Ember

A modern, open-source P2P file sharing client built on the eMule KAD network. Ground-up rewrite with Rust & Tauri for speed, safety, and simplicity.

No Spyware
No Ads
No Nonsense
GPLv3 Licensed

Ember is not a fork or reskin of eMule. It is a complete reimplementation of the eMule protocol stack in safe Rust, paired with a lightweight Tauri + Svelte shell. It speaks the same KAD wire protocol as eMule 0.50a and compatible clients (aMule, eMule Xtreme, etc.), participates in the same network, finds the same sources, and respects the same credit system. On first launch Ember can seed a community server.met from emule-security.org; you connect to KAD and ED2K servers when you choose (or enable optional auto-connect in Settings).

Ember also runs a network of its own. The Ember Network is an encrypted overlay with no servers and no central directory: Ember nodes find each other directly, publish the files they share, and look up sources for a download over their own DHT. It is on by default and runs alongside KAD and eD2K, so you keep the whole eMule network as well.

On top of that, EPX (Ember Peer Exchange) speeds up source discovery between Ember peers on the ordinary eMule wire, and an Ember-exclusive Friends system adds end-to-end encrypted chat, Noise-secured sessions, and privacy-preserving Friend Codes — all invisible to non-Ember clients.


Highlights

🧱

Modern Foundation

Built in Rust with Tokio async networking. No buffer overflows, no dangling pointers, no data races. The entire protocol stack runs in safe, memory-managed code.

🌐

Full Protocol Compliance

Wire-compatible with eMule 0.50a and the broader eMule ecosystem. KAD v8/v9, ED2K servers & peer exchange, credits, SecIdent, obfuscation, and AICH all work out of the box.

🔥

Ember Network (Beta)

Ember’s own encrypted overlay. No servers, no central directory, no shipped seed list — nodes find each other, publish shared files, and look up sources over their own DHT, alongside KAD and eD2K.

🔄

EPX Source Exchange

Ember peers share compact source lists with each other for faster downloads. Non-Ember clients silently ignore the extension—zero compatibility impact.

🔍

Advanced Search

Global, Server, KAD, and Ember keyword search with multi-tab results, type/size/source/extension filters, and built-in spam detection.

🛡

Security & Privacy

End-to-end friend chat encryption, signed anti-rollback updates, RC4 protocol obfuscation, IP filtering with automatic updates, private IP blocking, confirmed deep links, and strict CSP headers.

Lightweight Shell

Tauri v2 produces a small, fast desktop app (~15 MB installed) without bundling a full browser engine. Responsive UI powered by Svelte 5.

📦

Smart Transfers

Multi-source downloading with intelligent source management, real-time progress, health monitoring, queue tracking, and archive recovery.

📚

Library Management

Virtual-scrolling tables that handle thousands of files. Sort, filter, play media in-app, copy eD2K links, add comments and ratings, and create collections.

👥

Ember Friends

Share a Friend Code, connect through the rendezvous server, then chat end-to-end encrypted over Noise-secured sessions. Mutual friends also get remote browsing, friends-only shares, file offers, priority uploads, and transfers that can work without HighID.


Download & Installation

Ember

Get Ember 1.5.3

The latest release is available on GitHub for Windows 10 and Windows 11.

Supported Operating Systems

Windows 10 and Windows 11.

Requirements

No external runtimes needed. No Java, no .NET, no browser engine download. Ember ships everything it needs in a single installer.


Getting Started

  1. Install
    Download the latest release from the Releases page and run the installer.
  2. Setup Wizard
    On first launch, the Setup Wizard walks you through essential settings — nickname, download folder, ports, speed limits, KAD auto-connect, and theme.
  3. Connect
    Press Connect on the KAD Network page and/or connect from the ED2K Servers page. Optionally enable Auto-Connect KAD and Auto-Connect Server in Settings (or the Setup Wizard) so Ember reconnects on launch. A community server.met list can be downloaded from emule-security.org on first run. The Ember Network needs no connect step — it is on by default and joins on its own, but it finds its first peers through KAD and eD2K, so keep at least one of them available on a fresh install.
  4. Share & Download
    Add folders to your library, search with Global / Server / KAD methods, open ed2k:// links, and start downloading. Ember handles multi-source transfers, queue management, and source discovery automatically.
  5. Add Friends (optional)
    Open the Friends page, share your Friend Code, and add theirs. Once mutual and online, you get end-to-end encrypted chat, remote file browsing, and priority upload slots. See Friends.

Tip: For best performance (High ID), forward your TCP and UDP ports on your router, enable UPnP, or leave STUN port keep-alive on in Settings > Network. See the High ID vs Low ID section for details.


Features

Networking

  • Ember Network (Beta) — Ember’s own encrypted, server-less overlay for peer discovery, keyword search, publishing, and source lookup. On by default, joins automatically, and runs alongside KAD and eD2K. See the Ember Network section.
  • KAD Network — Connect to the decentralized KAD DHT for peer discovery, keyword search, publishing, firewall checks, and buddy relay. Optional Auto-Connect KAD in Settings; otherwise press Connect on the KAD Network page. If KAD will not connect, Settings > Network can fetch fresh nodes.dat bootstrap contacts from emule-security.org.
  • ED2K Servers & Peer Exchange — Manage servers on the ED2K Servers page, download a community server.met from emule-security.org, and optionally Auto-Connect Server (last server, else eMule Sunrise). Once connected, peer exchange helps find sources.
  • EPX Source Exchange — Ember peers share source lists with each other for faster downloads. Non-Ember clients are unaffected.
  • NAT Traversal — UPnP automatic port mapping, firewall detection, KAD buddy relay for LowID peers, and EPX peer-relay (ERAT) for LowID↔LowID paths when attestations allow.
  • STUN Port Keep-Alive — Periodic STUN plus a TCP hold from your listen port keeps NAT mappings alive and advertises the discovered public TCP/UDP ports for High ID. Designed for CGNAT and full-cone NAT when UPnP is unavailable; auto-suspends on symmetric or unstable remapping.
  • Protocol Obfuscation — RC4-based TCP and UDP header encryption to help with ISP throttling.
  • Deep Links — Opens ed2k:// URIs and .emulecollection files from the OS (including while Ember is already running). Incoming links require confirm / review before opening, and pending links can be reviewed later.

Transfers

  • Multi-Source Downloads — Download from multiple peers simultaneously with part-level hash verification, automatic source rotation, and queue management.
  • Transfer Monitoring — Real-time progress bars, per-source detail drawers, upload tracking, health indicators, and archive recovery.
  • Bulk Transfer Actions — Tick rows (or use the header checkbox) to pause, resume, stop or cancel many downloads at once, or use the Pause / Resume / Stop / Cancel All commands in the toolbar's More menu. Completed and failed rows can be selected the same way and removed from the list together; the files themselves are kept.
  • Upload Speed Sense (USS) — Optionally adjusts upload speed from network latency to reduce congestion (requires an upload speed limit).
  • AICH — Advanced Intelligent Corruption Handling for part-level hash verification and recovery.

Search & Library

  • Advanced Search — Global, KAD Only, Server Only, and Ember Only keyword search with multi-tab results plus type, size, source, and extension filters. Global runs every network that is up, so Ember results arrive alongside KAD and server hits, de-duplicated into one list.
  • Spam Detection — Built-in spam detection with balanced and aggressive profiles. Configurable spam threshold and automatic result hiding.
  • Library Management — Virtual-scrolling tables that handle thousands of files. Sort, filter, bulk-edit priorities, scan for missing files, copy all eD2K links for the current view, and create collections.
  • Copy eD2K Links from Search — Copy the link for one result, for every ticked result, or for the whole result list at once, from the context menu, the selection toolbar, or Ctrl+C.
  • In-App Media Player — Play supported audio and video from the Library detail drawer, with Open Externally still available.
  • Comments & Ratings — Add metadata to your shared files for other peers to see.

Social

  • Ember Friends — Ember-exclusive friend system powered by a rendezvous server. Share a v2 Friend Code, exchange mutual requests, then enjoy real-time online status, remote file browsing, friends-only shares, file offers, priority upload slots, durable offline chat, and end-to-end encrypted messaging. See the Friends section for details.
  • E2E Friend Chat — Mutual-friend messages use static X25519 ECDH + AEAD end-to-end encryption after session setup. The chat UI shows an Encrypted badge; plaintext fallbacks are rejected. Conversation history is encrypted in the local database, and outbound messages queue until the friend is reachable again. Being a static exchange, it provides no forward secrecy and covers message bodies only — see E2E Encryption.
  • Noise-Secured Friend Sessions — Friend connections use Noise IK secure streams with Ed25519 proof-of-possession before chat, browse, offers, and verified friend privileges unlock. Friend file transfers can also run over the same secure path when ordinary HighID/callback routes are unavailable.
  • Credits & SecIdent — RSA-based Secure Identification prevents credit theft. Upload priority follows the standard credit ratio formula.

Security

  • Signed Anti-Rollback Updates — In-app updates are cryptographically signed and gated by security epochs, so installs only advance when the signed epoch allows it.
  • Safer File Opens — Deep links require confirm / review; Library drag-and-drop shared folders ask for a system folder-picker confirmation; media and upload paths pin approved handles to avoid path-swap races.
  • Security Page — A dedicated page for IP filter management: download the default list, import a file, fetch from an HTTPS URL, enable or disable filtering, add and remove custom ranges, and review how many times each range has actually blocked something.
  • IP Filtering — Load ipfilter.dat / ipfilter.zip with automatic update support. Incoming connection filtering is off by default because VPN IP ranges commonly appear in ipfilter.dat hosting blocks, silently blocking legitimate peers. Outbound filtering remains active regardless of this setting.
  • Anti-Leech Filter — Reject incoming connections from known leech client patterns (customizable regex list in Settings).
  • Private IP Blocking — Prevents connections to reserved IP ranges.
  • Content Security Policy — Strict CSP headers in the Tauri webview.
  • Path Traversal Protection — Sanitized file paths prevent directory escape attacks.

User Experience

  • First-Time Setup Wizard — Guided configuration on first launch: nickname, download folder, ports, speed limits, optional KAD auto-connect, and theme.
  • Clean UI — Modern, responsive interface with real-time transfer monitoring and inline search filtering.
  • Close to System Tray — Choose what the title-bar close button does — ask each time, minimize to tray, or exit. The tray icon stays available either way, so you can reopen Ember from there.
  • Keyboard Shortcuts — Press ? for a shortcut cheat sheet, and Alt+1–9 to jump straight to the first nine sidebar pages.
  • Backup & Restore — Settings > Backup saves your whole profile to a single passphrase-encrypted .emberbackup file: identity and SecIdent keys, upload credits, settings, shared-folder list, known files, friends, chat history, transfer list, server and Kad contacts, IP filter, and learned spam data. The files you share and part-finished downloads are not included, so a backup stays small. Encryption is mandatory because the archive contains your private keys, and a lost passphrase cannot be recovered. Your identity keys are unwrapped from Windows DPAPI into the encrypted archive and re-wrapped for whichever Windows account restores them, so a restore on a new machine keeps your user hash, credits and friendships instead of silently rotating them. Restores are prepared immediately and applied while Ember next starts (the files being replaced are in use while it runs); the replaced originals are kept in a pre-restore-<timestamp> folder beside them, and a pending restore can be discarded from the same screen before it is applied. A restore that has sat waiting for more than a month is dropped rather than applied on top of the profile you have been using since; the backup file is untouched, so you can simply import it again. Two things to expect after restoring onto a different machine: shared and download folders need re-approving in Settings, and if the backup carried the database without chat-history.key, existing chat history stays sealed.
  • Statistics — Session and cumulative transfer statistics, connection uptime, network health indicators, and a peer reputation snapshot.
  • Automatic Updates — Ember checks for new versions on launch and installs cryptographically signed, anti-rollback updates in-app with one click. You can also check manually under Settings > About.
  • Languages — Full UI localization for English, Spanish, French, Brazilian Portuguese, German, Simplified Chinese, Italian, Russian, and Traditional Chinese, with a Settings language picker and system-language detection.
  • GeoIP — Country identification for connected peers via bundled MaxMind DB.

