Skip to content

Commit 6be9195

Browse files
Zayn995claude
andcommitted
Nexus texts for 1.21.0, and an updater that copies the whole program folder
The Nexus description, file description and credits now describe the signed python.org launcher and carry the three VirusTotal links of the 1.21.0 CI build (ZIP 0/66, exe 0/71, repak.exe 0/71). update.bat used to swap only S2Tweaker.exe and _internal; since 1.21.0 the runtime DLLs and python3XX._pth live next to the exe too, so it now copies everything the ZIP contains and keeps the old runtime in _internal.bak. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
1 parent 1d48998 commit 6be9195

4 files changed

Lines changed: 96 additions & 46 deletions

File tree

release/NEXUS_CREDITS_AND_PERMISSIONS.txt

Lines changed: 9 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,14 @@
1-
NEXUS — CREDITS UND PERMISSIONS (Stand 04.09.2026, v1.19.1)
1+
NEXUS — CREDITS UND PERMISSIONS (Stand 05.09.2026, v1.21.0)
22
===========================================================
33
Diese beiden Felder schlucken Zeilenumbrueche — die Texte sind deshalb
44
bewusst als EIN Block geschrieben und lesen sich auch so.
55

6-
Gegenueber der bisherigen Fassung geaendert:
6+
Neu seit 1.21.0: kein PyInstaller mehr. S2Tweaker.exe ist die
7+
PSF-signierte pythonw.exe von python.org; Python, Tcl/Tk, customtkinter,
8+
darkdetect und packaging sind als Komponenten genannt, die Lizenztexte
9+
liegen im Archiv unter _internal\licenses.
10+
11+
Gegenueber der Fassung vom 04.09. (1.19.1) geaendert:
712
1. Oodle wird NICHT mehr heruntergeladen. Der alte Satz ("fetched from
813
a public mirror when first needed") beschrieb 1.19.0 und waere jetzt
914
schlicht falsch — ausgerechnet an der Stelle, an der es um
@@ -20,14 +25,14 @@ Gegenueber der bisherigen Fassung geaendert:
2025
FELD: Credits / "Other user's assets" — Beschreibungstext
2126
==================================================================
2227

23-
This tool bundles third-party open-source components, all of which permit redistribution: repak by trumank (MIT OR Apache-2.0), included as repak.exe — note that this is a modified build, compiled from repak's source with its runtime download function and network stack removed, and that change is documented in the source; the cfg.bin decoder based on work by joric, sdwvit and thexii (public domain / MIT); customtkinter (MIT) and Python (PSF licence), linked in by PyInstaller. All are credited here and in the README inside the archive, and the full licence texts ship in THIRD_PARTY_LICENSES.txt with the source. No game assets are included: the tool reads the vanilla values from the user's own installation at runtime and ships none of GSC's files. Oodle's oo2core_9_win64.dll is proprietary, is not distributed with this tool, and is not downloaded by it either — the user obtains that file themselves, and the tool explains where to get it and where to put it. Since 1.19.2 the tool contains no networking code at all, which anyone can verify in the source. Thanks to the S.T.A.L.K.E.R. 2 modding community for documenting the {bpatch} config-patch system, and to GSC Game World for the game.
28+
This tool bundles third-party open-source components, all of which permit redistribution: repak by trumank (MIT OR Apache-2.0), included as repak.exe — note that this is a modified build, compiled from repak's source with its runtime download function and network stack removed, and that change is documented in the source; the cfg.bin decoder based on work by joric, sdwvit and thexii (public domain / MIT); Python itself (PSF licence) — S2Tweaker.exe is the unmodified pythonw.exe from python.org, signed by the Python Software Foundation, and the runtime, the extension modules and Tcl/Tk (BSD-style licence) come from the same python.org installation; and the pure-Python libraries customtkinter (MIT), darkdetect (BSD-3-Clause) and packaging (Apache-2.0 OR BSD-2-Clause). All are credited here and in the README inside the archive, and the full licence texts ship inside the archive in _internal\licenses. No game assets are included: the tool reads the vanilla values from the user's own installation at runtime and ships none of GSC's files. Oodle's oo2core_9_win64.dll is proprietary, is not distributed with this tool, and is not downloaded by it either — the user obtains that file themselves, and the tool explains where to get it and where to put it. Since 1.19.2 the tool contains no networking code at all, which anyone can verify in the source. Thanks to the S.T.A.L.K.E.R. 2 modding community for documenting the {bpatch} config-patch system, and to GSC Game World for the game.
2429

2530

2631
==================================================================
2732
FELD: Additional info / Author notes — Permissions
2833
==================================================================
2934

