot implementedDirect/current-lobby behavior works. Public discovery and the optional self-hostable directory remain later milestones.
Persistent moderationNot implementedIn-memory exact address, identity, and guarded CIDR bans are implemented. Persistence and report storage require future provider contracts.

See transport status, the upstream compatibility matrix, and the threat model before adopting the alpha.

Install

  1. Copy addons/redot_p2p_network into the target Redot project's addons/ directory.
  2. Enable RedotP2PNetwork in Project Settings > Plugins.
  3. Confirm the plugin registered the P2PNetwork and P2PLobby autoloads. It will not overwrite autoloads that already use those names.

The development project in this repository opens a keyboard-operable quickstart scene with ENet and explicit loopback WebSocket controls.

Minimal ENet session

# Listen host.varerror: Error=P2PNetwork.host_enet(7777, 16, "*")
# Client.varerror: Error=P2PNetwork.join_enet("127.0.0.1", 7777)

Register messages explicitly

Remote peers cannot select a NodePath, method, signal, property, or scene. A game registers every accepted message and its limits locally:

func_ready() ->void:
P2PNetwork.register_message(
"game.chat",
_on_chat,
512, # payload bytestrue, # accepted from clients by the authorityfalse, # not accepted from the authority by clients1,
RedotP2PTransportAdapter.Delivery.RELIABLE,
2.0, # messages per second per peer4, # burst"chat.send"
)
func_on_chat(peer_id: int, payload: PackedByteArray) ->void:
# Decode and validate the game's own bounded payload here.pass

The authority assigns roles or scoped capabilities through P2PNetwork.access_control. Client input still needs game-specific semantic validation; this addon supplies the trust boundary, not game rules.

Secure defaults

  • Incoming message types are deny-by-default.
  • Raw Variant/object deserialization is not used on network frames.
  • Client messages cannot invoke arbitrary methods, signals, properties, or scene creation.
  • The listen host or dedicated server is authoritative.
  • Frames, payloads, channels, packets per tick, bytes per tick, chat, lobby state, entity state, and intent rates are bounded.
  • Replayed or reordered sequence numbers are rejected per peer/channel.
  • Plain WebSocket is rejected except for explicitly enabled loopback development.
  • Moderation enforcement and CIDR banning are optional and off by default.
  • Address bans use only the authority-observed transport address. Relay-hidden transports return no address rather than trusting a client claim.
  • Exact address bans are the normal mode. CIDR requires explicit enablement; ranges broader than IPv4 /24 or IPv6 /64 require high-risk confirmation, and /16 or /48 are absolute limits.

JSON-backed compatibility state accepts only bounded JSON-safe values. Store network IDs and revision-like integers as canonical decimal strings when exact integer fidelity matters, because JSON numbers are decoded as floating-point values by the engine.

Upstream compatibility

The familiar classes and facade names remain where they can be made safe. Legacy arbitrary rpc_method, remote signal emission, arbitrary node removal, and free-form node synchronization are rejected while online with the stable status UNSAFE_LEGACY_API_REJECTED. Use registered messages, P2PNode, or the replication services instead. Wire compatibility with the upstream addon is not provided.

Development and tests

Set REDOT_BIN to the Redot 26.2 console executable, then run:

./tools/run_tests.ps1 -RedotBin $env:REDOT_BIN

Build a reviewable addon archive without publishing it:

./tools/package_addon.ps1

Generated test artifacts and packages are ignored by Git. See CONTRIBUTING.md and SECURITY.md.

Fork provenance

  • Upstream: DawnGroveStudios/GodotP2PNetwork
  • Upstream baseline: 54256e434c4735f38bbfbaae7d01fb6a47bc0c8b
  • Intended downstream: dominicbytes/RedotP2PNetwork
  • License: MIT; see LICENSE and NOTICE.md

The repository retains upstream Git ancestry. The addon path and protocol were changed intentionally for Redot and for safer defaults.

Notes

I vibe coded this in GPT Sol 5.6. Use at your own risk. Actual programmers are welcome to submit PR's and feedback.

About Dominic Bytes

Greetings! I am Dominic Bytes, the synth walker. I hail from the distant future. Where brains occupy robot bodies, time travel is a trip to the corner store, and the neon glow of our attire is powered by the light of our souls. Join me on a 1.21 gigawatt powered journey of chill vibes with gaming, anime, movies, and more!

About

Secure, transport-agnostic P2P networking plugin for Redot 26.2 (alpha).