Ember Network Beta

The Ember Network is Ember’s own peer-to-peer overlay: a second network that Ember nodes run between themselves, in parallel with KAD and eD2K. Nodes find each other directly, publish the files they share, and look up sources for a download over their own DHT. There is no directory server, no tracker, and no shipped seed list, and every frame between nodes travels inside an encrypted session.

It is on by default and joins on its own — there is no Connect button. You can turn it off (and back on) from the Ember Network page or Settings > Network; the change is applied live, with no restart. Because it runs alongside the eMule networks rather than replacing them, turning it on costs you nothing on KAD or eD2K.

What it does not change: Ember finds the source; the file itself still transfers over eD2K client-to-client. An Ember search result downloads through the same multi-source engine, credits, and AICH verification as any other result.

How a node joins

There is no bootstrap server to ask and no address list in the installer. A cold node gets in through whichever of these arrives first:

  1. The KAD rendezvous key
    Ember nodes advertise themselves under one fixed KAD key, as an ordinary source record carrying their Noise public key. A node with a near-empty routing table simply runs a source lookup there. Nodes re-advertise every 5 hours, and only while reachable and already publishing something, so a node that shares nothing never generates publish traffic just to list itself.
  2. The KAD bridge
    Ember peers noticed in ordinary KAD traffic get pinged on the Ember DHT; their signed reply folds them into the routing table. Rate-capped per maintenance cycle and quiet once the table is healthy.
  3. eD2K transfers
    A peer that advertises Ember capability during a normal eD2K transfer is cached with its UDP port and bridged in. This is the way in for a client running with no KAD at all.
  4. Gossip and the saved contact file
    Once a node has been online before, peers learned from other peers plus a persisted contact file (up to 200 entries) get it back in without help.

The first three paths all assume either a live KAD connection or an eD2K transfer with an Ember-capable peer, and the fourth only helps a node that has been online before. That is deliberate: Ember rides eMule’s bootstrap rather than standing up infrastructure of its own. The practical consequence is worth knowing — a first run with KAD off and no servers has no way in.

The rendezvous server has no role here. The server behind Friends is not involved in joining the Ember Network, and a server-hosted bootstrap pool is explicitly not planned: it would hand whoever runs the server an identity-to-IP roster of every participant. Hardcoded seed lists and DNS SRV seeds are ruled out for the same reason — joining stays the rendezvous key, the bridges, gossip, and your own saved contacts.

A fresh node can legitimately sit at zero peers for a minute or two while its first maintenance cycle runs the bridge. The status page shows Connecting during that window rather than pretending something is wrong.

The files you share are published to the Ember DHT as keyword records (so people can find them by name) and source records (so people can fetch them). Publishing happens automatically once the node has peers, and republishes on a cycle to stay alive.

  • Searching — The Search page has an Ember Only method, and Global queries Ember alongside KAD and servers, merging everything into one de-duplicated result list. If KAD and eD2K are both offline, Global quietly falls back to Ember alone.
  • Source lookup — Downloads ask the Ember DHT for sources in addition to KAD and servers, so a file can gain Ember sources even if you found it elsewhere.
  • Publish badge — The Library marks a shared file with an Ember badge once it has a source record placed on the network, which is the point at which other Ember users can actually fetch it.
  • Publishing while firewalled — A node that cannot be reached directly publishes through a buddy relay instead, so sharing still works behind a restrictive router.
  • BLAKE3 integrity — Ember records carry a BLAKE3 digest, and a download verifies against it whenever one is known (from a search hit, a DHT source record, or your own library). Links opened without a digest still download normally and are hashed for future sharing.

Multi-keyword search is approximate. A query with several words uses a sparse DHT intersection plus a filename match on the results, not a strict worldwide AND of every keyword. Recall can differ from KAD on the same query.

Encryption and identity

Ember DHT traffic shares the KAD UDP port (4672 by default) and is told apart by a two-byte marker, so forwarding that port covers both networks. Everything past the marker is encrypted.

PropertyDetail
Session encryption Noise with ChaCha20-Poly1305 and BLAKE2s. Noise_IK when the peer’s static key is already known, Noise_XX for first contact.
Node identity A 128-bit node ID derived from BLAKE3 of the node’s Ed25519 public key. DHT frames are Ed25519-signed, and a contact is only trusted once it has answered directly.
Routing Kademlia with k = 20, α = 5, and at most 20 contacts per response.
Wire versioning Version 2. The decoder accepts a version range and refuses anything outside it at the version byte, so an incompatible peer is a clean rejection rather than a stream of malformed-packet counters that read like packet loss.
Abuse resistance Per-IP and per-subnet admission caps that scale with table occupancy, return-routability checks before a node spends anything substantial on a request (so Ember cannot be used as a traffic reflector), retry cookies for unproven addresses, and per-publisher storage quotas so one peer cannot fill the space this node offers the network.

The Ember Network page

The page leads with the questions a user actually has — is it on, am I connected, can people reach me, are my shared files findable — and keeps the protocol detail behind a disclosure.

  • Status — Off, Connecting, Connected, or No peers found, with the on/off switch beside it.
  • Peers and Published files — How many nodes you are in touch with, and how many of your shared files are findable.
  • Health checklist — Whether you are on the network, whether people can reach you directly or through a relay, and whether your shares are published.
  • Technical details — Collapsed by default: your node ID and public keys, around twenty protocol counters (search hits and misses, store acks and failures, average replication, buddy publishes and forwards, malformed frames, observed address votes, EPX exchange stats, storage rejections), plus live tables of contacts, in-flight searches, and the keys this node is serving to others.

Beta limits

The overlay is on by default and in daily use, but it is labelled Beta for concrete reasons:

  • Bootstrap depends on eMule — A first run with KAD off and no servers cannot join, as described above.
  • Version mismatches are silent — Incompatible peers refuse each other cleanly, but neither side is told why and there is no upgrade prompt. They simply never appear in each other’s routing tables.
  • Multi-keyword recall is approximate — See the note above.
  • A busy keyword shows only a slice of what is out there — Each peer answers a keyword query with about as many records as fit in one packet, roughly five, and there is no way yet to ask it for the next page, so recall under a common word is bounded by how many peers the search walks. The same ceiling applies to publishing: one person may hold at most 45 entries under any single word across the whole network, so if you share 200 files that share a common word, not all of them are findable under it. 1.5.3 adds counters for how often this is actually biting, which is what decides whether we spend a protocol change on it.
  • Gossip is unverified until it answers — A peer another node told us about is a lead, not a fact, until it replies directly. Admission caps bound the damage, but there is no reputation scoring on gossip itself.
  • Content still moves over eD2K — The native Ember transfer path is written but not switched on, so the eMule wire is still doing the actual file transfer.
  • Some paths are not yet exercised end to end — Notably publishing while firewalled through a buddy relay, and a cold join from an empty contact file with no KAD.

EPX — Ember Peer Exchange

EPX is an Ember-exclusive extension to the eMule protocol that accelerates source discovery between Ember peers. It makes downloads faster whenever multiple Ember clients are present on the network.

EPX and the Ember Network are separate things that are easy to confuse. EPX is an extra opcode on the eMule wire, exchanged with Ember peers you are already transferring with. The Ember Network is a whole overlay of its own, with its own DHT and its own encrypted transport. Both work independently: EPX still helps with the Ember Network switched off.

How it works

When two Ember clients connect (during a download or upload), they exchange compact lists of the files they are currently downloading along with the sources they know about for each file. If the receiving peer is downloading one of those files, it immediately gains new sources it may not have found through KAD or ED2K peer exchange alone.

Key point: EPX only activates between confirmed Ember peers. Detection uses the private OP_EMBER_HELLO / OP_EMBER_HELLOANSWER handshake. TCP EPX also requires the peer's advertised Ed25519 public key to BLAKE3-bind to its Ember hash — an offline check that a replayed key pair can pass, and so a deliberately lower bar than the proof of possession behind chat, browse and other friend privileges. UDP EPX requires an authenticated Noise_IK session. Legacy ET_MOD_VERSION / CT_EMULE_MISCOPTIONS2 Ember bits are not used.

Wire Protocol

EPX uses opcode 0xF0 on the eMule extended protocol (OP_EMULEPROT). The current version is v4. The payload format:

version       (1 byte, currently 0x04)
file_count    (u16 LE)
  for each file:
    ed2k_hash   (16 bytes)
    file_size   (u64 LE)
    file_flags  (u8, bit 0 = has AICH root hash)
    aich_root   (20 bytes, only present if bit 0 of file_flags is set)
    source_count (u16 LE)
      for each source:
        ipv4      (4 bytes, network order)
        tcp_port  (u16 LE)
        udp_port  (u16 LE)
        flags     (u8, bit 0 = firewalled, bit 1 = obfuscation, bit 2 = relay-capable)
peer_count    (u16 LE)
  for each peer:
    ipv4      (4 bytes, network order)
    tcp_port  (u16 LE)
[optional ERAT trailer]

v4 is layout-identical to v3 for the main body and adds the relay-capable flag bit plus an optional ERAT relay-attestation trailer. v3 parsers ignore unknown flag bits. v3 additions over v2: per-file AICH root hashes for corruption recovery, UDP port and capability flags per source, and a peer discovery section for Ember mesh building. v2 and v3 payloads are still accepted.

ERAT relay attestations

After the peer list, a v4 packet may append a trailer beginning with magic ERAT: version byte, attestation count (max 16), then fixed-size Ed25519-signed entries binding a relay IP/port to an expiry and capability bits. Only cryptographically valid, non-expired attestations (max TTL 30 minutes) become connection-broker relay candidates. The per-source relay-capable flag alone never admits a relay.

Peer-relay QUIC RELAY_REQUEST messages are version 2 and require proof of possession: the requester includes their Ed25519 public key and Ember hash, a fresh nonce, and a signature over the session id, the relay's ERAT attestation hash, target address, and file hash. Legacy hash-only (bearer) requests are rejected. Relays also reject replayed nonces within a short TTL window.

Safety Limits

These caps prevent abuse from poisoned or malicious payloads. Private/reserved IPs and zero-port entries are silently dropped.

LimitValue
Max files per packet200
Max sources per file100
Max payload size64 KB
Max packets per TCP connection3
Max total sources per event2,000

Backward Compatibility

Non-Ember eMule clients silently ignore the 0xF0 opcode — it causes no errors, disconnects, or side effects. EPX is only sent to confirmed Ember peers, and the extension uses a dedicated capability bit so it can never be accidentally triggered.


Friends — Ember-Exclusive Social

Ember includes a built-in friend system that works exclusively between Ember users. It is powered by a separate cryptographic identity called the Ember Hash (also known as your Friend ID), which is distinct from the standard ed2k user_hash used for protocol operations and credits.

How it works

Each Ember client generates a unique 16-byte Ember Hash on first launch. Share a v2 Friend Code (shown on the Friends page) with someone so they can find you on the network. Friend Codes carry the identity needed for privacy-preserving rendezvous lookup without exposing a long-lived raw hash in casual sharing.

Friend discovery is powered by a lightweight rendezvous server. When you connect, Ember registers presence using hashed capabilities (never your raw Friend ID in the clear). When you search for a friend, Ember queries the server and gets back an IP and port for a direct connection. Adding or accepting a friend forces a presence refresh so discovery does not wait on the normal heartbeat interval.