30-
Everything here is MIT-licensed and yours to use — fork it, improve it, ship it, no need to ask. Two things I'd appreciate rather than require: (1) If you redistribute the compiled S2Tweaker.exe, please point people to the original source and make clear if your build is a modified one — binaries are hard for players to verify, and this tool already fights antivirus false positives. (2) Please keep the credits intact. Note on bundled components: these permissions cover S2Tweaker's own code and assets. The bundled repak.exe by trumank stays under its own MIT/Apache-2.0 licence, and the copy shipped here is a modified build with its runtime download removed. Oodle's oo2core_9_win64.dll is proprietary: it is not distributed with this tool and is not downloaded by it — the user places that file themselves.
35+
Everything here is MIT-licensed and yours to use — fork it, improve it, ship it, no need to ask. Two things I'd appreciate rather than require: (1) If you redistribute the program folder, please point people to the original source and make clear if your build is a modified one — binaries are hard for players to verify, and this tool has already fought enough antivirus false positives. (S2Tweaker.exe itself is the unmodified pythonw.exe from python.org and stays under the PSF licence.) (2) Please keep the credits intact. Note on bundled components: these permissions cover S2Tweaker's own code and assets. The bundled repak.exe by trumank stays under its own MIT/Apache-2.0 licence, and the copy shipped here is a modified build with its runtime download removed. Oodle's oo2core_9_win64.dll is proprietary: it is not distributed with this tool and is not downloaded by it — the user places that file themselves.
3136

3237

3338
==================================================================

release/NEXUS_DESCRIPTION.txt

Lines changed: 23 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -13,10 +13,11 @@ The full source code is open under the MIT license. There is a public S2Tweaker
1313

1414
[b]Virus scan of exactly the file on this page:[/b]
1515
[list]
16-
[*]The mod itself: [url=https://www.virustotal.com/gui/file/1fda3a616121293ecd0975e91caaa33208b93267f15f5d1c07f63ac934877ebe/detection]VirusTotal - 1 of 66[/url]. The single detection is Zillya ("Dropper.Agent"); every other engine, Windows Defender included, reports it clean. Zillya has been informed and asked to review it as a false positive
17-
[*]The program file inside it: [url=https://www.virustotal.com/gui/file/e6ad82b315682c01a74534ad800920e562c24cc1503cf7a21ca75e408aeaf973]VirusTotal - 2 detections[/url]. Both are generic guesses, not a named malware family: Microsoft's is "Wacatac.B!ml", where the "!ml" means it comes from a machine-learning model rather than a signature, and Zillya's is "Dropper.Agent". Windows Defender as installed on my machine reports every file clean. VirusTotal explains the difference in its own documentation: engines run there with "stronger heuristics, cloud interaction, inclusion of beta signatures". Both vendors have been asked to review it as a false positive
16+
[*]The mod itself: [url=https://www.virustotal.com/gui/file/23a25f307d0a9145ec19b9132ccf0fb638921b2ca30abc568124466b908edbb0]VirusTotal - 0 of 66[/url]
17+
[*]The program file inside it, S2Tweaker.exe: [url=https://www.virustotal.com/gui/file/d72294fb338bc2fc8896d25a7395a4db466425427e1559e77185d5135a830681]VirusTotal - 0 of 71[/url]. It is pythonw.exe from python.org, byte for byte, digitally signed by the Python Software Foundation - VirusTotal labels it "File distributed by Python Software Foundation"
18+
[*]The only unsigned file inside it, repak.exe (the open-source pak tool, compiled from source by the public build workflow): [url=https://www.virustotal.com/gui/file/73dd824ac6da17b9d1f73ae02f20a362d3262818875aea6e4860f26244317175]VirusTotal - 0 of 71[/url]
1819
[/list]
19-
Those numbers are from 1.19.2, the release that earned them by removing a 2.8 MB compressed blob from inside the executable (three detections down to two). 1.20.0 is built the exact same way and only adds the ammunition dropdown.
20+
Those numbers are for 1.21.0. Earlier versions were built with PyInstaller and kept collecting false positives (1.20.0: 1 of 65 for the ZIP, 2 of 70 for the exe) even after every setting had been tried; the changelog below explains what changed.
2021

2122
[quote][b]Honesty note:[/b] every patch the tool generates is cross-checked against the game's own config files, but it has [b]not been play-tested in-game yet[/b] - bug reports in the comments are very welcome![/quote]
2223