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

RedotP2PNetwork

RedotP2PNetwork is a security-first Redot adaptation of DawnGroveStudios/GodotP2PNetwork. It provides a transport-neutral multiplayer service, compatibility facades for the original P2PNetwork and P2PLobby names, bounded lobby chat, replicated state, explicit entity replication, capability checks, and optional IP or identity bans.

This repository is an alpha implementation for Redot 26.2. It is suitable for development and local integration testing, not a claim that every planned transport or production deployment profile is certified.

Current capability status

SurfaceStatusEvidence and limits
Secure protocol coreImplementedStrict binary envelope, registered message allowlist, sender direction, channel/delivery checks, replay rejection, per-peer rate limits, bounded work, and violation disconnects are unit tested.
ENetImplementedNative two-process core and facade fixtures pass on Windows with Redot 26.2.
WebSocketImplementedNative two-process core and facade fixtures pass on loopback. Plain ws:// is loopback-only and opt-in; production requires TLS/WSS and deployment qualification.
SteamProvider-gated alphaAdapter and dynamic dominicbytes/redot-steam provider compile without making RedotSteam mandatory. A live private-App-ID authentication fixture is not yet certified.
WebRTCProvider-gated alphaAuthority-star adapter and replaceable signaling, ICE, and peer-factory contracts are present. The installed Redot build has no usable default WebRTC backend, so a real provider fixture is still required.
Lobby discovery directoryNot implementedDirect/current-lobby behavior works. Public discovery and the optional self-hostable directory remain later milestones.
Persistent moderationNot implementedIn-memory exact address, identity, and guarded CIDR bans are implemented. Persistence and report storage require future provider contracts.

See transport status, the upstream compatibility matrix, and the threat model before adopting the alpha.

Install

  1. Copy addons/redot_p2p_network into the target Redot project's addons/ directory.
  2. Enable RedotP2PNetwork in Project Settings > Plugins.
  3. Confirm the plugin registered the P2PNetwork and P2PLobby autoloads. It will not overwrite autoloads that already use those names.

The development project in this repository opens a keyboard-operable quickstart scene with ENet and explicit loopback WebSocket controls.

Minimal ENet session

# Listen host.varerror: Error=P2PNetwork.host_enet(7777, 16, "*")
# Client.varerror: Error=P2PNetwork.join_enet("127.0.0.1", 7777)

Register messages explicitly

Remote peers cannot select a NodePath, method, signal, property, or scene. A game registers every accepted message and its limits locally:

func_ready() ->void:
P2PNetwork.register_message(
"game.chat",
_on_chat,
512, # payload bytestrue, # accepted from clients by the authorityfalse, # not accepted from the authority by clients1,
RedotP2PTransportAdapter.Delivery.RELIABLE,
2.0, # messages per second per peer4, # burst"chat.send"
)
func_on_chat(peer_id: int, payload: PackedByteArray) ->void:
# Decode and validate the game's own bounded payload here.pass

The authority assigns roles or scoped capabilities through P2PNetwork.access_control. Client input still needs game-specific semantic validation; this addon supplies the trust boundary, not game rules.

Secure defaults

  • Incoming message types are deny-by-default.
  • Raw Variant/object deserialization is not used on network frames.
  • Client messages cannot invoke arbitrary methods, signals, properties, or scene creation.
  • The listen host or dedicated server is authoritative.
  • Frames, payloads, channels, packets per tick, bytes per tick, chat, lobby state, entity state, and intent rates are bounded.
  • Replayed or reordered sequence numbers are rejected per peer/channel.
  • Plain WebSocket is rejected except for explicitly enabled loopback development.
  • Moderation enforcement and CIDR banning are optional and off by default.
  • Address bans use only the authority-observed transport address. Relay-hidden transports return no address rather than trusting a client claim.
  • Exact address bans are the normal mode. CIDR requires explicit enablement; ranges broader than IPv4 /24 or IPv6 /64 require high-risk confirmation, and /16 or /48 are absolute limits.

JSON-backed compatibility state accepts only bounded JSON-safe values. Store network IDs and revision-like integers as canonical decimal strings when exact integer fidelity matters, because JSON numbers are decoded as floating-point values by the engine.