Once a friend is found, Ember opens a direct TCP connection and establishes a Noise IK secure stream with Ed25519 proof-of-possession. After both sides accept the friend request, chat, file browsing, file offers, friends-only shares, and priority uploads unlock on that secured session. When both friends are behind difficult NAT, Ember can still move friend file traffic over the secure session (and optional peer relay) without waiting for HighID.

Ember-only: The friend system is completely invisible to non-Ember clients. It uses a separate identity hash, a dedicated rendezvous server, and dedicated protocol tags that other eMule clients silently ignore.

Features

  • v2 Friend Codes — Share a Friend Code from the Friends page instead of only a raw Friend ID. Codes support privacy-preserving pairwise presence so mutual chat and browse can unlock once both sides have added each other.
  • Mutual Friend Requests — The recipient sees an incoming request on the Friends page and can accept or reject it. Chat, file browsing, offers, and priority upload features only activate once both sides have accepted and a secure friend session is established.
  • Real-Time Online Status — Ember detects when a friend comes online and shows a live online/offline indicator on their card. The Friends page also surfaces when you are not currently discoverable on the rendezvous network.
  • End-to-End Encrypted Chat — Send and receive messages with mutual friends through a slide-out sidebar. After session setup, messages are encrypted end-to-end; the UI shows an Encrypted badge. Outbound messages queue locally and retry when the friend reconnects. See E2E Encryption.
  • Remote File Browsing — Browse a mutual friend’s shared file library while they are online and start downloads directly from the browse results.
  • Friends-Only Shares — Mark Library files as friends-only so they stay out of public search and only mutual friends can request them.
  • Friend File Offers — Push a specific shared file to a mutual friend from the Friends page. Offers appear as actionable notifications the recipient can accept or decline.
  • Friend Transfers Without HighID — Mutual-friend downloads can use the Noise-secured friend session (and optional Ember peer relay) when ordinary HighID or callback paths are unavailable—useful when both sides are behind difficult NAT.
  • Priority Upload Slots — Mutual friends automatically receive priority in your upload queue, giving them faster access to your shared files.
  • Friend Block List — Block a Friend ID so future requests, chat, browse, and offers from that identity are rejected. Existing mutual friendships with that identity are removed when you block.
  • Optional Peer RelayingRelay for other peers (Settings > Network) lets peers who cannot reach each other directly route through you, which is what makes LowID↔LowID transfers work behind strict NATs when attestations allow. It spends your upload bandwidth on people you are not trading with, so you can turn it off.
  • Discoverable Banner — The Friends page shows a confirmation banner when your identity is registered and discoverable, and warns when presence registration failed so friends may not find you.

E2E Encryption

Friend chat is designed so the rendezvous server and any on-path observer never see message plaintext after a secure session is up.

  • Noise IK sessions — Friend connections negotiate a Noise_IK secure stream authenticated with Ed25519 proof-of-possession before chat, browse, offer, and friends-only privileges unlock.
  • End-to-end chat crypto — Message bodies are sealed with XChaCha20-Poly1305 under a key derived from a static X25519 exchange between the two friends’ identity keys. After session setup, plaintext chat fallbacks are rejected. Outbound messages that cannot be delivered stay queued and are retried on reconnect.
  • Encrypted local history — Conversation history is encrypted at rest in the local database, under a key kept beside it. If that key cannot be recovered, history stays sealed and says so rather than failing quietly.
  • Clear UI signals — The chat UI shows an Encrypted badge when the secure channel is active, and reconnect-oriented errors when encryption or the friend session fails.

What the encryption does not cover. The key comes from a static Diffie-Hellman between long-lived identity keys, not a ratchet, so there is no forward secrecy: someone who captures your traffic today and later obtains an identity private key could read those messages. Encryption also protects message bodies only — IP addresses, relationship capabilities, message size and timing stay observable to peers and to on-path services. The in-app chat says the same thing rather than implying more.

Note: EPX source exchange and Ember mesh peer discovery can unlock earlier from HELLO hash↔pubkey binding between Ember peers. Friend privileges (chat, browse, offers, friends-only shares, verified requests) still require a secure friend session / proof-of-possession.

Privacy

The rendezvous server stores presence as hashed capabilities derived from your Friend identity (never the raw Friend ID in the clear), paired with IP and port. Registration is pubkey-bound and signature-checked so entries cannot be spoofed with a stolen hash alone. Entries expire automatically after 5 minutes without a heartbeat. Between Ember peers, the Ember Hash is exchanged via the private OP_EMBER_HELLO / OP_EMBER_HELLOANSWER handshake (with Ed25519 proof-of-possession on TCP) — not via the legacy EmuleInfo path used for ordinary eMule metadata.


Network Compatibility

Ember is a first-class citizen of the eMule network. It implements the full protocol suite required to participate alongside every other eMule-family client.

ProtocolDetails
KAD (Kademlia DHT) KAD v8/v9 for decentralized peer and file discovery, firewall checks, buddy relay for firewalled peers, keyword publishing, and note publishing.
ED2K Servers & Peer Exchange Connect from the ED2K Servers page or optional Auto-Connect Server (last server, else eMule Sunrise). Community server.met lists can be downloaded from emule-security.org. Once connected, servers provide High/Low ID and peer/source exchange.
Credits & SecIdent eMule credit system with RSA-based Secure Identification to prevent credit theft. Upload priority determined by the standard credit ratio formula.
Obfuscation RC4-based TCP and UDP header encryption matching eMule’s implementation, helping with ISP throttling.
AICH Advanced Intelligent Corruption Handling for part-level hash verification and recovery.

Beyond eMule: Ember additionally runs its own Ember Network overlay and the EPX source-exchange extension between Ember peers. Neither is visible to other eMule-family clients, and neither affects the compatibility above.


Port Forwarding

Ember uses two ports for peer communication. Both are configurable in Settings > Network.

PortProtocolPurpose
4662TCPPeer-to-peer file transfers
4672UDPKAD DHT and Ember Network communication (both share this socket)

For best performance (High ID), forward both ports on your router, enable UPnP for automatic mapping, or use STUN port keep-alive when you are behind CGNAT or full-cone NAT without UPnP.

UPnP: When enabled, Ember uses the IGD protocol to automatically request port mappings from your router. This works with most consumer routers and is the easiest path to High ID.

STUN port keep-alive: On by default in Settings > Network. Ember periodically refreshes your NAT mappings with STUN (and a TCP hold from the listen port) and advertises the public ports peers should connect to. It auto-suspends on Open / Symmetric NAT or unstable remapping and falls back to your Settings ports.


High ID vs Low ID

An ID is a value calculated from the client's IP address and assigned by the ED2K server when Ember connects for peer exchange. It indicates whether proper bidirectional communication is possible.

High ID

A High ID means your connection port is open and freely accessible from the internet. Your client is fully reachable by others. This is the optimal state.

Low ID

A Low ID means your connection port is blocked or cannot be reached, typically caused by firewalls, routers, or NAT. Any ID value less than 16,777,216 is considered a Low ID.

Disadvantages of a Low ID

  • Peer Routing — Since your IP is not directly reachable, all requests must be routed through the server, increasing overhead.
  • Reduced Sources — Two Low ID clients cannot connect to each other, leading to fewer available sources.
  • Lost Messages — On busy servers, messages can get lost, causing missed queue progression and slower downloads.

Note: The ID only affects control message exchange. Actual data transfer is still handled client-to-client. If your ID is High, there are no extra advantages to a higher numeric value.

Troubleshooting Low ID

If you're stuck with a Low ID despite correct settings:

  • Verify that ports 4662 (TCP) and 4672 (UDP) are forwarded on your router.
  • Check that your OS firewall allows Ember through on both protocols.
  • Restart Ember to reconnect to the ED2K server.
  • Enable UPnP in Settings > Network for automatic port mapping.
  • Leave STUN port keep-alive enabled (Settings > Network) if you are behind CGNAT or full-cone NAT without UPnP — Ember will try to hold and advertise remapped public ports.
  • If behind symmetric NAT or a VPN that remaps ports unstably, STUN keep-alive suspends automatically; High ID may still require a VPN with a fixed forwarded port or another tunneling solution.

Tech Stack

LayerTechnology
FrontendSvelte 5 + TypeScript + Vite
App ShellTauri v2
BackendRust (2021 edition)
DatabaseSQLite via rusqlite
NetworkingTokio async runtime
Ember Overlay TransportNoise IK / XX over UDP (ChaCha20-Poly1305 + BLAKE2s)
Ember DHTKademlia, 128-bit BLAKE3 node IDs, Ed25519-signed frames
Friend DiscoveryRendezvous server (Axum on Fly.io)
Friend SessionsNoise IK + Ed25519 PoP
Friend Chat CryptoX25519 ECDH + AEAD (E2E)
GeoIPMaxMind DB (dbip-country-lite)

For Developers

Prerequisites

  • Rust (1.94+)
  • Node.js (18+)
  • Windows: Visual Studio Build Tools with C++ workload

Development

# Install dependencies
npm install

# Run in development mode
npm run tauri dev

# Build for production
npm run tauri build

The production build produces NSIS and MSI installers in src-tauri/target/release/bundle/.

Project Structure

DirectoryDescription
src/Svelte frontend (components, stores, views)
src-tauri/src/Rust backend (protocol stack, networking, storage)
src-tauri/Cargo.tomlRust dependencies
docs/This documentation site

Contributing

Ember is licensed under the GPLv3 and welcomes contributions. Visit the GitHub repository to open issues, submit pull requests, or review the codebase.


FAQ

Yes. Ember speaks the same KAD wire protocol as eMule 0.50a and compatible clients (aMule, eMule Xtreme, etc.). It participates in the same network, finds the same sources, and respects the same credit system. Connect to KAD and/or an ED2K server from the app (or enable optional auto-connect in Settings). Ember’s own additions — the Ember Network overlay and the EPX extension — only involve other Ember clients and are silently ignored by everything else.
Use Settings > Backup. Choose a passphrase, create the backup, copy the single .emberbackup file across, then restore it on the new machine from the same screen and restart when prompted. Your user hash, SecIdent keys, upload credits, friends, known files and settings all come across, which is what keeps your standing on the network. The files you share are not in the backup, so copy those separately and re-add the folders in Settings > Library — folders always need re-approving on a new machine. Keep the backup somewhere safe: it contains your private keys, and a lost passphrase cannot be recovered.
It is Ember’s own encrypted peer-to-peer overlay, with its own DHT and no directory server. Ember nodes find each other directly, publish the files they share, and look up download sources over it. You do not set anything up: it is on by default and joins on its own, with no Connect button. It runs alongside KAD and eD2K, so you keep access to the whole eMule network as well. See the Ember Network section.
Because there is no bootstrap server to ask. Ember deliberately ships no seed list and hosts no bootstrap pool — one would hand its operator a list of every participant’s identity and IP. Instead a new node finds its first Ember peers through KAD (via a fixed rendezvous key and Ember peers spotted in ordinary KAD traffic) or through an eD2K transfer with an Ember-capable client. Once it has been online, it remembers up to 200 contacts and can rejoin on its own. So on a fresh install, keep KAD and/or a server available; after that the overlay stands on its own feet.
Probably not. There is no central pool to fetch peers from, so a fresh node fills its routing table on a maintenance cycle and the first connection can take a minute or two. If it stays empty, check that KAD is connected or that you have an ED2K server available — those are how Ember finds its first peers. Ember keeps looking for as long as it is switched on.
EPX (Ember Peer Exchange) is an Ember-exclusive extension that lets Ember peers share source lists with each other, speeding up source discovery. It activates automatically when two Ember clients connect — no configuration needed. It has zero impact on non-Ember clients. It is not the same thing as the Ember Network: EPX is an extra opcode on the eMule wire, while the Ember Network is a separate overlay with its own DHT. Both work independently of each other.
No. ED2K High/Low ID is assigned when Ember connects to an ED2K server and reflects TCP reachability. KAD Open/Firewalled is KAD's independent assessment of UDP reachability. You can have a High ID on ED2K while being Firewalled on KAD if only your TCP port is open but UDP is blocked.
Forward ports 4662 (TCP) and 4672 (UDP) on your router, enable UPnP, or leave STUN port keep-alive on in Settings > Network. Make sure your OS firewall also allows Ember through. On CGNAT or full-cone NAT without UPnP, STUN keep-alive can hold remapped public ports and advertise them for High ID. Symmetric or unstable VPN remapping still often needs a VPN with a fixed forwarded port.
Friends are an Ember-exclusive feature. Share a v2 Friend Code from the Friends page with another Ember user. Ember finds them through its rendezvous server and sends a friend request. Once both sides accept and a secure Noise session is established, mutual friends unlock online status, end-to-end encrypted chat, remote file browsing, friends-only shares, file offers, priority uploads, and transfers that can work without HighID. You can also block a Friend ID to reject future contact. Non-Ember clients do not have a Friend ID / Friend Code and cannot participate.
Yes. Mutual-friend sessions use Noise IK secure streams with Ed25519 proof-of-possession. Chat messages then use static X25519 ECDH + AEAD end-to-end encryption; plaintext chat fallbacks are rejected after session setup. The chat UI shows an Encrypted badge when the secure channel is active. Outbound messages queue until the friend is reachable again, and conversation history is encrypted in the local database. The rendezvous server only helps with discovery — it never sees message plaintext.
Credits reward users who upload. The transferred amount of data determines the credit you are given with a particular client. They are not global — they only apply on the client who granted them. Credits are a major modifier when calculating how fast you advance through other users' upload queues. Ember uses RSA-based Secure Identification (SecIdent) to prevent credit theft.
Currently, official releases are Windows-only (Windows 10/11). However, the underlying stack (Tauri + Rust) is cross-platform, and community builds for other platforms may become available in the future.
Ember checks for a newer version automatically on launch and shows a non-blocking notification when one is available. You can install it in-app with one click — no need to download installers manually — and Ember restarts into the new version. You can also check anytime under Settings > About. Every release is cryptographically signed, and Ember verifies the signature before installing. Updates are also gated by signed security epochs (anti-rollback), so installs only advance when the signed epoch allows it.
Yes. Ember is released under the GNU General Public License v3 (GPLv3). The full source code is available on GitHub. This means anyone can use, modify, and distribute it, but derivative works must also be released under the same license.
No. Ember is a complete ground-up rewrite of the eMule protocol stack in Rust, not a fork or modification of the original C++ codebase. It implements the same protocols from scratch to ensure compatibility while using modern, memory-safe code.

Release History

Every Ember release for Windows, newest first. These are the same notes we publish on GitHub Releases. Ember can also update itself in-app once a signed release is published.

Ember v1.5.3

v1.5.3

What’s New

  • Drag folders onto Ember to share them. Dropping folders on the window used to name what you dropped and then open the folder picker anyway, so dropping five folders still meant choosing one of them by hand. They are shared as they land now, however many you drop at once, and the folder picker accepts more than one selection too. Dropping a file offers to share the folder holding it, since sharing here works a folder at a time. We still ask first in the two cases worth asking about: when a drop would include your user folder, which would offer your documents, desktop and pictures to other users, and when it carries far more folders than anyone means to share in one go
  • The downloads list does more without leaving it. Right-clicking an empty part of the list opens the actions that apply to the whole list: pause, resume, stop or cancel everything, copy every download link, paste a link, clear finished rows, select all, and open your Downloads folder. Selecting rows also puts a Copy Link button next to Cancel, which reads Copy All Links once you have selected more than one
  • Ember search results appear as they are found. We used to hold everything a lookup gathered until the whole search finished, and an Ember lookup deliberately keeps asking further peers rather than stopping early, so on a cold start you watched Kad fill the list while Ember showed nothing until the very end. Results now arrive as they are found, the first one straight away and the rest in batches. A file both networks know about updates the row you already have instead of adding a second one
  • The Ember Network page shows when answers are being cut short. A peer replies to a keyword query with as many records as fit in one packet, which is about five, so a busy word can hold far more than anyone can see. There was no way to tell that apart from a quiet network. The page now counts the answers we had to trim and the records that did not fit
  • Four new figures for judging whether your node is healthy. An estimate of how many nodes are out there, how many of your contacts have actually answered you rather than just been mentioned by somebody else, how far behind republishing is, and how long it has been since any Ember packet arrived. Between them they separate still joining from joined and quiet from stuck

What’s Fixed

We compared Ember’s network against our own Kad implementation, constant for constant, and audited every change made since 1.5.2. Most of what follows is the result. The theme is silent failure: several of these switched a feature off completely and reported nothing.

Before you upgrade
  • Nothing to do. We didn’t touch the library database, so you can move between 1.5.0, 1.5.1, 1.5.2 and 1.5.3 in either direction. 1.5.3 also speaks the same Ember network protocol as 1.5.2, so the two find each other normally while everyone upgrades
Publishing and search
  • Your files stop quietly leaving search. Keyword publishing could switch itself off entirely, and did so after every restart on a well-connected node. Sources kept publishing the whole time, so your files stayed downloadable by anyone who already had the link while their keyword records expired and they disappeared from search. Nothing reported it, because from the inside it looked like there was nothing due
  • Searching your own library returns all of it. When Ember read your own node’s index it applied the limit that exists only because a reply has to fit in one packet, so it offered about five of your files. That bit hardest on a small network, where your node holds much of the index and the local read is most of the search
  • A search result can’t leave a download impossible to finish. In 1.5.2 we made a content hash learned from the network need two publishers to agree before we hold a file to it, and covered the path that finds sources. A hash arriving with a search result took a different route and kept the old rule, so one wrong value still meant a download that failed its final check, reopened every part, and started again forever
  • A popular word can’t be taken over and locked. When a keyword filled up we displaced whichever publisher held the most entries, which reads as fairness until you notice that a publisher identity is a free keypair: an arrival holding nothing always outranked an established publisher, so a few hundred keys could strip a word bare and then keep it. A full word now turns new records away, and no single publisher may hold more than 45 of its 300 entries
  • A full word frees up the moment its records expire. Every limit counts records that are still resident and the tidy-up only ran every five minutes, so a word at its limit turned away genuine records for that long after the records blocking it had already died
The Ember Network
  • What you store for other people survives a restart. We dropped all of it on exit. Replication refills it within the hour and publishers re-announce on their own schedules, so nothing was lost for good, but on a young network, and especially when an update restarts many nodes at once, that leaves a window where content is simply missing. The saved file isn’t trusted: every record goes back in through the ordinary checks
  • Publishing addresses peers that are still there. We cached whole contacts for four hours and never rechecked them, so a publish kept talking to peers the routing table had already dropped. We now look up who is closest at the time we publish
  • A contact that never existed can’t end a lookup early. Contacts arrive unverified, so a peer could answer with an invented address one bit away from what we were looking for, pin the front of the queue, and make every later answer look like no progress. A lookup now only counts a peer that has actually replied
  • Half the background traffic is gone. Records held on other publishers’ behalf were re-sent to twenty peers every hour, which was the single largest thing Ember put on the wire, about double everything else it sends. Re-sending cannot extend a record’s life, because expiry is computed from the publisher’s signed timestamp and every copy is identical. What it genuinely buys is reaching nodes that joined recently, and two hours buys that just as well
  • Changing address doesn’t leave people dialling your old one. Source records carry the address to connect to and were only refreshed on a two-hour cycle, so a DHCP lease change or an ISP reconnect left every record we had placed pointing downloaders at whoever holds that address now
  • Source records expire on their own clock. They borrowed the keyword record’s twenty-four hours. A source names a peer to download from, so it stops being true the moment that peer leaves, while a keyword record stays true whoever is online. Six hours survives two missed refreshes and clears a departed peer four times sooner
  • A node with Kad switched off can tell whether its port is open. Only Kad’s probe could establish it, so an Ember-only node marked every source record it published as firewalled for as long as it ran. That is the safe direction, but it relays connections that never needed relaying and hides exactly the open nodes that make the best relays for everyone else
  • A spoofed address can’t get a real peer’s session dropped. When we had to shed a session both rules picked the wrong one: a peer pushed aside while it was busy looks idle, so it always seemed the right one to drop. Refreshing a peer’s liveness also outlived its session by half, so every scheduled check found a dead session and paid for a fresh handshake
  • Your node paces itself by how big the network is. A node among two hundred peers and a node among two hundred thousand ran identical timers. Ember now estimates the size of the network from how tightly packed its neighbours are and scales what it checks and how often against it
Library
  • Copy All Links copies in the order you are looking at. The button took files in the order they were scanned rather than the order on screen, so sorting by name, size or folder changed the list in front of you and made no difference at all to what landed on the clipboard
Transfers
  • Pause All and Resume All follow the filter box. Stop All and Cancel All already applied to the downloads you could actually see, but these two reached every download regardless. With a filter typed in, two commands sitting in the same menu meant different things by All, and the pair that reached rows you could not see was the dangerous half
  • A long upload stops freezing at 100%. An upload counts the bytes actually sent, and a peer that re-requests data pushes that past the size of the file, routinely and by tens of megabytes over a long session. We trimmed the figure to the file size before it reached the speed calculation, so from that moment every sample looked identical and the row froze: no speed, the counter stuck exactly at the file size, and a status of Complete. One session here carried on serving at over a megabyte a second for another half hour behind a row that said it had finished
Updating
  • Ember tells you when an update handed off to an installer that never ran. Installing ends by launching the installer and exiting, so nothing of ours is left to see whether it started. Our installer isn’t Authenticode-signed yet, which makes every release an unknown program to SmartScreen, and a refusal there is indistinguishable from success from inside Ember: the app closes and nothing happens. The verified installer is now kept on disk and the attempt recorded, so the next launch can see the update didn’t land, say so, and offer to run it
  • That offer survives the routine update check. The check a few seconds after startup wiped the notice, then found the staged version again and offered to download the very same bytes and repeat the hand-off that had just failed, so the feature disabled itself in the exact situation it was built for
  • A staged installer is still held to the rollback floor. Rechecking the signature answers whether these are the bytes we verified, which is a different question from whether that version is still one we will install. A staged build now has to beat the running one, and anything below the floor is deleted rather than offered

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.5.2...v1.5.3

Ember v1.5.2

v1.5.2

What’s New

  • The Ember Network has its own light on the status bar. We only showed it once Kad was up, which made the two look like the same thing. They aren’t. You can now see whether the overlay is running and how many peers it is holding
  • Finished downloads say when their Ember hash was checked. If we verified a completed file against the content hash published on the Ember Network and it matched, the row gets a badge. It only appears when the check actually ran, so a file recovered after a crash, or one with no Ember hash to check against, won’t have it
  • File properties show the Ember content hash next to the ed2k and AICH hashes, so you can see the digest your downloads are checked against
  • The Ember Network page shows what you’re holding for other people. Your node stores records on the network’s behalf and there was no way to see how many. We count only records somebody else published, so the number is what you’re actually contributing rather than your own entries coming back to you

What’s Fixed

Our third audit since 1.4.2, this time seven passes reading in parallel over everything we had changed. It turned up 28 findings. 26 held up and are fixed here; two were our own false alarms.

Before you upgrade
  • Nothing to do. We didn’t touch the library database, so you can move between 1.5.0, 1.5.1 and 1.5.2 in either direction
Friends and the Ember Network
  • Your friend code can’t be used to take over your presence. An ember2: code is meant to be public, and it’s enough to work out where your presence is registered. Anyone holding yours could claim that spot with their own key, so friends looking you up reached a stranger or found nothing at all. One request was enough, and it worked every time. A presence slot now belongs to the identity it was derived from and to nobody else. This one is server-side and already deployed, so 1.5.0 and 1.5.1 are covered too
  • Your node can relay for friends again. We tied the relay offer to Kad being connected, and Kad is off in a default install, so a default install advertised nothing and turned away every friend that tried to use it. Relaying is the one discovery path that works for two friends who share no downloads, which is the case we built it for
  • Relayed transfers survive both ends going quiet. Our 1.5.1 fix kept the second peer’s side of a relay alive and missed the first, so a quiet relayed session was still being closed at thirty seconds. Also server-side, also already deployed
  • A spoofed packet can’t stop a peer reaching you. Someone forging a peer’s address could displace that peer’s half-finished handshake over and over, so when the real reply turned up there was nothing left to match it against and first contact never completed. Both halves of the handshake now survive a forged packet
  • One unverified claim can’t fail a download forever. A single node could assert the content hash for a file and we would enforce it at completion. If the claim was wrong the download failed, found nothing to repair, and started again from the top, indefinitely. A hash we learn from the network now needs two publishers to agree before we hold a file to it
Talking to other clients
  • Obfuscated connections don’t corrupt themselves after a stall. If a peer stopped reading for a minute, the next packet could put part of the previous one back on the wire. It decrypts cleanly at the far end, so nothing looks wrong until the framing has drifted and the connection is finished
  • One byte can’t hold an incoming connection slot. A connection that sent a single byte and then went silent was waited on with no timeout at all. Around thirty-four of those filled the listener and shut out every real peer, upload and port test
  • Source swapping runs with Kad off. Moving a peer from a file it can’t help with to one it can was gated on Kad, even though it only ever deals with ordinary ed2k sources. Nobody running server-only ever saw it work
  • A peer can’t make us hold hundreds of megabytes. We bounded the corruption-recovery buffer by bytes in one download path and by packet count in the other. The one we missed is the path a single-source download takes
Search
  • The name you see is the name you get. Two different rules picked the filename for the results list and the filename written to disk, so a result could show one name and download another
  • Peers send a full page of results. Our budget for how many packets one answer may use was smaller than a single page, so the 1.5.1 fix couldn’t take effect and each peer still returned a slice of what it held
Kad
  • One peer can’t block all publishing on your node. Comments, ratings and source records shared one space with keyword records, and only keyword records could be trimmed to make room. Whichever of the other two filled it first locked the whole store and refused everything else in the meantime: five hours for sources, a full day for comments
  • A refused publish can’t delete somebody else’s records. Our 1.5.1 fix covered new records and not updates to existing ones, so a peer could still make us drop another publisher’s entries to clear space for a record its own limits were about to turn down
Your data
  • An interrupted save doesn’t reset your settings. Replacing a file on Windows sometimes needs the old one moved aside first. In 1.5.1 we taught the identity file to recover from that and left every other file as it was. For settings it meant a launch that looked like a fresh install: every preference back to default and every shared folder gone
  • Approved folders stay approved, and stay yours. The record of which folders Ember may use failed the same way, and it failed open. An empty record looked like a first run, so whatever was sitting at each configured path got approved again without anyone asking you
  • An interrupted save doesn’t lock you out of chat history. The chat key could be left under the set-aside name, and we would then report the history sealed and tell you to restore a backup, with the key sitting right next to the database
  • Backups are never shared, whatever you call them. Our rule for keeping a profile backup out of your shared folders matched the extension exactly, so a file saved as .EmberBackup went straight past it and got indexed and offered to peers like anything else
  • Restoring an old backup can’t stop Ember opening. A chat message that happened to start with the text we use to mark encrypted messages made the upgrade of a pre-1.4 database fail, and then fail again on every launch after that
  • The last saves on exit aren’t skipped. One save finishing at the wrong moment consumed the signal another was waiting on, and the wait that followed ate the time the reputation, source list and server list saves needed
  • Two smaller ones: file permissions on Windows are applied through a handle that can’t be redirected between the check and the change, and the peer credit counters saturate instead of wrapping when a stored value is out of range

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.5.1...v1.5.2

Ember v1.5.1

v1.5.1

What’s Fixed

No new features in this one. It’s our second full audit, read in parallel across the network loop, each eD2K path, Kad, the Ember overlay, storage and security, the command layer, the interface and the rendezvous server. Twenty-two findings held up and all of them are fixed here.

Two of them were costing people something every day. If you run Ember server-only, which is what you have if you’ve never pressed Connect on the Kad page, every reply peers sent you was being thrown away, so queue positions never moved while we kept asking for them. And roughly one in every 250 incoming connections from a stock eMule client was dropped before it started, over a byte we assumed eMule would never send and it turns out picks at random.

Before you upgrade
  • Nothing to do this time. Unlike 1.5.0, we didn’t change your library database, so you can move between 1.5.0 and 1.5.1 freely
Talking to other clients
  • Queue positions update again with Kad off. Replies from peers all arrive on the socket Kad uses: your place in their queue, whether a source is still alive, the answer to the UDP port test, reask relaying for firewalled peers. We discarded the lot whenever Kad wasn’t connected, and we kept sending the questions, so the traffic went out and nothing ever came back. Peers waiting in your queue got no acknowledgement either, and had to fall back or give up
  • eMule clients connect reliably. Our private friend handshake opens with a byte we believed eMule’s obfuscation could never begin with. It can: eMule picks that first byte at random and rules out only three values. Every collision sent an ordinary eMule client into the wrong handshake and dropped the connection, usually after making it wait ten seconds first
  • One peer’s “I don’t have that” doesn’t count against your other downloads. A peer declining one file was marked failed on every file you were getting from it, and any queue position you had just learned went out with it. Peers commonly serve several of your downloads at once, so this cost people working sources
  • Server names show up instead of an address. A server that sent its name in the compact form the eMule protocol also allows wasn’t parsed, so the list kept showing a bare IP for it
Uploads
  • A single peer can’t pin your disk and a CPU core. One small request asked us to hash an entire shared file start to finish, and nothing remembered the answer, so repeating the request cost the same work every time. It needed no upload slot, no queue position and no identity. On a large share a handful of packets could make the app unresponsive for minutes and stall your downloads with it
  • More upload slots on a slow connection. We guaranteed two upload slots where eMule guarantees four, and since the number comes from how fast you’re actually uploading, two slow peers kept it at two. You now serve as many peers as eMule would, and two trickling peers can’t hold your whole upload
Downloads
  • Peers that compress aren’t dropped mid-transfer. When another source finished the part you were working on first, a compressed block already in flight arrived with nothing to match it against, and we treated that as the peer misbehaving, closed the connection, then sat out a cooldown of nearly half an hour before trying again. Nothing is wrong at either end when this happens
  • Invented identities can’t push out real sources. When a file’s source list is full we drop the least valuable entry rather than the oldest. Which entries counted as least valuable depended on a name the sending peer chose, so a peer that made one up for each source it offered could push out sources you had already used, and its replacements were what we wrote to disk for next time
  • Repeated junk sources don’t displace working ones. A firewalled source offered with an id of zero can never be contacted, and zero was the one value our duplicate check couldn’t recognise, so the same packet sent again added another dead entry every time
  • A peer can’t make us hold hundreds of megabytes. While waiting for a corruption-recovery answer we set aside a fixed number of packets regardless of how large they were, and a peer could inflate them on purpose
Search
  • Each peer contributes everything it holds. Asking a peer for another page of results was meant to happen once it had sent a full page, but we compared a single network packet against the size of a whole page, and a page always arrives split across many packets. No peer was ever asked for a second page, so popular keywords returned only the first slice of what each one actually had
Friends and the Ember Network
  • Relayed transfers survive a quiet moment. When both sides are firewalled, traffic can go through the rendezvous server. A relayed connection that went quiet for thirty seconds was closed by the layer underneath even though the relay itself allows three minutes, and quiet is normal here: a peer parked in an upload queue says nothing for close to half an hour. This is a server-side fix and is already deployed, so it applies to 1.5.0 too
  • Kad storage can’t be filled by one peer. Comments and ratings published to your node had no per-publisher limit at all, so one peer could fill the space shared with keyword and source records. After that no new source could be stored, and honest keyword records were discarded to make room. Separately, a peer whose own record was about to be refused could still make us delete somebody else’s to clear space for it
Your data
  • An unexpected exit doesn’t discard the session. Our save-on-exit sequence ran against a deadline set forty-five seconds after launch. If the app closed any way other than being asked to, that deadline was long gone and every step was skipped: peer list, library checkpoint, credits, reputation, server list. The log blamed a slow disk. The library checkpoint on its own is what saves you re-hashing your whole share on the next start
  • Your identity survives an interrupted save. Replacing a file on Windows sometimes needs the old one moved aside first, and if the app died in that instant the only copy was left under a name nothing ever looked for again. For the identity file that meant the next launch generated a brand new one, silently resetting your Kad id, your friendships and your credit with every peer
  • A locked settings file doesn’t unapprove your folders. If we couldn’t read the record of which folders Ember may use at startup, and a backup tool or antivirus holding it open is enough for that, we treated it as damaged and replaced it with an empty one. Every shared folder and your download folder then had to be re-approved by hand
  • Backups are never shared to the network. Saving a profile backup into one of your shared folders got it indexed, hashed and offered to other peers like any other file. It holds your keys, so it should never have been publishable, however strong the passphrase
  • Two exports at once can’t destroy a backup. Starting a second export to the same file before the first finished interleaved the two and reported success, leaving a backup no passphrase could ever open where a good one used to be
  • The brief hitch every few minutes while we wrote the Ember peer list to disk is gone, and a slow save no longer eats into the time the other saves have

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.5.0...v1.5.1

Ember v1.5.0

v1.5.0

Our first full read-only audit of the app, plus the work that was prepared for 1.4.1. There is no 1.4.1 release; all of it ships here instead.

The headline is a bug that had been in 1.4.0 from the start: no file larger than 4 GiB could be downloaded at all. Most of the rest you had no way of seeing from outside the app. Uploads capped at a tenth of their limit, friends unable to find you, a source exchange that never answered, and several paths that failed without leaving a trace.

Before you upgrade
  • This release upgrades your library database, and 1.4.0 can’t open it afterwards. The upgrade is automatic and keeps your data, but it only goes one way. If you want the option of going back to 1.4.0, copy your Ember data folder somewhere safe before you install

What’s New

  • Diagnostics on the Ember Network page. Counters for source exchanges, how many offered sources we use versus filter out, replies too large for UDP, and storage rejections. Every one of them covers a path that used to fail without saying anything

What’s Fixed

Downloads
  • Files larger than 4 GiB download again. We rejected the very first block of data every source sent for a large file, because we believed the packet couldn’t describe a position that far in. Every source disconnected immediately and the download never started. Nothing above 4 GiB could be fetched from anyone, eMule or Ember
  • Less re-downloading after corruption. When a peer asked us to help pinpoint which small piece of a part was damaged, we built the answer wrong for most file sizes and it was rejected. That peer then had to fetch the whole 9 MB part again instead of the 180 KB block that was actually bad
  • Damaged archives salvage what they can. A single unreadable entry threw away the entire recovery, including everything already checked and rescued
  • Finished parts are on disk before we trust them. A part could be recorded as verified while its data was still only in memory. A power cut at that moment left us convinced the data was good, and we would then serve it to other peers
  • Progress doesn’t jump backwards. The bar could drop by a whole part near the end while the last piece waited to be checked
Uploads and sharing
  • Uploads aren’t stuck at a tenth of your limit. Upload Speed Sense briefly lowers your upload to measure a quiet connection before it starts managing speed. If it couldn’t find a peer to measure against, which is the normal case with Kad disabled, a failed bootstrap, or a restrictive router, it never finished measuring and stayed there for the whole session. Nothing in the interface said so
  • Your credit with other peers survives a restart. Credit earned by uploading was reset the first time each peer verified itself after we restarted, costing you the queue position you had built up
  • Credit is harder to steal. Our protection against a stranger claiming another peer’s identity to inherit their credit could never actually fire. Separately, anyone who knew a peer’s identifier could strip that peer’s standing by failing a single check on their behalf
  • Large libraries scan without stalling the app. We matched each finished file by scanning every file already indexed, which on a big share held up uploads and the interface for the length of the scan. Watching offline network shares doesn’t block the window any more either
Search
  • Nobody else can rename your download. When several peers answered for the same file we kept the longest name offered. Anyone can pad a name, so a single peer could rename a file in the results, and since that name is what we save the download as, on your disk too. The name most peers agree on now wins
  • Inflated results sink. A peer claiming an impossible number of sources sorted above every honest result
  • Turning Ember on takes effect immediately. Enabling the Ember Network from its own page left Search still convinced it was off, refusing Ember searches until you restarted the app
  • Searches find more. A popular file is held by many peers, and every copy it returned used one of the 300 result slots. Copies are counted once now, so a common file doesn’t crowd out everything else
Friends and the Ember Network
  • Friends can find you again. Registration with the rendezvous server restarted every ten seconds and threw away its own result each time, so it never completed. For most setups that meant you were never discoverable, friend transfers couldn’t start, and we re-registered forever
  • UDP source exchanges get answered. We built the reply for a connection where size isn’t limited, so on any client with a real download list it was too big to send and got dropped. It’s built to fit now, and sends fewer files rather than nothing
  • Your own address isn’t accepted back. Sources travel peer to peer, so one eventually came back pointing at you and left a download trying to connect to itself
  • Relay offers are charged to whoever sent them. A single peer could fill the relay list with entries it made up and push out relays learned elsewhere
  • A missed reply isn’t the end. A peer that failed to answer once was dropped from that search for good, and one lost packet is enough to cause it
  • Known-good peers stay known-good. Peers that had answered were pushed aside by ones we had merely heard about, so the connections actually in use went stale and were dropped
  • Downloads can’t be misdirected. Any peer could publish a false fingerprint for a file. We would finish the download, find it didn’t match, find nothing actually wrong with it, and start over from scratch, forever. Fingerprints now need agreement from several peers, and they never override one we worked out ourselves
Network protection
  • Ember isn’t usable as a reflector. Two of our handshakes replied to whoever a packet claimed to come from, with a response larger than the request. Both prove an address is real now before spending anything substantial on it, which also stops one peer being locked out of another’s connection list
  • Flood defences cost less than the flood. The tables protecting against packet floods searched tens of thousands of entries per packet, and chose the busiest peer to forget, which let an attacker reset the very limit meant to catch it. One tracker grew without limit
  • Shared storage can’t be monopolised. A single peer could fill the space we offer the network and lock out every honest publisher for a day, and could sidestep its own quota by changing port
  • A stalled server can’t wedge reconnection. A server that answered slowly but never finished logging in could hold us on “Connecting” for close to an hour with no fallback
Files, folders and updates
  • Changing a folder’s properties doesn’t break downloads. Compressing your download folder, turning off search indexing on it, or a cloud client marking it, all looked identical to the folder being swapped out. We revoked our own access, every download failed, and there was no way to restore it from inside the app. Saving Settings restores it now, and ordinary property changes are ignored
  • Installing an update doesn’t lose progress. The installer shut us down in a way that skipped saving, so every update discarded the resume data for downloads in progress, the library checkpoint that exists to avoid a full re-scan, and the peer and server lists
  • “Up to date” instead of a security warning. If the published release was older than the version installed, every check failed with a warning rather than telling you there was nothing to install
  • Chat day separators stay correct across daylight saving changes, and remote text can’t use invisible characters to disguise how a name reads

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.4.0...v1.5.0

Ember v1.4.0

v1.4.0

The Ember Network beta. 1.4.0 turns on our own encrypted overlay by default, so peers can find each other, publish what they share, and discover download sources without a central directory. File bytes still move over the familiar eD2K path.

What’s New

Ember Network (beta)
  • On by default. The overlay joins on its own. Profiles that still had it switched off from an older default are migrated on, and we tell you if anything was flipped
  • Finding other Ember users. Nodes meet through a well-known KAD rendezvous key, through Ember peers we notice in ordinary KAD traffic, and through eD2K transfers with Ember-capable clients. There is no central bootstrap pool and no seed list shipped in the build
  • Publish and search. Shared files are published so other Ember users can find them, and keyword search and source lookup run on the Ember DHT alongside KAD and servers
  • Downloads still use eD2K. Ember finds the source; the file transfers client to client over eD2K. Keep KAD or servers available so a fresh install can join
  • Ember Network page. Redesigned to show whether you’re connected, whether people can reach you, and whether your shared files are published, with the technical diagnostics kept collapsed
  • A versioned wire format. Incompatible peers refuse each other cleanly instead of looking like packet loss
Library
  • Ember share badges. The Library’s Shared column shows when a file has a live Ember source record

What’s Fixed

  • No full re-hash on every launch. An idle startup doesn’t re-hash the whole library when nothing has changed
  • An audit pass over everything added since 1.3.5: publish, search, store replay limits, table admission, and the edges around them
  • Disabling Ember stops advertising under the rendezvous key, so other nodes don’t spend bridge pings on a peer that won’t answer
  • The developer-only Ember console is out of the shipping build

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.3.5...v1.4.0

Ember v1.3.5

v1.3.5

What’s Fixed

A reliability release, and the result of a full audit. Most of what it fixes was quiet by nature: settings that didn’t apply, messages that were never shown, and a library that could stop indexing without telling you.

Library and sharing
  • One slow file doesn’t empty your library. A file that took more than five minutes to hash cancelled the whole scan and discarded everything not yet indexed, and it happened again on every launch, so files went missing from your share with no explanation. Large files on a network share, an external drive or OneDrive are left for a later attempt now, while the rest of the scan carries on
  • Adding a folder can’t wedge. A file whose read never returned could hold the scan lock for the rest of the session, blocking every later folder add or reload and delaying shutdown. That wait doesn’t hold the lock any more
  • Copy All Links on large libraries. Copying every link failed outright above 50,000 files. It’s sent in batches now
  • Accurate scan warnings. The “only the first 100,000 files were indexed” notice appeared on ordinary reloads of any large folder. It only shows up when the limit was actually hit
  • Excluded files stay excluded. Part-finished downloads, our own temporary and backup files, and anything inside the Ember data folder could come back into your share through the known-files list
  • Failures are visible. When the library failed to load, we rendered an empty library with an invitation to add a folder. It reports the error now
Friends and chat
  • Privacy toggles take effect. Turning off incoming chat or browsing did nothing at all if the save failed: the switch stayed on and the setting never reached the network. The switch reverts now, and you get told
  • No more missing messages. Sending the same text twice in quick succession delivered both and showed one, and the second stayed invisible until you reopened the conversation
  • Queued messages reach their friend. A message typed while a friend was offline could stay marked queued indefinitely after they came back, if the reconnect reused a connection that was already open
  • Abandoned messages say so. A queued message we’ve given up on shows as failed instead of reading “queued” for the rest of the session
  • Unread badges while minimised. Messages that arrived with the window minimised were marked read and raised no badge, so they were easy to miss entirely
  • Browsing a friend. A friend sharing two copies of one file could blank the browse window
Transfers
  • Archive recovery works again on large files. Recovery of a part-finished archive ran out of time before it began on anything multi-gigabyte. Those are the files people actually want it for
  • Lighter Known Clients tab. Trust badges issued one lookup per credit record every few seconds, which on a mature client list meant thousands at once and could crowd out other work
Search
  • Preferences are saved. Search method, filters, sort order and column choices were never written to disk and reset on every launch
  • Stop actually stops. Results kept arriving in a search that had been stopped, and a stop that failed to reach the network said nothing
  • Held Enter. Holding or repeatedly pressing Enter opened an unbounded number of searches and tabs
  • A failed notes lookup was indistinguishable from a file that genuinely has none
Settings
  • Unsaved changes are protected. Clicking away to another page discarded pending edits without asking
  • Empty number fields. Clearing a box and saving stored that field’s factory default, including the listening ports, and could prompt a restart for a change you never made
  • Choosing a language. Arrow keys committed a language and restarted the app mid-selection, so you couldn’t browse the list from the keyboard
  • Bandwidth fields. After typing in a speed box, Apply Recommended and Discard didn’t update what was shown, so the value saved wasn’t the value on screen
Security
  • Fail closed on durable state. Closes silent data loss from unsaved transfers, mixed backup restores and chat that vanished after a reload, and bounds resource exhaustion in rendezvous admission, relays and oversized friend requests
  • Stricter URL checks. Our rejection of credentials embedded in a URL could be sidestepped by leaving out the slashes after https:, which would let a download link display a trusted host while fetching from somewhere else. IPv6 addresses are handled properly again too
  • Deep links. An ed2k:// link that failed once stopped every later link from being handled for the rest of the session. The confirmation prompt also shows the file name, size and hash on separate lines rather than running them together
  • Archive recovery limits. A deliberately crafted archive could keep recovery scanning past its own time limit and ignore a cancel
  • Relay stability. Live relay sessions were torn down by ordinary congestion instead of waiting for it to clear
Smaller things
  • Two crashes that blanked a page outright: repeated lines in the server log, and duplicate entries in a friend’s file list
  • Error notifications appeared behind the dialog whose failure they were reporting, so the message was invisible at the moment it mattered
  • The “TCP port already in use” warning disappeared a few seconds after appearing, while uploads stayed broken
  • The update notice did nothing once an update had downloaded or failed, leaving the banner on screen until restart
  • A security notice was unreadable in the light theme, and several error messages ended in the word “undefined”
  • Re-selecting a played audio or video file restarted it from the beginning without being asked
  • A folder priority we had rejected stayed on screen as though it had been applied

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.3.4...v1.3.5

Ember v1.3.4

v1.3.4

What’s New

Backup and restore
  • Move Ember to a new PC. Settings > Backup writes your whole profile to one passphrase-encrypted .emberbackup file and restores it on another machine or after a reinstall. Your identity, secure-identification keys and upload credits come across, so your standing on the network survives the move
  • What it covers. Identity and SecIdent keys, credits, settings, the shared-folder list, known files, friends, chat history, the transfer list, server and KAD contacts, the IP filter, and learned spam data. The files you share and part-finished downloads stay out, so the backup stays small
  • Always encrypted. The archive holds your private keys, so a passphrase is required rather than optional, and Windows-bound key material is re-wrapped for whichever account restores it. A lost passphrase can’t be recovered
  • Safe restores. A restore is prepared immediately and applied while Ember next starts, because the files it replaces are in use while Ember runs. We keep the replaced originals in a pre-restore folder, and you can discard a pending restore before it’s applied
Transfers
  • Stop All and Cancel All. Both sit beside Pause All and Resume All in the toolbar’s More menu. With the Filter box narrowed they act only on the downloads you can see, and the confirmation says which filter it matched
  • Bulk actions on finished downloads. Completed and failed rows can be selected like active ones and removed together, instead of one right-click at a time. Your files are kept; only the list entries go
  • Clearer selection. Each bulk button reports how many rows it would affect and greys out when none apply, so a mixed selection can’t silently do nothing
Search
  • Copy eD2K links for one result, for every ticked result, or for the whole list at once, from the right-click menu, the selection bar, or Ctrl+C. No need to start a download just to get its link

What’s Fixed

  • We stopped looking like an eMule that misreports its version. Our MuleInfo packet carried a real version byte where eMule expects a sentinel, which is what anti-leecher mods treat as a spoofed client, and it could cost you upload slots or credit score