@@ -155,7 +156,7 @@ A small Windows tool with sliders and checkboxes. You pick your values, it build
155156
[list=1]
156157
[*]Download and extract the ZIP
157158
[*]Create a folder, for example on your desktop: Desktop\S2Tweaker
158-
[*]Extract the whole ZIP into that folder - S2Tweaker.exe needs the "_internal" folder that sits next to it
159+
[*]Extract the whole ZIP into that folder - S2Tweaker.exe needs the DLL files and the "_internal" folder that sit next to it
159160
[*]Run S2Tweaker.exe
160161
[*]The tool suggests your game folder, e.g. C:\Games\Steam\steamapps\common\S.T.A.L.K.E.R. 2 Heart of Chornobyl - check it. If it's wrong, click "Browse ..." and select your game folder (the one that contains Stalker2\Content\Paks)
161162
[*]Click "Confirm & load game data" and wait 10-20 seconds (only needed on first start and after game updates)
@@ -186,13 +187,24 @@ If the ~mods folder doesn't exist, create it.
186187
[*]Weapon fire rate, spread and recoil live in game data shared with NPCs - NPCs using those weapons are affected too (noted in the app)
187188
[*]Since game patch 2.0 the community reports that cfg-based movement-speed changes can desync from animations or partially not apply - the movement and carry-weight sliders carry an in-app warning until this settles
188189
[*]The fire-rate factor is reported to have the same animation limitation: firing animation and sound can desync from the actual shots. It stays available - test in-game and keep changes moderate
189-
[*]Some antivirus tools flag freshly built Python exes - this is a known false-positive pattern
190+
[*]S2Tweaker.exe is the unmodified pythonw.exe from python.org, signed by the Python Software Foundation - that is why it shows the Python icon and Python's version info. If an antivirus tool still flags anything, it is a false positive; the scan links at the top of this page are for exactly the file you download here
190191
[*]Reading the game's packed config files needs Oodle's oo2core_9_win64.dll (0.6 MB). It is proprietary, cannot be shipped with the tool, and the game does not ship it as a separate file either (Oodle is compiled into the game's own executable). Since 1.19.1 the tool does NOT download it - a program that fetches a library and then runs it is exactly what malware does, and that is one reason scanners flag tools like this one. Instead a setup window walks you through getting it once, with pictures, and shows you where to put it. It takes a minute, and afterwards the tool never asks again. You may already have the file: every Unreal Engine installation ships it
191192
[*]Debug checkbox: also exports the raw .cfg patch files to output\<ModName>_cfg so you can see exactly what the mod changes
192193
[/list]
193194

194195
[heading]CHANGELOG[/heading]
195196

197+
[b]v1.21.0 - No more PyInstaller: the launcher is the signed python.org interpreter[/b] (~230 tweaks + ammo swap, 13 tabs)
198+
[list]
199+
[*][b]What changes for you:[/b] nothing in the tool - and the exe now shows the Python icon. S2Tweaker.exe is pythonw.exe from python.org, byte for byte, digitally signed by the Python Software Foundation; changing the icon or the version info would break that signature. The tool's own version is in the window title. Extract the whole ZIP and keep the files together: next to S2Tweaker.exe there are now python312.dll, vcruntime140.dll and python312._pth as well as the _internal folder
200+
[*][b]Why:[/b] 1.20.0 was still flagged by two engines although its launcher was byte for byte PyInstaller's official one, which scans clean on its own - the detections were aimed at the archive PyInstaller appends to it, i.e. at PyInstaller itself. No build setting could change that, so PyInstaller is gone
201+
[*][b]Everything in the folder is readable or signed.[/b] The tool's own code ships as plain .py files in _internal\s2tweaker, next to the Python runtime and Tcl/Tk from the same python.org installation. Every DLL, PYD and EXE in the folder is signed by the PSF or Microsoft, with one exception: repak.exe, the open-source pak tool, which the public build workflow compiles from source
202+
[*][b]No networking capability at all:[/b] Python's socket and ssl modules and the OpenSSL libraries are not in the package. Since 1.19.2 the program has had no networking code; now the runtime it ships with could not open a connection either
203+
[*][b]Result:[/b] 0 detections on VirusTotal for the ZIP, for the exe and for repak.exe - the links are at the top of this page. 1.20.0 stood at 1 of 65 and 2 of 70
204+
[*][b]To update:[/b] extract the new ZIP over your S2Tweaker folder, replacing what is there. Settings, presets, cache and output are not in the ZIP and stay untouched
205+
[*]Not play-tested, like the rest of the tool. No new game files, no re-extraction. Your existing paks stay valid
206+
[/list]
207+
196208
[b]v1.20.0 - Change which ammunition a weapon uses[/b] (~230 tweaks + ammo swap, 13 tabs)
197209
[list]
198210
[*][b]New: an "Ammunition" dropdown per weapon[/b] (Weapons tab, "Single weapon overrides", above the sliders). Requested on GitHub by Molkerr: put the AK-74 on 5.56, the Viper on .45, whatever you like - every caliber the game actually uses is offered
@@ -205,15 +217,18 @@ If the ~mods folder doesn't exist, create it.
205217
[/list]
206218