Upstream compatibility

The familiar classes and facade names remain where they can be made safe. Legacy arbitrary rpc_method, remote signal emission, arbitrary node removal, and free-form node synchronization are rejected while online with the stable status UNSAFE_LEGACY_API_REJECTED. Use registered messages, P2PNode, or the replication services instead. Wire compatibility with the upstream addon is not provided.

Development and tests

Set REDOT_BIN to the Redot 26.2 console executable, then run:

./tools/run_tests.ps1 -RedotBin $env:REDOT_BIN

Build a reviewable addon archive without publishing it:

./tools/package_addon.ps1

Generated test artifacts and packages are ignored by Git. See CONTRIBUTING.md and SECURITY.md.

Fork provenance

  • Upstream: DawnGroveStudios/GodotP2PNetwork
  • Upstream baseline: 54256e434c4735f38bbfbaae7d01fb6a47bc0c8b
  • Intended downstream: dominicbytes/RedotP2PNetwork
  • License: MIT; see LICENSE and NOTICE.md

The repository retains upstream Git ancestry. The addon path and protocol were changed intentionally for Redot and for safer defaults.

Notes

I vibe coded this in GPT Sol 5.6. Use at your own risk. Actual programmers are welcome to submit PR's and feedback.

About Dominic Bytes

Greetings! I am Dominic Bytes, the synth walker. I hail from the distant future. Where brains occupy robot bodies, time travel is a trip to the corner store, and the neon glow of our attire is powered by the light of our souls. Join me on a 1.21 gigawatt powered journey of chill vibes with gaming, anime, movies, and more!

About

Secure, transport-agnostic P2P networking plugin for Redot 26.2 (alpha).

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

RedotP2PNetwork

RedotP2PNetwork is a security-first Redot adaptation of DawnGroveStudios/GodotP2PNetwork. It provides a transport-neutral multiplayer service, compatibility facades for the original P2PNetwork and P2PLobby names, bounded lobby chat, replicated state, explicit entity replication, capability checks, and optional IP or identity bans.

This repository is an alpha implementation for Redot 26.2. It is suitable for development and local integration testing, not a claim that every planned transport or production deployment profile is certified.

Current capability status

SurfaceStatusEvidence and limits
Secure protocol coreImplementedStrict binary envelope, registered message allowlist, sender direction, channel/delivery checks, replay rejection, per-peer rate limits, bounded work, and violation disconnects are unit tested.
ENetImplementedNative two-process core and facade fixtures pass on Windows with Redot 26.2.
WebSocketImplementedNative two-process core and facade fixtures pass on loopback. Plain ws:// is loopback-only and opt-in; production requires TLS/WSS and deployment qualification.
SteamProvider-gated alphaAdapter and dynamic dominicbytes/redot-steam provider compile without making RedotSteam mandatory. A live private-App-ID authentication fixture is not yet certified.
WebRTCProvider-gated alphaAuthority-star adapter and replaceable signaling, ICE, and peer-factory contracts are present. The installed Redot build has no usable default WebRTC backend, so a real provider fixture is still required.
Lobby discovery directoryNot implementedDirect/current-lobby behavior works. Public discovery and the optional self-hostable directory remain later milestones.
Persistent moderationNot implementedIn-memory exact address, identity, and guarded CIDR bans are implemented. Persistence and report storage require future provider contracts.

See transport status, the upstream compatibility matrix, and the threat model before adopting the alpha.

Install

  1. Copy addons/redot_p2p_network into the target Redot project's addons/ directory.
  2. Enable RedotP2PNetwork in Project Settings > Plugins.
  3. Confirm the plugin registered the P2PNetwork and P2PLobby autoloads. It will not overwrite autoloads that already use those names.

The development project in this repository opens a keyboard-operable quickstart scene with ENet and explicit loopback WebSocket controls.

Minimal ENet session

# Listen host.varerror: Error=P2PNetwork.host_enet(7777, 16, "*")
# Client.varerror: Error=P2PNetwork.join_enet("127.0.0.1", 7777)

Register messages explicitly

Remote peers cannot select a NodePath, method, signal, property, or scene. A game registers every accepted message and its limits locally:

func_ready() ->void:
P2PNetwork.register_message(
"game.chat",
_on_chat,
512, # payload bytestrue, # accepted from clients by the authorityfalse, # not accepted from the authority by clients1,
RedotP2PTransportAdapter.Delivery.RELIABLE,
2.0, # messages per second per peer4, # burst"chat.send"
)
func_on_chat(peer_id: int, payload: PackedByteArray) ->void:
# Decode and validate the game's own bounded payload here.pass

The authority assigns roles or scoped capabilities through P2PNetwork.access_control. Client input still needs game-specific semantic validation; this addon supplies the trust boundary, not game rules.

