These scripts are disposable loopback Paper 1.21.11 protocol QA, not plugins to install on a real server. They use a minimal non-rendering client and a test fixture. They do not load actual cheat-client mods or certify every bypass.

The controller assumes /home/user/aegis-work/paper-1.21.11, loopback ports 25569/25579, flat terrain, Java 21 and cached Paper libraries. Configure a disposable server to match those paths or adapt the controller. Never copy its offline-mode or RCON test settings onto a public server.

Build the production JAR, run tools/build-qa-fixture.py --paper PATH, place the production JAR in that disposable server's plugins directory, then run qa/harness/controller.py full-qa.py. Final full-qa logs and result JSON identify the exact tested production JAR hash. There are five suites: reported gameplay, motion, attack/block geometry, impossible packets/timer, and 1/5/15 idle-client load.

Historical development attempts are retained in attempts/ with explanations in QA_REPORT.md; they are not counted as final passes. Incorrect synthetic packet sequences, stale player death state and initially wrong observation assumptions were corrected in the harness. Offline reset, pause guards and thread-safe counter resets were corrected in production code. No Discord webhook endpoint was configured or contacted during QA.