207219
[b]v1.19.2 - No network code, and no archive hidden inside the exe[/b] (~230 tweaks, 13 tabs)
220+
[spoiler]
208221
[list]
209222
[*][b]The executable was 90 % compressed archive - that is fixed.[/b] Shipping as a folder in 1.19.0 only moved the DLLs out; the Python code stayed inside S2Tweaker.exe as a compressed blob of 2,857,284 bytes with an entropy of 7.999 out of a possible 8.0. A small loader in front of a large opaque block is what a packer looks like, and it is how analysts recognise malware built with the same tooling. The code now ships as ordinary files next to the exe: [b]the program file is 345 KB instead of 3.2 MB[/b], and one of the three scanners that flagged it stopped
210223
[*][b]The update check is gone, and with it every trace of networking.[/b] No urllib, no sockets, no HTTP client. Nexus' own file guidelines prohibit executables that connect to the internet "unless where it is crucial" and say plainly that "'auto update' functionality does not qualify as crucial" - they were right, so it is out. You can check that claim yourself with one search of the public source
211224
[*][b]To update from now on[/b]: download the new ZIP and replace S2Tweaker.exe and the _internal folder next to it. Your settings, presets, cache and built mods are never touched. The version you are running is in the window title
212225
[*][b]This download is the build server's own output[/b], downloaded from the public GitHub Actions run and uploaded here unchanged - nothing in it was built on my PC
213226
[*]No new game files, no re-extraction. Your existing paks stay valid
214227
[/list]
228+
[/spoiler]
215229

216230
[b]v1.19.1 - Nothing is downloaded at runtime any more[/b] (~230 tweaks, 13 tabs)
231+
[spoiler]
217232
[list]
218233
[*][b]The tool no longer fetches anything while it runs.[/b] Until now it downloaded the Oodle decompression library on first use, and the bundled repak could fetch it too. A program that pulls a library off the internet and then executes it is exactly what a dropper does - one of the reasons antivirus scanners kept flagging this tool. That capability is gone now, not disabled
219234
[*][b]repak is built from source[/b] with the download function and its whole HTTP/TLS stack removed. Measured in the binary: 113 occurrences of the TLS library before, none after; the file shrank from 4.4 MB to 2.1 MB. It is also no longer a third-party prebuilt binary, so every file in this download now comes from the public source code, built by a public GitHub Actions workflow
@@ -222,8 +237,10 @@ If the ~mods folder doesn't exist, create it.
222237
[*]Sorry that this means one manual step. The library cannot legally be bundled, it cannot be taken out of the game (Oodle is compiled into the game's own executable), and the open re-implementations carry no licence at all. Doing it for you was the old answer, and that is what got this tool flagged
223238
[*]No new game files, no re-extraction. Generated paks are unchanged apart from the version stamp
224239
[/list]
240+
[/spoiler]
225241

226242
[b]v1.19.0 - The tool now ships as a folder, to stop antivirus false positives[/b] (~230 tweaks, 13 tabs)
243+
[spoiler]
227244
[list]
228245
[*][b]What changes for you:[/b] extract the whole ZIP and keep the files together - S2Tweaker.exe now needs the "_internal" folder sitting next to it. Everything else is the same: double-click S2Tweaker.exe, and settings, presets, cache and output are still created next to it. The download is even slightly smaller than before
229246
[*][b]Why:[/b] the exe used to be a PyInstaller one-file build - a self-extracting 15 MB archive that unpacks itself into your temp folder and runs from there. That is harmless, but it is also exactly what a dropper does, so antivirus machine-learning heuristics kept guessing wrong: Windows Defender deleted one freshly built exe as Trojan:Win32/Bearfoos.A!ml, and the upload here could not be approved because scanners flagged it on download. The launcher is now 3 MB with nothing embedded in it
@@ -233,6 +250,7 @@ If the ~mods folder doesn't exist, create it.
233250
[*][b]New test suite that checks every slider against your game's real values[/b] - over 3,000 checks across all sliders, weapon/ammo/armor/mutant overrides and all 582 faction pairs, each one built three times to verify the maths holds. It found no wrong values, and it is the kind of test that would have caught the "quest cooldown does nothing" and "recoil at 0 % does nothing" bugs on its own
234251
[*]No new game files, no re-extraction on first start. Generated paks are unchanged apart from the version stamp in their manifest
235252
[/list]
253+
[/spoiler]
236254

237255
[b]v1.18.3 - Hardening: weather templates and the NPC threat profile are written out completely[/b] (~230 tweaks, 13 tabs)
238256
[spoiler]

0 commit comments

Comments
 (0)