Secure defaults

  • Incoming message types are deny-by-default.
  • Raw Variant/object deserialization is not used on network frames.
  • Client messages cannot invoke arbitrary methods, signals, properties, or scene creation.
  • The listen host or dedicated server is authoritative.
  • Frames, payloads, channels, packets per tick, bytes per tick, chat, lobby state, entity state, and intent rates are bounded.
  • Replayed or reordered sequence numbers are rejected per peer/channel.
  • Plain WebSocket is rejected except for explicitly enabled loopback development.
  • Moderation enforcement and CIDR banning are optional and off by default.
  • Address bans use only the authority-observed transport address. Relay-hidden transports return no address rather than trusting a client claim.
  • Exact address bans are the normal mode. CIDR requires explicit enablement; ranges broader than IPv4 /24 or IPv6 /64 require high-risk confirmation, and /16 or /48 are absolute limits.

JSON-backed compatibility state accepts only bounded JSON-safe values. Store network IDs and revision-like integers as canonical decimal strings when exact integer fidelity matters, because JSON numbers are decoded as floating-point values by the engine.

Upstream compatibility

The familiar classes and facade names remain where they can be made safe. Legacy arbitrary rpc_method, remote signal emission, arbitrary node removal, and free-form node synchronization are rejected while online with the stable status UNSAFE_LEGACY_API_REJECTED. Use registered messages, P2PNode, or the replication services instead. Wire compatibility with the upstream addon is not provided.

Development and tests

Set REDOT_BIN to the Redot 26.2 console executable, then run:

./tools/run_tests.ps1 -RedotBin $env:REDOT_BIN

Build a reviewable addon archive without publishing it:

./tools/package_addon.ps1

Generated test artifacts and packages are ignored by Git. See CONTRIBUTING.md and SECURITY.md.

Fork provenance

  • Upstream: DawnGroveStudios/GodotP2PNetwork
  • Upstream baseline: 54256e434c4735f38bbfbaae7d01fb6a47bc0c8b
  • Intended downstream: dominicbytes/RedotP2PNetwork
  • License: MIT; see LICENSE and NOTICE.md

The repository retains upstream Git ancestry. The addon path and protocol were changed intentionally for Redot and for safer defaults.

Notes

I vibe coded this in GPT Sol 5.6. Use at your own risk. Actual programmers are welcome to submit PR's and feedback.

About Dominic Bytes

Greetings! I am Dominic Bytes, the synth walker. I hail from the distant future. Where brains occupy robot bodies, time travel is a trip to the corner store, and the neon glow of our attire is powered by the light of our souls. Join me on a 1.21 gigawatt powered journey of chill vibes with gaming, anime, movies, and more!

About

Secure, transport-agnostic P2P networking plugin for Redot 26.2 (alpha).

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

RedotP2PNetwork

RedotP2PNetwork is a security-first Redot adaptation of DawnGroveStudios/GodotP2PNetwork. It provides a transport-neutral multiplayer service, compatibility facades for the original P2PNetwork and P2PLobby names, bounded lobby chat, replicated state, explicit entity replication, capability checks, and optional IP or identity bans.

This repository is an alpha implementation for Redot 26.2. It is suitable for development and local integration testing, not a claim that every planned transport or production deployment profile is certified.

Current capability status

SurfaceStatusEvidence and limits
Secure protocol coreImplementedStrict binary envelope, registered message allowlist, sender direction, channel/delivery checks, replay rejection, per-peer rate limits, bounded work, and violation disconnects are unit tested.
ENetImplementedNative two-process core and facade fixtures pass on Windows with Redot 26.2.
WebSocketImplementedNative two-process core and facade fixtures pass on loopback. Plain ws:// is loopback-only and opt-in; production requires TLS/WSS and deployment qualification.
SteamProvider-gated alphaAdapter and dynamic dominicbytes/redot-steam provider compile without making RedotSteam mandatory. A live private-App-ID authentication fixture is not yet certified.
WebRTCProvider-gated alphaAuthority-star adapter and replaceable signaling, ICE, and peer-factory contracts are present. The installed Redot build has no usable default WebRTC backend, so a real provider fixture is still required.
Lobby discovery directoryNot implementedDirect/current-lobby behavior works. Public discovery and the optional self-hostable directory remain later milestones.
Persistent moderationNot implementedIn-memory exact address, identity, and guarded CIDR bans are implemented. Persistence and report storage require future provider contracts.