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.3.3...v1.3.4

Ember v1.3.3

v1.3.3

What’s New

Friends
  • Friends-only shares. Mark Library files as friends-only so they stay out of public search and only mutual friends can request them. Non-friends are refused at the protocol layer
  • Friend file offers. Push a specific shared file to a mutual friend from the Friends page. Offers arrive as notifications the recipient can accept or decline, with rate limits and expiry
  • Friend transfers without HighID. Mutual-friend downloads can use the Noise-secured friend session when ordinary HighID or callback paths aren’t available. We can also discover optional peer relays through friend gossip for harder NAT cases
  • Friend block list. Block a Friend ID and future requests, chat, browse and offers from that identity are rejected. Blocking also removes any existing mutual friendship with it
  • Durable offline chat queue. Outbound friend messages stay queued across reconnects and app restarts, then retry when the friend session is back. Undeliverable messages surface as failed instead of hanging forever
  • Knowing when you’re reachable. The Friends page warns when you aren’t currently discoverable on the rendezvous network, and a friend card can show when a peer is online but not reachable for a direct connection
  • Optional friend relaying. Help friends connect (Settings) controls whether you advertise willingness to assist LowID↔LowID paths. Turn it off if you’d rather not relay for other people
  • Friend chat polish. Clearer conversation grouping, day separators, and tab scrolling in the chat dock

What’s Fixed

  • Friends-only share flags survive Library rescans and resume paths, and are enforced for downloads already in progress rather than only fresh requests
  • Friend relay discovery works in both directions on secure friend sessions, with safer candidate caps and clearer failure attribution, so we don’t drop a good relay because the far side refused
  • Friend file offers are harder to spam, and friend-connect hints don’t mis-attribute progress to the wrong peer

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.3.2...v1.3.3

Ember v1.3.2

v1.3.2

What’s New

Friends
  • Friend cards redesigned. One compact row per friend, presence shown once, and the secondary actions (Browse, Reconnect, Copy Friend ID, Remove) collected in an overflow menu with the Friend ID and last address
  • Friend browse redesigned. Download controls are clearly visible, and a filter box narrows a large shared library
  • Fewer interruptions. No toast when a friend comes online or goes offline, since the card already shows it. Actionable notices, like a friend being behind a firewall or needing a newer Ember, still appear
Diagnostics
  • Panics are written to ember.log, so a crash during startup records its cause instead of closing silently
Transfers and statistics
  • Known Clients shows a friend’s nickname, last address, country and last-seen, instead of just a name
Interface
  • Fits laptop screens. The sidebar auto-collapses on narrower windows, the status bar and Transfers columns compact, and the Library folder drawer overlays instead of squeezing the file table. 4K layouts are unchanged
  • The default window is 1400×900, so the app fits without scrolling on a 16″ laptop
  • Unread chats show a blue dot rather than an orange count
  • KAD page: we removed the redundant Ember peers and EPX sources tiles. Both are still in the status bar

What’s Fixed

  • Ember starts when a shared or download folder’s filesystem identity has changed, for example a folder that was deleted and recreated, or a re-imaged drive. We revoke the affected folder instead, and you can re-approve it from Settings, so a stale record can’t keep the app from launching
  • Unreadable folder-approval state is quarantined instead of being treated as fatal
  • Friend downloads reconnect after both clients restart. A rediscovered friend’s address is reseeded into your existing download sources
  • Statistics: File Requests protocol overhead is measured now. It used to always read zero

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.3.1...v1.3.2

Ember v1.3.1

v1.3.1

What’s Fixed

Friends
  • One-sided Add Friend when both peers are online. Friend-code intro presence lets you find someone before mutual pairwise capabilities exist
  • Adding or accepting a friend forces a rendezvous presence refresh, so discovery doesn’t wait about two minutes
  • Clearer “not found” messaging when the peer is offline or still needs to add you back
Ember and EPX
  • EPX and Ember mesh peer discovery unlock on the HELLO hash↔pubkey binding. Legacy proof-of-possession is disabled and was blocking the status bar EPX count and the KAD Ember peer count
  • Friend privileges (chat, browse, verified requests) still need a secure friend session or PoP

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.3.0...v1.3.1

Ember v1.3.0

v1.3.0

What’s New

A security and Friends release: end-to-end friend chat, hardened sessions and updater, safer file opens, and a batch of Library, EPX and connectivity fixes since 1.2.3. Please tell us if anything here misbehaves.

  • Friend chat is end-to-end encrypted (static X25519 ECDH plus AEAD), and plaintext chat fallbacks are rejected once a session is set up
  • Chat shows an Encrypted badge, and errors point you at reconnecting when encryption fails
  • Friend sessions use Noise IK secure streams, with chat history encrypted in the local database
  • v2 Friend Codes and privacy-preserving rendezvous capabilities (pairwise presence). The Friends page explains how mutual chat and browse unlock
  • A signed anti-rollback updater with security epochs. An install only advances when the signed epoch allows it
  • Deep links need confirming before they open, and you can review a pending link later
  • Dragging a folder into Library asks you to confirm in a system folder picker before sharing it
  • Queued downloads over the safety budget are quarantined rather than deleted, with a notice in the app
  • A corrupted or unreadable ban–reputation policy prompts an explicit acknowledge and reset before networking continues
  • The default window is 1920×1200 on first launch
  • The updater treats a missing manifest or signature (HTTP 404) as “no update”, so a check doesn’t fail while release assets are still uploading
  • The first-run and Settings IP filter download uses the live ipfilter.zip mirror, the same one Security uses, and remembers the enable preference

What’s Fixed

Library and media
  • Library activity, collections, media playback and bulk actions persist and clear busy state correctly
  • Media serve doesn’t reopen files by path after approval, which was a TOCTOU. Reads stay on the approved handle
Friends, EPX and transfers
  • EmuleInfo no longer clears Ember identity during EPX auth
  • AICH trust is scoped to the local file hash, and AICH upload requests use the pinned open handle
  • Oversized UDP exchanges are refused, ERAT trailer space is reserved, and UDP ingest is rate-limited
  • Attestation expiry is honored, reserved EPX versions are rejected, and mesh discovery requires PoP
  • Friend and Ember upload-queue priority flags reset correctly across sessions, so there’s no sticky queue boost
  • Archive recovery hashing opens the recovery file handle-safe instead of reopening by path
  • Upload and completion paths pin approved handles so a path-swap race can’t slip through
Connectivity and rendezvous
  • NAT TCP mappings are discovered over TCP instead of inferred from UDP STUN readings
  • Friend punch doesn’t fail open on legacy proof v3 during v4 sessions, and rendezvous filters legacy entries on v4 polls
  • Mailbox delivery is page-cached with idempotent replay, so a crash mid-page can’t permanently skip messages
  • Rendezvous and friend flows stay compatible across protocol v3 and v4 without breaking stock eMule traffic
Updater, deep links and setup
  • Install stays offered when a verified pending update is retained after the native updater clears pending state
  • Deferred deep links survive handler remounts without reopening twice
  • Windows shared-folder prepare doesn’t delete an opened directory entry on a path or type mismatch
  • Added the missing translation for invalid terminal deep links (deeplink_terminal_invalid)

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.2.3...v1.3.0

Ember v1.2.3

v1.2.3

What’s New

A connectivity fix for STUN and NATMAP keep-alive: we advertise the remapped public TCP port again, and a LowID session reconnects so the eD2k server learns it. Please tell us if anything here misbehaves.

  • When STUN keep-alive confirms a remapped public TCP port while you’re still LowID, we reconnect to the eD2k server, with a 60-second cooldown, so it can retry HighID connect-back with the corrected port

What’s Fixed

  • STUN keep-alive advertises the twin-probe’s public TCP port again, gated on stability (corroborated immediately, or after two matching readings), instead of always mirroring the configured listen port. HighID and public port status can improve behind full-cone NAT and CGNAT
  • A remapped TCP port discovered after login isn’t left unused on an already-connected LowID session

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.2.2...v1.2.3

Ember v1.2.2

v1.2.2

What’s New

A reliability release: Library sharing and large-collection workflows, download source counting, Settings save hangs, relay and friend connects, and KAD publish validation.

  • Library warns clearly when a shared folder hits the 100,000-file per-folder indexing cap
  • Settings and Security report whether saves, nodes.dat and IP filter updates were applied live, deferred, or need a restart
  • Collection create and load use native OS dialogs, so exports aren’t forced into shared or download folders
  • ed2k:// links and collection opens are persisted until they’re handled, so they survive relaunches and setup-wizard restarts

What’s Fixed

Library
  • Stale pending share and priority intents don’t silently re-share or flip priority after a rehash
  • Share, unshare and priority changes persist more safely, with rollback, and apply hash-wide across identical copies
  • Bulk share, unshare and priority actions work on large selections (batched IPC)
  • Remove missing keeps clearing until the scan has actually finished, so no missing rows are left over after the 10k batch limit
  • Large collections: Download All queues in chunks instead of failing wholesale, with skip, oversize and failure feedback
  • Top Uploads de-dupes by hash, shows total uploaded, and explains unattributed older history when only aggregate totals exist
  • Keyboard shortcuts work again with the collections panel open, and are blocked correctly during stop-hash confirmation
  • In-app media playback uses a scoped ember-media protocol that re-checks shared and download roots per request
  • Duplicate library copies don’t force unnecessary rehashes of non-canonical paths
Downloads and sources
  • Ephemeral callback and push-grant ports are session-only, so they don’t inflate per-download source counts across relaunches
  • Resume and reasks prefer dialable listening ports and skip undialable ephemerals
  • Max download file size is aligned to the ED2K wire limit (593 GiB), and large-file part-count and hashset handling doesn’t truncate into bogus values
  • MultiPacket parsing is more tolerant of peer extended-request variants
Sharing and settings
  • Saving Settings doesn’t hang behind long library hashes and scans when shared folders change; folder reconcile runs in the background
  • Removing a shared folder cancels in-progress scans under that root sooner
  • Clearer save and download messaging when a live network apply has to wait for a restart
Relay, rendezvous and friends
  • Friend relay tickets hardened (v3 candidate polling, quota and reservation cleanup, legacy v2 cursor sweep) for more reliable LowID friend connects
  • Browse friend cancels and correlates by request ID, so stale or swapped results don’t land in the wrong dialog
  • Friend sessions close and evict cleanly, and relay tickets are limited to manually known friends
  • STUN keep-alive doesn’t override your configured TCP listen port in Hello and advertising. The UDP mapping stays UDP-only
KAD and protocol
  • KAD keyword publishes without a filename, size or tags are rejected, so there’s no more empty junk served back to searchers
  • Published source entries with UDP port 0 fall back to the packet’s real source port, which is what eMule does
  • Safer .part.met save-path guard cleanup after a download is removed
Search and UI
  • Backspace doesn’t delete a hovered saved search. Only Delete removes recent entries
  • Deep-link handling doesn’t double-apply or drop links across restarts and HMR
  • The setup wizard reports deferred or failed live apply for nodes.dat and the IP filter more clearly
  • Library table rows support Enter and Space activation, and we filled assorted i18n gaps

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.2.1...v1.2.2

Ember v1.2.1

v1.2.1

What’s New

Connectivity and Library quality of life: STUN and NATMAP port keep-alive for CGNAT and cone NATs, a Simplified Chinese interface, and a few Library and chat fixes.

Network and HighID
  • STUN port keep-alive (Settings, on by default) keeps NAT mappings alive with periodic STUN plus a TCP hold from your listen port, and advertises the discovered public TCP and UDP ports for HighID. Useful behind CGNAT or full-cone NAT without UPnP
  • It auto-suspends on Open or Symmetric NAT, or on unstable port remapping, then falls back to your Settings ports
  • Home status shows when keep-alive is active and which public ports are being advertised
Library
  • Copy all eD2K links for the current Library view in one shot, as a single IPC batch, so it works on large libraries
Localization
  • Simplified Chinese (zh-CN), including the Settings picker and system-language detection (zh and zh-Hans map to zh-CN)

What’s Fixed

  • Library Missing stays greyed out until a scan actually finds missing files
  • Closing an active chat tab doesn’t resurrect its wiped draft when you reopen a chat later
  • The rendezvous-server Docker image builds again; the Rust toolchain pin is aligned with rust-version

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.2.0...v1.2.1

Ember v1.2.0

v1.2.0

Stability and accuracy across transfers, search, KAD, Security and Statistics, Settings and Library.

What’s New

  • Internal protocol knobs and the rendezvous URL are out of the Settings interface
  • Friend session encryption is always on
  • The misleading obfuscation “Restart” badge is gone
  • Incremental auto_vacuum is enabled on the database (schema v21)
  • i18n updates across en, de, es, fr and pt-BR

What’s Fixed

Downloads and uploads
  • A final hash failure can be retried instead of staying permanently failed
  • Stop doesn’t race into a false Failed state
  • Disk space checks use remaining bytes, so a large near-done resume doesn’t false-flag Insufficient
  • Uploads end on unique coverage, and soft rejects preserve queue seniority
  • Pause and cancel teardown, and concurrent-slot promotion, hardened
  • Better soft disk probe and startup hash timeout behavior
Sources and discovery
  • Soft-dropped peers can re-inject, and LowID callbacks flush for active downloads
  • Pause and resume reseed from per-file sources, and pause-offline source rows stay visible
  • Source counts and offer tracking corrected
Search
  • Cancel and KAD keyword results are preserved across capacity eviction
  • Hardened filters, notes, source safety, download gating and spam overrides
  • Fixed Clear Results and bulk UX races, and improved method-specific search hints
KAD and network
  • A fail-closed IP filter doesn’t block KAD bootstrap or routing-table admission while ranges load
  • A quiet KAD timeout doesn’t tear down eD2K
  • Fixed eD2K reconnect and the related filter side effects
  • The server list and routing table aren’t wiped during a filter load
Security and Statistics
  • The IP filter Hits column tracks per-range blocks, not only the header total
  • ranges_ready is shown, enable refresh and poll work, and fail-closed load failures are visible
  • KAD upload overhead and status-ping wire bytes are counted correctly
  • Fake overhead estimates are gone, and uptime, ratio and locale formatting are cleaned up
Library and Settings
  • The Library Peers column updates live, clears when peers drop, and counts complete copies and KAD publish acks only
Friends and UI
  • Friend connect slots and firewall rules clear correctly, and the settings toggles work
  • The source drawer empty state is authoritative, plus minor search and transfers polish

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.8...v1.2.0

Ember v1.1.8

v1.1.8

What’s Fixed

Startup and connectivity
  • Heavy network startup I/O (UPnP, ipfilter, known.met, GeoIP) is deferred so splash IPC stays responsive
  • The IP filter fails closed until ranges finish loading, so peers can’t slip through an empty enabled list
  • Fixed HighID port-test and firewall sticky LowID, preferred-server auto-connect, and auto-ban edge cases
Transfers and bandwidth
  • Upload Speed Sense requires an upload limit, and we fixed RTT throttling and the single-sample USS ratchet
  • Cancelled downloads don’t briefly flash red
Persistence and sharing
  • Fixed silent friend loss, disk-full state wipes, settings resets, orphaned KAD searches, and share and indexer leaks
  • Hardened the related UI races and the friend-connect proof-of-possession test mocks

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.7...v1.1.8

Ember v1.1.7

v1.1.7

What’s New

Search
  • Global, Server and KAD search line up more closely with eMule: UDP eligibility and reply auth, Arc/Iso→Pro wire types, KAD AND stripping, availability merge, and stop-cap accounting
  • We request more server results (OP_QUERY_MORE) automatically when a page is full, up to the eMule-style limits
  • Shared and downloading files are skipped when counting toward the ed2k search stop limit. The results still appear
  • Hide spam moved into Advanced Filters, and the empty-server “retry” banner is gone
Uploads
  • HighID waiting peers are dialled to grant upload slots (AddUpNextClient / push-grant), with concurrency and backoff limits
  • Soft-zone admission judges newcomers by credit and file priority instead of a zero-wait score
Downloads and transfers
  • KAD, TCP and UDP source discovery start for queued and add-paused downloads, so sources are ready when you resume
  • Resume All includes Stopped downloads
  • Pause All, Resume All and Clear Completed are collapsed into a More menu, which closes on Escape and on an outside click
Library and status
  • Redesigned Library detail drawer, with sections, missing and hashing banners, and context Properties
  • Total shared size sits next to the shared-file count in the status bar
  • Better missing-file scan feedback and bulk selection toasts
Statistics
  • Completed Uploads counts only when a peer received the entire file in that session
  • Cumulative counters don’t roll backward across save races, zero durations show as 0s, and empty overhead bars are hidden

What’s Fixed

Connectivity and firewall
  • Reconnect backoff and per-server cooldowns are honored, and LowID stays sticky against a false “Open” from UPnP
  • Mid-session OP_IDCHANGE (LowID to HighID) is handled without a full disconnect where possible
  • A known Open or Firewalled status is preferred over a stale Unknown in the interface
Transfers
  • Batch cancel always removes the database rows, so cancelled downloads don’t resurrect after a restart
  • Spam-filter saves are serialized to avoid lost or out-of-order writes
Installer
  • The desktop shortcut isn’t recreated during in-app updates (/UPDATE), which was making duplicate desktop icons

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.6...v1.1.7

Ember v1.1.6

v1.1.6

What’s New

Library
  • An in-app media player for playable audio and video
  • Playable files open from the detail drawer, with Open Externally still there
Search
  • Polished the search tab stop and close controls
  • KAD store, search and verify paths line up more closely with eMule: wire publisher IDs, verified contact seeding after a cold start, legacy Hello challenges, and dropping oversized KadRes

What’s Fixed

Security and trust
  • Peer-relay (ERAT) requests require Ed25519 proof-of-possession, and legacy hash-only RELAY_REQUEST payloads are rejected
  • EPX trust hardened: PoP required on TCP source exchange, KAD Noise keys pinned, and ERAT TTL handling aligned
  • Bare-nonce Ember auth is gone in favor of domain-separated signed auth only
  • IP filtering hardened: the live filter is kept during an async reload or enable, we fail closed on reload errors, always reject bogus inbound TCP, and honor block_private on source inject paths
Downloads and sources
  • IP filter, ban and reputation checks are unified across dial and inject paths
  • Insufficient-space downloads are kept across a restart
  • Mid-download disk-full is classified as insufficient space instead of a generic failure
  • Friend-related and settings hot-reload fixes from the audit pass: live friend toggles, browse and chat gates, and nickname, max-sources and filter-server updates without restart noise

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.5...v1.1.6

Ember v1.1.5

v1.1.5

What’s New

Languages
  • French, Brazilian Portuguese and German interface translations
  • Country flags on the Settings language picker cards
Dependencies
  • Frontend stack updated (Vite 8, SvelteKit, TypeScript 5.9, Tauri JS packages)
  • Rust crates updated, including rusqlite, reqwest, directories, lofty and zip, with the lockfile refreshes that go with them
  • Rust MSRV raised to 1.94 for the newer crate requirements

What’s Fixed

  • Removed duplicate search_bitrate_value keys from the English, Spanish and French catalogs

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.4...v1.1.5

Ember v1.1.4

v1.1.4

If you’re on 1.1.3, this is the one to install. 1.1.3 migrated the database on first launch and then refused to open it again.

What’s New

  • A link to the Ember website from the About dialog and Settings → About

What’s Fixed

  • Fixed the schema version gate so Ember can open databases after the v20 migration (credits.ember_hash). 1.1.3 migrated on first launch, then refused to start on every later launch

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.3...v1.1.4

Ember v1.1.3

v1.1.3

What’s New

  • A row context menu on Known Clients for copy hash, add friend and ban
  • A Release History section on the docs site, with GitHub-style changelogs
  • Expanded .gitignore for runtime data, installer copies and tooling artifacts

What’s Fixed

KAD and eD2K
  • Cleared store, FindBuddy and routing failure modes that could stall discovery and publishing
  • Restored callback peer caps and source-search capacity handling
GeoIP
  • Refreshed the bundled DB-IP country lite database (July 2026)
  • Updated the MaxMind reader dependency
Known Clients
  • Friend markers match on the Ember hash, not only the eD2K user hash
  • The trust badge reflects manual bans
  • Reputation refreshes on each poll, and the friend list keeps the same cadence
Library
  • Stop hashing stays stopped against filesystem-watcher rescans
  • Windows folder filters are case-insensitive
  • KAD and eD2K badges mean published, not merely connected
  • The missing-file scan reports when results are truncated
Statistics
  • Session and connection time use monotonic elapsed time, so a clock jump can’t affect them
  • Download completions are counted only after the transfer is confirmed complete
  • Status bar and protocol-overhead labels match their real scopes (payload, session)
  • The transfer-stats cache refreshes every second, and session versus all-time upload ratio is clearer

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.2...v1.1.3

Ember v1.1.2

v1.1.2

What’s Fixed

Search and downloads
  • Search results with a file hash but no embedded peer IPs can be downloaded again; the backend discovers the sources
  • Batch cancel doesn’t fail the interface after transfers are already cancelled. An incomplete teardown retains the partials and logs a warning
Sharing and settings
  • Overlapping shared folders from older configs are soft-deduped on upgrade instead of resetting all your settings
  • A temporarily unavailable shared folder doesn’t block saving unrelated settings
  • Share, unshare and priority updates succeed even if network persistence is briefly busy (best-effort reconcile)
Reliability and compatibility
  • A corrupt known.met keeps the records we already parsed instead of wiping the whole catalog
  • A corrupt ember.db still recreates safely, and now shows a recovery toast with the backup path
  • Ember auth works across mixed versions (transitional bare-nonce emit, dual verify retained)
  • The network command send timeout is longer, which reduces false failures under load
  • A slow KAD ack on a note publish softens to “queued” instead of a hard error

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.1...v1.1.2

Ember v1.1.1

v1.1.1

What’s Fixed

Persistence and transfers
  • Stale persistence can’t write outdated transfer and settings state
  • Fixed a divergence between on-disk progress and the in-app transfer tracker
KAD and networking
  • Dropped KAD work doesn’t silently stall discovery and publish paths
  • Hardened relay networking while keeping eMule-compatible behavior
Frontend
  • Closed state races that could leave the interface out of sync with the backend

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.0...v1.1.1

Ember v1.1.0 Initial Release

v1.1.0

What’s New

Networking
  • Full eMule KAD v8/v9 participation, with automatic Security-server ED2K peer exchange
  • Credits, SecIdent, protocol obfuscation and AICH
  • EPX (Ember Peer Exchange) for faster source discovery between Ember clients
Transfers and library
  • Multi-source downloads with queue management, health monitoring and live progress
  • Multi-tab search with filters and spam detection
  • A virtual-scrolling library with priorities, comments and collections
Friends and security
  • Ember-exclusive Friend IDs with rendezvous discovery, mutual requests, chat, remote browsing and priority upload slots
  • IP filtering, private-IP blocking, path traversal protection and a strict webview CSP
Desktop app
  • A Windows 10/11 installer, a first-run setup wizard, statistics, GeoIP peer countries and signed in-app updates

Support

Report an Issue

To report a bug or suggest an improvement, please use the GitHub Issues page.

What to include in a good report

  • The exact Ember version (shown in the About dialog).
  • Your Windows version.
  • Clear step-by-step instructions that reproduce the problem.
  • What you expected to happen and what actually happened instead.
  • Relevant screenshots or log excerpts if applicable.

Community & Source Code

Visit the Ember GitHub repository to browse source code, review open issues, or contribute. Ember is GPLv3-licensed and contributions are welcome.