See transport status, the upstream compatibility matrix, and the threat model before adopting the alpha.

Install

  1. Copy addons/redot_p2p_network into the target Redot project's addons/ directory.
  2. Enable RedotP2PNetwork in Project Settings > Plugins.
  3. Confirm the plugin registered the P2PNetwork and P2PLobby autoloads. It will not overwrite autoloads that already use those names.

The development project in this repository opens a keyboard-operable quickstart scene with ENet and explicit loopback WebSocket controls.

Minimal ENet session

# Listen host.varerror: Error=P2PNetwork.host_enet(7777, 16, "*")
# Client.varerror: Error=P2PNetwork.join_enet("127.0.0.1", 7777)

Register messages explicitly

Remote peers cannot select a NodePath, method, signal, property, or scene. A game registers every accepted message and its limits locally:

func_ready() ->void:
P2PNetwork.register_message(
"game.chat",
_on_chat,
512, # payload bytestrue, # accepted from clients by the authorityfalse, # not accepted from the authority by clients1,
RedotP2PTransportAdapter.Delivery.RELIABLE,
2.0, # messages per second per peer4, # burst"chat.send"
)
func_on_chat(peer_id: int, payload: PackedByteArray) ->void:
# Decode and validate the game's own bounded payload here.pass

The authority assigns roles or scoped capabilities through P2PNetwork.access_control. Client input still needs game-specific semantic validation; this addon supplies the trust boundary, not game rules.

Secure defaults

  • Incoming message types are deny-by-default.
  • Raw Variant/object deserialization is not used on network frames.
  • Client messages cannot invoke arbitrary methods, signals, properties, or scene creation.
  • The listen host or dedicated server is authoritative.
  • Frames, payloads, channels, packets per tick, bytes per tick, chat, lobby state, entity state, and intent rates are bounded.
  • Replayed or reordered sequence numbers are rejected per peer/channel.
  • Plain WebSocket is rejected except for explicitly enabled loopback development.
  • Moderation enforcement and CIDR banning are optional and off by default.
  • Address bans use only the authority-observed transport address. Relay-hidden transports return no address rather than trusting a client claim.
  • Exact address bans are the normal mode. CIDR requires explicit enablement; ranges broader than IPv4 /24 or IPv6 /64 require high-risk confirmation, and /16 or /48 are absolute limits.

JSON-backed compatibility state accepts only bounded JSON-safe values. Store network IDs and revision-like integers as canonical decimal strings when exact integer fidelity matters, because JSON numbers are decoded as floating-point values by the engine.

Upstream compatibility

The familiar classes and facade names remain where they can be made safe. Legacy arbitrary rpc_method, remote signal emission, arbitrary node removal, and free-form node synchronization are rejected while online with the stable status UNSAFE_LEGACY_API_REJECTED. Use registered messages, P2PNode, or the replication services instead. Wire compatibility with the upstream addon is not provided.

Development and tests

Set REDOT_BIN to the Redot 26.2 console executable, then run:

./tools/run_tests.ps1 -RedotBin $env:REDOT_BIN

Build a reviewable addon archive without publishing it:

./tools/package_addon.ps1

Generated test artifacts and packages are ignored by Git. See CONTRIBUTING.md and SECURITY.md.

Fork provenance

  • Upstream: DawnGroveStudios/GodotP2PNetwork
  • Upstream baseline: 54256e434c4735f38bbfbaae7d01fb6a47bc0c8b
  • Intended downstream: dominicbytes/RedotP2PNetwork
  • License: MIT; see LICENSE and NOTICE.md

The repository retains upstream Git ancestry. The addon path and protocol were changed intentionally for Redot and for safer defaults.

Notes

I vibe coded this in GPT Sol 5.6. Use at your own risk. Actual programmers are welcome to submit PR's and feedback.

About Dominic Bytes

Greetings! I am Dominic Bytes, the synth walker. I hail from the distant future. Where brains occupy robot bodies, time travel is a trip to the corner store, and the neon glow of our attire is powered by the light of our souls. Join me on a 1.21 gigawatt powered journey of chill vibes with gaming, anime, movies, and more!

About

Secure, transport-agnostic P2P networking plugin for Redot 26.2 (alpha).

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages