Open-source P2P for Windows and Linux

Ember

A modern, open-source P2P file sharing client built on the eMule KAD network. Ground-up rewrite with Rust & Tauri for speed, safety, and simplicity.

No Spyware
No Ads
No Nonsense
GPLv3 Licensed

Ember is not a fork or reskin of eMule. It is a complete reimplementation of the eMule protocol stack in safe Rust, paired with a lightweight Tauri + Svelte shell. It speaks the same KAD wire protocol as eMule 0.50a and compatible clients (aMule, eMule Xtreme, etc.), participates in the same network, finds the same sources, and respects the same credit system. KAD is joined automatically at startup; ED2K servers are yours to choose, and on first launch Ember can seed a community server.met from emule-security.org.

Ember also runs a network of its own. The Ember Network is an encrypted overlay with no servers and no central directory: Ember nodes find each other directly, publish the files they share, and look up sources for a download over their own DHT. It is on by default and runs alongside KAD and eD2K, so you keep the whole eMule network as well.

On top of that, EPX (Ember Peer Exchange) speeds up source discovery between Ember peers on the ordinary eMule wire, and an Ember-exclusive Friends system adds end-to-end encrypted chat, Noise-secured sessions, and privacy-preserving Friend Codes — all invisible to non-Ember clients.


Highlights

The same eMule network, with a modern app around it.

🧱

Modern Foundation

Built in Rust with Tokio async networking. No buffer overflows, no dangling pointers, no data races. The entire protocol stack runs in safe, memory-managed code.

🌐

Full Protocol Compliance

Wire-compatible with eMule 0.50a and the broader eMule ecosystem. KAD v8/v9, ED2K servers & peer exchange, credits, SecIdent, obfuscation, and AICH all work out of the box.

🔥

Ember Network

Ember’s own encrypted overlay. No servers, no central directory, no shipped seed list — nodes find each other, publish shared files, and look up sources over their own DHT, alongside KAD and eD2K.

🔄

EPX Source Exchange

Ember peers share compact source lists with each other for faster downloads. Non-Ember clients silently ignore the extension—zero compatibility impact.

🔍

Advanced Search

All-networks, Server, KAD, and Ember keyword search with multi-tab results, type/size/source/extension filters, related-file lookup from any row, and built-in spam detection.

🛡

Security & Privacy

End-to-end friend chat encryption, signed anti-rollback updates, RC4 protocol obfuscation, IP filtering with one-click list download, private IP blocking, confirmed deep links, and strict CSP headers.

⚡

Lightweight Shell

Tauri v2 produces a small, fast desktop app (~15 MB installed) without bundling a full browser engine. Responsive UI powered by Svelte 5.

📦

Smart Transfers

Multi-source downloading with intelligent source management, real-time progress, health monitoring, queue tracking, and archive recovery.

📚

Library Management

Virtual-scrolling tables that handle thousands of files. Sort, filter, play media in-app, copy eD2K links, add comments and ratings, and create collections.

👥

Ember Friends

Share a Friend Code, connect through the rendezvous server, then chat end-to-end encrypted over Noise-secured sessions. Mutual friends also get remote browsing, friends-only shares, file offers, priority uploads, and transfers that can work without HighID.

💬

Channels Beta

Group rooms carried over the Ember Network itself — no server hosts them and nobody publishes their IP to the room. Create a public room anyone can find, or a private one that needs an invite, with moderation tools and member-to-member file sending.


Download & Installation

Get Ember 1.7.1

The latest release is available on GitHub for Windows 10 and Windows 11, and for x86-64 Linux as a .deb or an AppImage.

Windows installer · Linux .deb / AppImage · no extra runtimes

Supported Operating Systems

Windows 10 and Windows 11. On Linux, x86-64 distributions with glibc 2.35 or newer (Ubuntu 22.04 and later, Debian 12 and later, and their derivatives), as a .deb or an AppImage. The AppImage needs FUSE 2 to start — libfuse2 on Ubuntu 22.04, libfuse2t64 on Ubuntu 24.04 and Debian 13 — so on those the .deb is the simpler choice.

Requirements

No external runtimes needed. No Java, no .NET, no browser engine download. Ember ships everything it needs in a single installer.

Updates

Ember updates itself. Every release is signed, and Ember checks the signature of both the release manifest and the package before installing anything. Each build updates with the format it was installed from, so a .deb install updates through dpkg and an AppImage replaces itself in place.

With Silent updates switched on in Settings > About, Ember installs a new version by itself while nobody is using it, and reopens the way you left it. This works with the Windows installer and the AppImage. The .deb and MSI packages need your password or administrator approval to install an update, so there Ember tells you an update is ready and you install it with one click.


Getting Started

  1. Install
    Download the latest release from the Releases page and run the installer. On Linux, install the .deb with your package manager, or mark the AppImage executable and run it.
  2. Setup Wizard
    On first launch, the Setup Wizard walks you through essential settings — an optional import from an existing eMule install, nickname, download folder, ports, speed limits, and theme.
  3. Connect
    KAD connects on its own at every launch, so there is nothing to press; you can still disconnect for the current session from the KAD Network page. The Ember Network needs no connect step either — it is on by default and finds its first peers through KAD. ED2K servers stay opt-in: connect from the ED2K Servers page, or enable Auto-connect to server in Settings > Network so Ember rejoins your last one on launch. A community server.met list can be downloaded from emule-security.org on first run.
  4. Share & Download
    Add folders to your library, search with the All networks / Server only / KAD only / Ember only methods, open ed2k:// links, and start downloading. Right-click a result to look for related files or to look the file up on a web service. Ember handles multi-source transfers, queue management, and source discovery automatically.
  5. Add Friends (optional)
    Open the Friends page, share your Friend Code, and add theirs. Adding somebody already gives them priority in your upload queue; once the two of you are mutual and online you also get end-to-end encrypted chat, remote file browsing, and friends-only shares. See Friends.
  6. Join a Channel (optional)
    Open the Channels page, pick a Channel username, then create a room or paste an invite. Discover lists public rooms other people have published. See Channels.

Tip: For best performance (High ID), forward your TCP and UDP ports on your router, enable UPnP, or leave STUN port keep-alive on in Settings > Network. See the High ID vs Low ID section for details.


Features

Networking

  • Ember Network — Ember’s own encrypted, server-less overlay for peer discovery, keyword search, publishing, and source lookup. Always on, joins automatically, and runs alongside KAD and eD2K. See the Ember Network section.
  • KAD Network — The decentralized KAD DHT for peer discovery, keyword search, publishing, firewall checks, and buddy relay. Bootstraps at startup with no setting to configure; the KAD Network page can disconnect it for the current session. If KAD will not connect, Settings > Network can fetch fresh nodes.dat bootstrap contacts from emule-security.org.
  • ED2K Servers & Peer Exchange — Manage servers on the ED2K Servers page, download a community server.met from emule-security.org, and optionally turn on Auto-connect to server (last server, else eMule Sunrise). Once connected, peer exchange helps find sources.
  • EPX Source Exchange — Ember peers share source lists with each other for faster downloads. Non-Ember clients are unaffected.
  • NAT Traversal — UPnP automatic port mapping, firewall detection, KAD buddy relay for LowID peers, and EPX peer-relay (ERAT) for LowID↔LowID paths when attestations allow.
  • STUN Port Keep-Alive — Periodic STUN plus a TCP hold from your listen port keeps NAT mappings alive and advertises the discovered public TCP/UDP ports for High ID. Designed for CGNAT and full-cone NAT when UPnP is unavailable; auto-suspends on symmetric or unstable remapping.
  • Protocol Obfuscation — RC4-based TCP and UDP header encryption to help with ISP throttling.
  • Deep Links — Opens ed2k:// URIs and .emulecollection files from the OS (including while Ember is already running). Incoming links require confirm / review before opening, and pending links can be reviewed later.

Transfers

  • Multi-Source Downloads — Download from multiple peers simultaneously with part-level hash verification, automatic source rotation, and queue management.
  • Transfer Monitoring — Real-time progress bars, per-source detail drawers, upload tracking, health indicators, and archive recovery. The Sources column reads the way eMule’s does, counting peers holding a place in a remote queue and showing how many are actually transferring in parentheses.
  • Find More Sources — Ask every connected network for more sources for one download — KAD, the Ember DHT, the connected eD2K server over TCP, and the rest of the server list over UDP. Each leg answers on its own schedule and what it finds goes straight into the transfer; legs with nowhere to send the question are reported rather than waited on.
  • Bulk Transfer Actions — Tick rows (or use the header checkbox) to pause, resume, stop or cancel many downloads at once, or use the Pause / Resume / Stop / Cancel All commands in the toolbar's More menu. Completed and failed rows can be selected the same way and removed from the list together; the files themselves are kept.
  • Upload Speed Sense (USS) — Optionally adjusts upload speed from network latency to reduce congestion (requires an upload speed limit).
  • AICH — Advanced Intelligent Corruption Handling for part-level hash verification and recovery.

Search & Library

  • Advanced Search — All networks, KAD only, Server only, and Ember only keyword search with multi-tab results plus type, size, source, and extension filters. All networks runs every network that is up, so Ember results arrive alongside KAD and server hits, de-duplicated into one list.
  • Related Files — Right-click a search result, a transfer or a shared file to look for the rest of what it belongs to. eMule’s version asks the connected server and is unavailable unless that server advertises support, which most do not; Ember keeps that request as one signal and also reads the season and episode marker, disc or part marker, year and title out of the file’s own name, so the search runs on every network with no server support. The tab is named after what it went looking for.
  • Web Services — eMule’s right-click > Web services: open a site with a file’s details substituted in, most usefully one that reports how many complete sources the network has seen. All six eMule placeholders are supported and an existing webservices.dat can be imported. An availability lookup ships configured; nothing is contacted until you click one, adding a site asks for confirmation, and the list is editable in Settings > Web services.
  • Spam Detection — Built-in spam detection with Relaxed, Balanced (the default) and Aggressive profiles, each setting how high a score must be to count as spam, and automatic result hiding.
  • Library Management — Virtual-scrolling tables that handle thousands of files. Sort, filter, bulk-edit priorities, scan for missing files, copy all eD2K links for the current view, and create collections.
  • Copy eD2K Links from Search — Copy the link for one result, for every ticked result, or for the whole result list at once, from the context menu, the selection toolbar, or Ctrl+C.
  • In-App Media Player — Play supported audio and video from the Library detail drawer, with Open Externally still available.
  • Comments & Ratings — Add metadata to your shared files for other peers to see.

Social

  • Ember Friends — Ember-exclusive friend system powered by a rendezvous server. Share a Friend Code, exchange mutual requests, then enjoy real-time online status, remote file browsing, friends-only shares, file offers, priority upload slots, durable offline chat, and end-to-end encrypted messaging. See the Friends section for details.
  • E2E Friend Chat — Mutual-friend messages use static X25519 ECDH + AEAD end-to-end encryption after session setup. A lock icon in the chat window and on online mutual friends’ cards marks it; plaintext fallbacks are rejected. Conversation history is encrypted in the local database, and outbound messages queue until the friend is reachable again. Being a static exchange, it provides no forward secrecy and covers message bodies only — see E2E Encryption.
  • Noise-Secured Friend Sessions — Friend connections use Noise IK secure streams with Ed25519 proof-of-possession before chat, browse, offers, and verified friend privileges unlock. Friend file transfers can also run over the same secure path when ordinary HighID/callback routes are unavailable.
  • Channels Beta — Group rooms carried over the Ember Network itself. Create a public room anyone can find or a private one that needs an invite, moderate it with bans, moderators, owner-only invites and slow mode, edit and react to messages, and send a file to one member at a time — encrypted to that member, not to the room. Nobody publishes their IP address to the room. See the Channels section for details.
  • Credits & SecIdent — RSA-based Secure Identification prevents credit theft. Upload priority follows the standard credit ratio formula.

Security

  • Signed Anti-Rollback Updates — In-app updates are cryptographically signed and gated by security epochs, so installs only advance when the signed epoch allows it.
  • Safer File Opens — Deep links require confirm / review; folders dropped on the Library are shared directly, while dropping files, your user folder or a large batch asks first, and sharing a whole parent folder or drive needs a native confirmation; media and upload paths pin approved handles to avoid path-swap races.
  • Confirmed External Links — A link in a room or a message is opened only after a native system confirmation, showing the destination host, and only after the host is checked: anything that is or resolves to a loopback, private or link-local address is refused, so a link cannot reach your router’s admin page or a cloud metadata endpoint. Web services collect the same confirmation once, when a site is added to the list.
  • Security Page — A dedicated page for IP filter management: download the default list, import a file, fetch from an HTTPS URL, enable or disable filtering, add and remove custom ranges, and review how many times each range has actually blocked something.
  • IP Filtering — Download the default ipfilter.zip with one click, import an ipfilter.dat / ipfilter.zip file, or fetch one from an HTTPS URL; the list is updated when you ask, not on a schedule. Incoming connection filtering is off by default because VPN IP ranges commonly appear in ipfilter.dat hosting blocks, silently blocking legitimate peers. Outbound filtering remains active regardless of this setting.
  • Anti-Leech Filter — Reject incoming connections from known leech client patterns (customizable regex list in Settings).
  • Private IP Blocking — Prevents connections to reserved IP ranges.
  • Content Security Policy — Strict CSP headers in the Tauri webview.
  • Path Traversal Protection — Sanitized file paths prevent directory escape attacks.

User Experience

  • First-Time Setup Wizard — Guided configuration on first launch: an optional import from an existing eMule install, nickname, download folder, ports, speed limits, and theme, plus a summary of the networks Ember joins on its own.
  • Clean UI — Modern, responsive interface with real-time transfer monitoring and inline search filtering.
  • Close to System Tray — Choose what the title-bar close button does — ask each time, minimize to tray, or exit. The tray icon stays available either way, so you can reopen Ember from there. On a Linux desktop with nothing to show the icon, such as stock GNOME without the AppIndicator extension, closing to the tray minimizes the window instead.
  • Keyboard Shortcuts — Press ? for a shortcut cheat sheet, Alt+1–9 then Alt+0 to jump straight to the first ten sidebar pages, and Ctrl+, to open Settings.
  • Backup & Restore — Settings > Backup saves your whole profile to a single passphrase-encrypted .emberbackup file: identity and SecIdent keys, upload credits, settings, shared-folder list, known files, friends, chat history, transfer list, server and Kad contacts, IP filter, and learned spam data. The files you share and part-finished downloads are not included, so a backup stays small. Encryption is mandatory because the archive contains your private keys, and a lost passphrase cannot be recovered. Your identity keys are unwrapped from this machine’s at-rest protection (Windows DPAPI, or on Linux a key tied to the machine and your user) into the encrypted archive and re-wrapped for whichever account restores them, so a restore on a new machine keeps your user hash, credits and friendships instead of silently rotating them. Restores are prepared immediately and applied while Ember next starts (the files being replaced are in use while it runs); the replaced originals are kept in a pre-restore-<timestamp> folder beside them, and a pending restore can be discarded from the same screen before it is applied. A restore that has sat waiting for more than a month is dropped rather than applied on top of the profile you have been using since; the backup file is untouched, so you can simply import it again. After restoring onto a different machine, the restored shared and download folders are approved automatically, so put the files back at the same paths; and if the backup carried the database without chat-history.key, existing chat history stays sealed.
  • Statistics — Session and cumulative transfer statistics, connection uptime, network health indicators, and a peer reputation snapshot.
  • Automatic Updates — Ember checks for new versions on the schedule you choose (hourly, daily, weekly or monthly; daily by default), including while it stays open, and installs cryptographically signed, anti-rollback updates in-app with one click. You can also check manually under Settings > About.
  • Silent Updates — An optional switch in Settings > About for anyone who leaves Ember running. A new version downloads and verifies in the background, then waits until nothing is transferring and nobody has touched Ember for ten minutes. A one-minute warning appears as a dialog, a desktop notification and a Cancel update entry on the tray icon, and Not now puts it off for a day. Ember then updates and comes back as you left it: hidden in the tray or where the window was, connected to the same eD2K server, on the same page, with your search tabs, and with the peers waiting in your upload queue still in line. If an update ever fails to install, Ember reopens on the version you had and never retries that version silently.
  • Languages — Full UI localization for English, Spanish, French, Brazilian Portuguese, German, Simplified Chinese, Italian, Russian, and Traditional Chinese, with a Settings language picker and system-language detection.
  • GeoIP — Country identification for connected peers via the bundled DB-IP Country Lite database (MMDB format).

Ember Network

The Ember Network is Ember’s own peer-to-peer overlay: a second network that Ember nodes run between themselves, in parallel with KAD and eD2K. Nodes find each other directly, publish the files they share, and look up sources for a download over their own DHT. There is no directory server, no tracker, and no shipped seed list, and every frame between nodes travels inside an encrypted session.

It is always on and joins on its own — there is no Connect button and no switch to turn it off. Because it runs alongside the eMule networks rather than replacing them, taking part costs you nothing on KAD or eD2K.

What it does not change: Ember finds the source; the file itself still transfers over eD2K client-to-client. An Ember search result downloads through the same multi-source engine, credits, and AICH verification as any other result.

How a node joins

There is no bootstrap server to ask and no address list in the installer. A cold node gets in through whichever of these arrives first:

  1. The KAD rendezvous key
    Ember nodes advertise themselves under one fixed KAD key, as an ordinary source record carrying their Noise public key. A node with a near-empty routing table simply runs a source lookup there. Nodes re-advertise every 5 hours, while they are reachable enough to be a useful first contact. Sharing a library is not required — a node that can answer a DHT ping is worth listing whether or not it publishes anything — but a firewalled node that cannot be reached directly is left out.
  2. The KAD bridge
    Ember peers noticed in ordinary KAD traffic get pinged on the Ember DHT; their signed reply folds them into the routing table. Rate-capped per maintenance cycle and quiet once the table is healthy.
  3. eD2K transfers
    A peer that advertises Ember capability during a normal eD2K transfer is cached with its UDP port and bridged in. This is the way in for a client running with no KAD at all.
  4. Gossip and the saved contact file
    Once a node has been online before, peers learned from other peers plus a persisted contact file (up to 200 entries) get it back in without help.

The first three paths all assume either a live KAD connection or an eD2K transfer with an Ember-capable peer, and the fourth only helps a node that has been online before. That is deliberate: Ember rides eMule’s bootstrap rather than standing up infrastructure of its own. The practical consequence is worth knowing — a first run with KAD off and no servers has no way in.

The rendezvous server has no role here. The server behind Friends is not involved in joining the Ember Network, and a server-hosted bootstrap pool is explicitly not planned: it would hand whoever runs the server an identity-to-IP roster of every participant. Hardcoded seed lists and DNS SRV seeds are ruled out for the same reason — joining stays the rendezvous key, the bridges, gossip, and your own saved contacts.

A fresh node can legitimately sit at zero peers for a minute or two while its first maintenance cycle runs the bridge. The status page shows Connecting during that window rather than pretending something is wrong.

The files you share are published to the Ember DHT as keyword records (so people can find them by name) and source records (so people can fetch them). Publishing happens automatically once the node has peers, and republishes on a cycle to stay alive.

  • Searching — The Search page has an Ember only method, and All networks queries Ember alongside KAD and servers, merging everything into one de-duplicated result list. If KAD and eD2K are both offline, All networks quietly falls back to Ember alone.
  • What a result carries — A keyword record holds the file’s media details (duration, bitrate, codec, artist, album, title) alongside its name and size, so an Ember hit fills the same columns an eD2K server hit fills. Your library is probed once and the answer is persisted — including “nothing to find”, which is the answer for most of a library and has to be as durable as a positive one.
  • Complete sources — Only complete public shares are keyword-published, so the count of distinct publishers who signed a record is a floor on the complete sources. That is a firmer number than a server or KAD swarm estimate, which is one peer’s claim about a swarm it cannot see — and the Sources column says which of the two it is showing.
  • Filters that cost the network nothing — Size, type and extension travel with the query as constraints the responder applies before it packs an answer, rather than as published keys. An indexed .mp3 would be the hottest key on the network, with every mp3 anyone shares competing for one key’s slots on the twenty nodes nearest it.
  • Source lookup — Downloads ask the Ember DHT for sources in addition to KAD and servers, so a file can gain Ember sources even if you found it elsewhere. Find Sources on a transfer asks every network that is connected.
  • Publish badge — The Library marks a shared file with an Ember badge once it has a source record placed on the network, which is the point at which other Ember users can actually fetch it.
  • Publishing while firewalled — A node that cannot be reached directly publishes through a buddy relay instead, so sharing still works behind a restrictive router.
  • BLAKE3 integrity — Ember records carry a BLAKE3 digest, and a download verifies against it whenever one is known (from a search hit, a DHT source record, or your own library). A match shows an Ember badge on the finished row; a mismatch fails the download instead of retrying parts that already matched. Links opened without a digest still download normally and are hashed for future sharing.

Multi-keyword search is approximate. A query with several words uses a sparse DHT intersection plus a filename match on the results, not a strict worldwide AND of every keyword. Recall can differ from KAD on the same query.

Encryption and identity

Ember DHT traffic shares the KAD UDP port (4672 by default) and is told apart by a two-byte marker, so forwarding that port covers both networks, and Ember’s QUIC transfers, which share the same socket by default. Everything past the marker is encrypted.

PropertyDetail
Session encryption Noise with ChaCha20-Poly1305 and BLAKE2s. Noise_IK when the peer’s static key is already known, Noise_XX for first contact.
Node identity A 128-bit node ID derived from BLAKE3 of the node’s Ed25519 public key. DHT frames are Ed25519-signed and bound to the encrypted session they arrive on, and a contact is only trusted once it has answered directly.
Routing Kademlia with k = 20 and α = 5. A response carries up to 17 IPv4 contacts, so it fits one unfragmented datagram; decoders accept up to 20.
Wire versioning Version 4. The decoder accepts a version range and refuses anything outside it at the version byte, so an incompatible peer is a clean rejection rather than a stream of malformed-packet counters that read like packet loss.
Abuse resistance Per-IP and per-subnet admission caps that tighten as more contacts answer this node (gossiped leads do not count), return-routability checks before a node spends anything substantial on a request (so Ember cannot be used as a traffic reflector), retry cookies for unproven addresses, and per-publisher storage quotas so one peer cannot fill the space this node offers the network.

The full wire format — every frame and its encoding, the signing and session rules, the version negotiation, and the storage and admission limits — is written up in the EmberDHT Protocol Specification, also available as a PDF. It is written against wire version 4, as implemented in this release, and marks each change since v3 as additive or breaking, which is the distinction another implementation needs.

The Ember Network page

The page leads with the questions a user actually has — is it on, am I connected, can people reach me, are my shared files findable — and keeps the protocol detail behind a disclosure.

  • Status — Connecting, Connected, or No peers found. There is nothing to switch: the overlay reports what it is doing, it does not ask you to start it.
  • Peers and Published files — How many nodes you are in touch with, and how many of your shared files are findable.
  • Health checklist — Whether people can reach you directly or through a relay (or are still waiting for one), and whether your shares are published. Whether you are on the network is the status line above it.
  • Technical details — Collapsed by default: your node ID and public keys, the protocol counters (search hits and misses, store acks and failures, truncated and withheld answers, average replication, buddy publishes and forwards, malformed frames, version mismatches, observed address votes, EPX exchange stats, storage rejections), plus live tables of contacts, in-flight searches, and the keys this node is serving to others.

Current limits

The overlay is always on and in daily use, but these are the things it does not do yet:

  • Bootstrap depends on eMule — A first run with KAD off and no servers cannot join, as described above.
  • A peer that needs to update cannot be told so — Incompatible peers refuse each other cleanly at the version byte. Your side is not in the dark about it: refusals are counted, split into peer-older and peer-newer, and the Ember page raises a banner while older peers are being turned away. The other half cannot be fixed from here, because the peer that needs to update is by definition the one that cannot decode anything we send. Builds now advertise which versions they can decode on PING and PONG, so a future change to an existing frame can be negotiated rather than partitioning the overlay on the day it ships — but that only helps between peers that both carry it.
  • Multi-keyword recall is approximate — See the note above.
  • A busy keyword is answered a page at a time — One packet still only carries a few records, but a searcher can ask the same peer for the next page, so recall under a common word is bounded by how many peers the search walks and how deep it pages rather than by one datagram. A peer is held to a quarter of a search’s budget while the walk still has somewhere to go, and may serve the rest of it once there is nothing left to ask — so a single node holding an uncommon word can hand over its whole index instead of the first slice of it. Publishing has its own ceiling: a key holds 1000 records and any one publisher at most 150 of them, matching KAD’s numbers, so if you share far more than 150 files under one common word not all of them are findable under it. The Ember page counts how often an answer was truncated or records were withheld.
  • Gossip is unverified until it answers — A peer another node told us about is a lead, not a fact, until it replies directly. The Ember page, status bar, and Search readiness wait for a verified answer before calling the overlay connected, so a table full of gossip does not look like a successful join. Admission caps bound the damage, and a peer whose introductions almost never answer has its leads probed less often. It is still sampled, so it can recover, and no contact is refused on that basis alone.
  • Library content still moves over eD2K — Ember finds the source; the bytes travel the eMule wire. The exceptions are a file sent to a friend in chat or to a member of a room, which goes directly between the two of you (accept-first, up to 2 GB). Putting ordinary downloads on the same footing is the largest remaining piece.
  • Some paths are not yet exercised end to end — Notably publishing while firewalled through a buddy relay, and a cold join from an empty contact file with no KAD.

EPX — Ember Peer Exchange

EPX is an Ember-exclusive extension to the eMule protocol that accelerates source discovery between Ember peers. It makes downloads faster whenever multiple Ember clients are present on the network.

EPX and the Ember Network are separate things that are easy to confuse. EPX is an extra opcode on the eMule wire, exchanged with Ember peers you are already transferring with. The Ember Network is a whole overlay of its own, with its own DHT and its own encrypted transport. Both work independently: EPX helps with any Ember peer you are transferring with, whether or not that peer is in your Ember DHT routing table. (The overlay itself is always on in this build; there is no switch to turn it off.)

How it works

When two Ember clients connect (during a download or upload), they exchange compact lists of the files they are currently downloading along with the sources they know about for each file. If the receiving peer is downloading one of those files, it immediately gains new sources it may not have found through KAD or ED2K peer exchange alone.

Key point: EPX only activates between confirmed Ember peers. Detection uses the private OP_EMBER_HELLO / OP_EMBER_HELLOANSWER handshake. TCP EPX also requires the peer's advertised Ed25519 public key to BLAKE3-bind to its Ember hash — an offline check that a replayed key pair can pass, and so a deliberately lower bar than the proof of possession behind chat, browse and other friend privileges. UDP EPX requires an authenticated Noise_IK session. Legacy ET_MOD_VERSION / CT_EMULE_MISCOPTIONS2 Ember bits are not used.

Wire Protocol

EPX uses opcode 0xF0 on the eMule extended protocol (OP_EMULEPROT). The current version is v4. The payload format:

version       (1 byte, currently 0x04)
file_count    (u16 LE)
  for each file:
    ed2k_hash   (16 bytes)
    file_size   (u64 LE)
    file_flags  (u8, bit 0 = has AICH root hash)
    aich_root   (20 bytes, only present if bit 0 of file_flags is set)
    source_count (u16 LE)
      for each source:
        ipv4      (4 bytes, network order)
        tcp_port  (u16 LE)
        udp_port  (u16 LE)
        flags     (u8, bit 0 = firewalled, bit 1 = obfuscation, bit 2 = relay-capable)
peer_count    (u16 LE)
  for each peer:
    ipv4      (4 bytes, network order)
    tcp_port  (u16 LE)
[optional ERAT trailer]

v4 is layout-identical to v3 for the main body and adds the relay-capable flag bit plus an optional ERAT relay-attestation trailer. v3 parsers ignore unknown flag bits. v3 additions over v2: per-file AICH root hashes for corruption recovery, UDP port and capability flags per source, and a peer discovery section for Ember mesh building. v2 and v3 payloads are still accepted.

ERAT relay attestations

After the peer list, a v4 packet may append a trailer beginning with magic ERAT: version byte, attestation count (max 16), then fixed-size Ed25519-signed entries binding a relay IP/port to an expiry and capability bits. Only cryptographically valid, non-expired attestations (max TTL 30 minutes) become connection-broker relay candidates. The per-source relay-capable flag alone never admits a relay.

Peer-relay QUIC RELAY_REQUEST messages are version 2 or 3 and require proof of possession: the requester includes their Ed25519 public key and Ember hash, a fresh nonce, and a signature over the session id, the relay's ERAT attestation hash, target address, and file hash. Legacy hash-only (bearer) requests are rejected. Relays also reject replayed nonces within a short TTL window.

The target port in the request is the port the relay dials over QUIC. For Ember DHT sources, that is the QUIC port the source advertises in its record. Version 3 adds the target's Ember node id ahead of the signature, which is made under a separate domain, and the relay then refuses to bridge to any endpoint whose QUIC certificate does not prove that id. A relay advertises support with ERAT capability bit 0x02. Requesters send version 3 only to relays with that bit, because older relays accept no request length other than version 2's. A relay also holds at most two sessions per requester, and it closes a bridge after two minutes in which neither direction moves a byte.

The relay answers only once it has reached the target. RELAY_ACCEPT means the bridge is up; RELAY_REJECT carries a reason byte for capacity, a target it will not dial, a requester that is not its friend or an attestation it does not know, a bad signature or replayed nonce, or a target it could not reach, and none of these counts against the relay. A requester asks one relay for no more sessions at once than it would hold, sends the next to another relay, and keeps the newest copy of a relay’s attestation when an older one comes round again. A relay with no room left can only close the connection or refuse the handshake, and the requester then skips it for a minute; a refused handshake still counts against it, because anyone at that address could send one. Within a bridge, a side that finishes its stream has that passed on at once, and what the relay still holds for either side when the bridge ends is given up to ten seconds to arrive before the connections close.

Safety Limits

These caps prevent abuse from poisoned or malicious payloads. Private/reserved IPs and zero-port entries are silently dropped.

LimitValue
Max files per packet200
Max sources per file100
Max payload size64 KB (TCP)
Max packets per TCP connection3
Max total sources per event2,000

The 64 KB ceiling is the TCP path, which streams. UDP EPX has to fit inside a single Noise datagram, so it is packed to a much smaller budget — the same files and sources, just fewer of them per reply.

Backward Compatibility

Non-Ember eMule clients silently ignore the 0xF0 opcode — it causes no errors, disconnects, or side effects. EPX is only sent to peers confirmed as Ember through the private OP_EMBER_HELLO handshake, so a stock client never triggers it.


Friends — Ember-Exclusive Social

Ember includes a built-in friend system that works exclusively between Ember users. It is powered by a separate cryptographic identity called the Ember Hash (also known as your Friend ID), which is distinct from the standard ed2k user_hash used for protocol operations and credits.

How it works

Each Ember client generates a unique 16-byte Ember Hash on first launch. Share a Friend Code (shown on the Friends page) with someone so they can find you on the network. A Friend Code (ember3:) carries your identity plus a random secret, so only someone you gave it to can look up where you are — a public key seen in a room roster is not enough. Friends > Reset code makes a new secret; Ember still accepts older ember2: codes and bare Friend IDs.

Friend discovery is powered by a lightweight rendezvous server. When you connect, Ember registers presence using hashed capabilities (never your raw Friend ID in the clear). When you search for a friend, Ember queries the server and gets back an IP and port for a direct connection. Adding or accepting a friend forces a presence refresh so discovery does not wait on the normal heartbeat interval.

Once a friend is found, Ember opens a direct TCP connection and establishes a Noise IK secure stream with Ed25519 proof-of-possession. After both sides accept the friend request, chat, file browsing, file offers, friends-only shares, and priority uploads unlock on that secured session. When both friends are behind difficult NAT, Ember can still move friend file traffic over the secure session (and optional peer relay) without waiting for HighID.

Ember-only: The friend system is completely invisible to non-Ember clients. It uses a separate identity hash, a dedicated rendezvous server, and dedicated protocol tags that other eMule clients silently ignore.

Features

  • Friend Codes — Share a Friend Code from the Friends page instead of only a raw Friend ID. Codes support privacy-preserving pairwise presence so mutual chat and browse can unlock once both sides have added each other. Codes made by 1.7.0 and later start with ember3:, which 1.6.x cannot read.
  • Mutual Friend Requests — The recipient sees an incoming request on the Friends page and can accept or reject it. Chat, file browsing, offers, and priority upload features only activate once both sides have accepted and a secure friend session is established.
  • Real-Time Online Status — Ember detects when a friend comes online and shows a live online/offline indicator on their card. The Friends page also surfaces when you are not currently discoverable on the rendezvous network.
  • End-to-End Encrypted Chat — Send and receive messages with mutual friends through a slide-out sidebar. After session setup, messages are encrypted end-to-end, marked by a lock icon in the chat window. Outbound messages queue locally and retry when the friend reconnects. The chat can also pop out into its own window. See E2E Encryption.
  • Send Files in Chat — Attach a file to a conversation and it goes directly to that friend, up to 2 GB, over QUIC or, when the sender’s UDP port is not reachable, an encrypted stream on their TCP upload port. Each piece is checked against the offered hash as it arrives. Received files are saved to a Chat Files folder, small ones can download automatically, and programs, scripts and disguised files carry a warning. Both of you need 1.7.0, and files are not sent through relays.
  • Remote File Browsing — Browse a mutual friend’s shared file library while they are online and start downloads directly from the browse results.
  • Friends-Only Shares — Mark Library files as friends-only so they stay out of public search and only mutual friends can request them.
  • Friend File Offers — Push a specific shared file to a mutual friend from the Friends page. Offers appear as actionable notifications the recipient can accept or decline.
  • Friend Transfers Without HighID — Mutual-friend downloads can use the Noise-secured friend session (and optional Ember peer relay) when ordinary HighID or callback paths are unavailable—useful when both sides are behind difficult NAT.
  • Priority Upload Slots — Anyone you have added as a friend gets priority in your upload queue on an authenticated Ember friend session, giving them faster access to your shared files. This one is deliberately one-sided: it costs you only queue position, so it does not wait on them adding you back. Friends-only shares and remote browse do.
  • Friend Block List — Block a Friend ID so future requests, chat, browse, and offers from that identity are rejected. Existing mutual friendships with that identity are removed when you block.
  • Optional Peer Relaying — Relay for other peers (Settings > Network) lets peers who cannot reach each other directly route through you, which is what makes LowID↔LowID transfers work behind strict NATs when attestations allow. It spends your upload bandwidth on people you are not trading with, so you can turn it off.
  • Discoverable Banner — The Friends page shows a confirmation banner when your identity is registered and discoverable, and warns when presence registration failed so friends may not find you.

E2E Encryption

Friend chat is designed so the rendezvous server and any on-path observer never see message plaintext after a secure session is up.

  • Noise IK sessions — Friend connections negotiate a Noise_IK secure stream authenticated with Ed25519 proof-of-possession before chat, browse, offer, and friends-only privileges unlock.
  • End-to-end chat crypto — Message bodies are sealed with XChaCha20-Poly1305 under a key derived from a static X25519 exchange between the two friends’ identity keys. After session setup, plaintext chat fallbacks are rejected. Outbound messages that cannot be delivered stay queued and are retried on reconnect.
  • Encrypted local history — Conversation history is encrypted at rest in the local database, under a key kept beside it. If that key cannot be recovered, history stays sealed and says so rather than failing quietly.
  • Clear UI signals — A lock icon in the chat window and on online mutual friends’ cards marks encrypted chat (its tooltip says what is and is not protected), and reconnect-oriented errors when encryption or the friend session fails.

What the encryption does not cover. The key comes from a static Diffie-Hellman between long-lived identity keys, not a ratchet, so there is no forward secrecy: someone who captures your traffic today and later obtains an identity private key could read those messages. Encryption also protects message bodies only — IP addresses, relationship capabilities, message size and timing stay observable to peers and to on-path services. The in-app chat says the same thing rather than implying more.

Note: EPX source exchange and Ember mesh peer discovery can unlock earlier from HELLO hash↔pubkey binding between Ember peers. Friend privileges (chat, browse, offers, friends-only shares, verified requests) still require a secure friend session / proof-of-possession.

Privacy

The rendezvous server stores presence as hashed capabilities derived from your Friend identity (never the raw Friend ID in the clear), paired with IP and port. Registration is pubkey-bound and signature-checked so entries cannot be spoofed with a stolen hash alone. Entries expire automatically after 5 minutes without a heartbeat. Between Ember peers, the Ember Hash is exchanged via the private OP_EMBER_HELLO / OP_EMBER_HELLOANSWER handshake (with Ed25519 proof-of-possession on TCP) — not via the legacy EmuleInfo path used for ordinary eMule metadata.


Channels Beta

Channels are group chat rooms carried over the Ember Network itself. No server hosts a room and no company runs one: messages travel encrypted between the members over the same overlay that carries search and source lookup. Room and user names are registered with the rendezvous server; messages never pass through it. Members never publish their IP address to the room.

Friends are for people you know one-to-one. Channels are for a group — a room you can hand an invite to, hand off to someone else, or leave running after you have gone.

Channels are in beta. The app marks them so too. The format is still settling, so expect rough edges, and read What to expect before you rely on a room for anything that matters.

Getting started

  1. Pick a Channel username
    Two to twelve letters or numbers, and it has to be free — the name is claimed in Ember’s rendezvous directory so two people in a room are never the same “Ada”. This is separate from your friend nickname, and you need one before you can create or join anything.
  2. Create a room, or join one
    A room name is up to 32 characters and is claimed first come first served; the owner can rename the room later. To join someone else’s, paste the ember-channel: invite they sent you.
  3. Or find one with Discover
    Discover lists public rooms that other people have published. Private rooms never appear there.

Public and private rooms

The choice you make when you create a room is the one that matters most, and it cannot be changed afterwards.

  • Public — listed in Discover so anyone can find and join it. Anyone who finds it can also read it: the key that unlocks the conversation is derived from the address in its public listing. A public room is a public conversation.
  • Private — never listed. Joining needs an invite link, which carries the key. If the conversation should stay with the people you invite, this is the one to use.

A private room’s owner can rotate its key, which cuts off anyone holding an older invite — the remedy when a link has been shared further than you meant.

Running a room

Whoever creates a room owns it. Owner tools open in a room settings window from the gear in the room header.

  • Rename — give the room a new name, up to 32 characters.
  • Topic and welcome — a line at the top of the room and a greeting new members see.
  • Language — mark the language the room is held in. It shows as a small flag beside the name in the room list, the header and Discover.
  • Pins — pin up to 3 messages to the top of the room, from a message’s own menu.
  • Announcements only — only you and your moderators can post; members can still read and react. Each member’s own app enforces it, so a member on an older build is not held to it.
  • Moderators — up to 6 members who can ban and unban on your behalf. They cannot ban you, and they cannot delete the room.
  • Bans — up to 12 at a time.
  • Owner-only invites — stops a member re-sharing the room without thinking. Every member holds the key either way, so treat this as a guard against carelessness rather than against someone determined.
  • Slow mode — sets how long members wait between messages, from 5 seconds to 5 minutes. Off unless you turn it on. You and your moderators are exempt, and everyone in the room can see it is on.
  • Rotate the key — private rooms only, for when an invite has leaked.
  • Hand the room over — transfer ownership to a member, or nominate a successor who can claim the room if you go quiet for a window you choose. Better than sharing your key.
  • Delete — permanent. The room name is retired and cannot be claimed again.

One device can own up to 10 rooms at once. Deleting a room gives the slot back. Joining rooms is not limited.

Every member, owner or not, can mute a room so it stops raising notifications, and ignore a member so their messages are hidden. Both are private to your device and are listed under Settings > Channels, where you can undo them.

Messages

  • Edit your own message for 15 minutes after sending it. Every receiver checks the author’s signature and both clocks itself, so “only the author may edit” is not something the sending client is trusted about. Members who were away are handed the corrected line rather than the original followed by a revision.
  • Reply to a message and your line quotes the one it answers. A member on 1.6.x sees the reply as an ordinary line.
  • React with one of 20 reactions. One reaction per person per message, and changing yours replaces it. The original thumb up, thumb down and heart work with 1.6.1 and newer; the others need 1.7.0.
  • Format with **bold**, *italic*, ~~strike~~ and `code`. Formatting is only how the line is shown; an older Ember shows the marks as typed.
  • See who is typing, on 1.7.0.
  • Remove a message from this device. Local only — the protocol has no way to unsend, so every other member keeps their copy. What it does guarantee is that the line stays gone here, including when another member replays it later.
  • Mention a member by typing @, which completes handles from the room’s member list.

Edits and reactions need both sides on 1.6.1 or newer. An older client does not recognise them and drops them rather than passing them on, so in a mixed room they reach only the members who have updated.

Sending files

You can send a file to one member of a room at a time, up to 2 GB, and only after they accept the offer. An offer that goes unanswered lapses after 5 minutes, and up to 4 transfers can run at once. Files go directly between the two of you, not to the whole room, and the payload is encrypted to that member rather than to the room. Transfers count against your upload speed limit like any other upload, and appear in a drawer under the member list with their speed and time left.

Between two members on 1.7.0 the file moves over a direct QUIC stream, or an encrypted stream on the sender’s TCP upload port when their UDP port cannot be reached, and each piece is checked against the offer as it lands. If neither can be opened — a member on 1.6.x, or two firewalled members who can only meet through a relay — the transfer falls back to the older block protocol, which is much slower, keeps what was already verified, and is limited to 100 MB for a 1.6.x member. Received files are saved to a Channel Files folder, which is not shared, and programs, scripts and disguised files carry a warning.

What to expect

Room chat has no forward secrecy. Everyone in a room shares one key. Someone who captures the traffic today and later obtains that key can read what was said. Rotating a private room’s key protects future messages, not past ones. File transfers are the exception: each one is sealed to the member you sent it to with a key only the two of you can derive, so the rest of the room cannot read the bytes even though they can see the traffic.

  • Moderation is local. A ban stops honest clients from showing that member and stops them being served. It is not a network-level eviction, and someone running a modified client can ignore it.
  • Public listings can be spammed. Discover shows what people published, and nobody vets it.
  • A room holds up to 256 members and a message up to 4096 bytes.
  • History is what your device kept. Rooms are not archived anywhere central. When you join, members near you share recent messages; older conversation you were not present for is gone.
  • Search inside a room looks only through the history your device has.

Network Compatibility

Ember is a first-class citizen of the eMule network. It implements the full protocol suite required to participate alongside every other eMule-family client.

ProtocolDetails
KAD (Kademlia DHT) KAD v8/v9 for decentralized peer and file discovery, firewall checks, buddy relay for firewalled peers, keyword publishing, and note publishing.
ED2K Servers & Peer Exchange Connect from the ED2K Servers page or the optional Auto-connect to server setting (last server, else eMule Sunrise). Community server.met lists can be downloaded from emule-security.org. Once connected, servers provide High/Low ID and peer/source exchange.
Credits & SecIdent eMule credit system with RSA-based Secure Identification to prevent credit theft. Upload priority determined by the standard credit ratio formula.
Obfuscation RC4-based TCP and UDP header encryption matching eMule’s implementation, helping with ISP throttling.
AICH Advanced Intelligent Corruption Handling for part-level hash verification and recovery.

Beyond eMule: Ember additionally runs its own Ember Network overlay and the EPX source-exchange extension between Ember peers. Neither is visible to other eMule-family clients, and neither affects the compatibility above.


Port Forwarding

Ember uses two port numbers for peer communication. Both are configurable in Settings > Network.

PortProtocolPurpose
4662TCPPeer-to-peer file transfers
4672UDPKAD DHT, Ember Network communication and Ember’s QUIC transport (all share this socket)
4662UDPQUIC for relays that dial your TCP port number over UDP: 1.7.0 peers, and relays that know you only from KAD

For best performance (High ID), forward 4662 TCP and 4672 UDP on your router, and 4662 UDP as well if you forward by hand (UPnP maps it for you), enable UPnP for automatic mapping, or use STUN port keep-alive when you are behind CGNAT or full-cone NAT without UPnP.

UPnP: When enabled, Ember uses the IGD protocol to automatically request port mappings from your router. This works with most consumer routers and is the easiest path to High ID.

STUN port keep-alive: On by default in Settings > Network. Ember periodically refreshes your NAT mappings with STUN (and a TCP hold from the listen port) and advertises the public ports peers should connect to. It auto-suspends on Open / Symmetric NAT or unstable remapping and falls back to your Settings ports.


High ID vs Low ID

An ID is a value calculated from the client's IP address and assigned by the ED2K server when Ember connects for peer exchange. It indicates whether proper bidirectional communication is possible.

High ID

A High ID means your connection port is open and freely accessible from the internet. Your client is fully reachable by others. This is the optimal state.

Low ID

A Low ID means your connection port is blocked or cannot be reached, typically caused by firewalls, routers, or NAT. Any ID value less than 16,777,216 is considered a Low ID.

Disadvantages of a Low ID

  • Peer Routing — Since your IP is not directly reachable, all requests must be routed through the server, increasing overhead.
  • Reduced Sources — On the ordinary eD2K path, two Low ID clients cannot connect to each other, so you see fewer sources. Ember can route around some of those cases through a peer relay, and mutual friends can use a Noise session without either side holding a High ID, but neither is a substitute for opening the port.
  • Lost Messages — On busy servers, messages can get lost, causing missed queue progression and slower downloads.

Note: The ID only affects control message exchange. Actual data transfer is still handled client-to-client. If your ID is High, there are no extra advantages to a higher numeric value.

Troubleshooting Low ID

If you're stuck with a Low ID despite correct settings:

  • Verify that ports 4662 (TCP) and 4672 (UDP) are forwarded on your router.
  • Check that your OS firewall allows Ember through on both protocols.
  • Restart Ember to reconnect to the ED2K server.
  • Enable UPnP in Settings > Network for automatic port mapping.
  • Leave STUN port keep-alive enabled (Settings > Network) if you are behind CGNAT or full-cone NAT without UPnP — Ember will try to hold and advertise remapped public ports.
  • If behind symmetric NAT or a VPN that remaps ports unstably, STUN keep-alive suspends automatically; High ID may still require a VPN with a fixed forwarded port or another tunneling solution.

Tech Stack

LayerTechnology
FrontendSvelteKit (Svelte 5) + TypeScript + Vite
App ShellTauri v2
BackendRust (2021 edition)
DatabaseSQLite via rusqlite
NetworkingTokio async runtime
Ember Overlay TransportNoise IK / XX over UDP (ChaCha20-Poly1305 + BLAKE2s), plus QUIC (quinn + rustls) for relays, hole-punched transfers and attachments on the same UDP port
Ember DHTKademlia, 128-bit BLAKE3 node IDs, Ed25519-signed frames
Friend DiscoveryRendezvous server (Axum on Fly.io)
Friend SessionsNoise IK + Ed25519 PoP
Friend Chat CryptoX25519 ECDH + AEAD (E2E)
GeoIPDB-IP Country Lite (MMDB, read with the maxminddb crate)

For Developers

Protocol documentation

Ember’s eMule-side behaviour follows the published eD2K and KAD protocols. Its own overlay is specified in the EmberDHT Protocol Specification (PDF) — wire version 4, as implemented in this release — which is enough to write an independent implementation that joins the same network.

Prerequisites

  • Rust (1.94+)
  • Node.js (20.19+, 22.12+, or 24+)
  • Windows: Visual Studio Build Tools with C++ workload

Development

# Install dependencies
npm install

# Run in development mode
npm run tauri dev

# Build for production (updater artifacts need the release signing key)
npm run tauri build -- --config '{"bundle":{"createUpdaterArtifacts":false}}'

Without that override, or TAURI_SIGNING_PRIVATE_KEY set, the build stops at the updater-signing step. On Windows the production build produces NSIS and MSI installers in src-tauri/target/release/bundle/. A Linux build from the same tree produces the same .deb and AppImage the official release publishes, unsigned.

Project Structure

DirectoryDescription
src/SvelteKit frontend (routes, components, stores)
src-tauri/src/Rust backend (protocol stack, networking, storage)
src-tauri/Cargo.tomlRust dependencies
docs/This documentation site

Contributing

Ember is licensed under the GPLv3 and welcomes contributions. Visit the GitHub repository to open issues, submit pull requests, or review the codebase.


FAQ

Answers to the questions people ask most. Click a question to expand it.

Yes. Ember speaks the same KAD wire protocol as eMule 0.50a and compatible clients (aMule, eMule Xtreme, etc.). It participates in the same network, finds the same sources, and respects the same credit system. KAD is joined automatically at startup, and you can add an ED2K server from the app. Ember’s own additions — the Ember Network overlay and the EPX extension — only involve other Ember clients and are silently ignored by everything else.
Use Settings > Backup. Choose a passphrase, create the backup, copy the single .emberbackup file across, then restore it on the new machine from the same screen and restart when prompted. Your user hash, SecIdent keys, upload credits, friends, known files and settings all come across, which is what keeps your standing on the network. The files you share are not in the backup, so copy those separately. Put them at the same paths and Ember picks the folders up again after the restore; otherwise re-add them on the Library page. Keep the backup somewhere safe: it contains your private keys, and a lost passphrase cannot be recovered.
It is Ember’s own encrypted peer-to-peer overlay, with its own DHT and no directory server. Ember nodes find each other directly, publish the files they share, and look up download sources over it. You do not set anything up: it is on by default and joins on its own, with no Connect button. It runs alongside KAD and eD2K, so you keep access to the whole eMule network as well. See the Ember Network section.
Because there is no bootstrap server to ask. Ember deliberately ships no seed list and hosts no bootstrap pool — one would hand its operator a list of every participant’s identity and IP. Instead a new node finds its first Ember peers through KAD (via a fixed rendezvous key and Ember peers spotted in ordinary KAD traffic) or through an eD2K transfer with an Ember-capable client. Once it has been online, it remembers up to 200 contacts and can rejoin on its own. So on a fresh install, keep KAD and/or a server available; after that the overlay stands on its own feet.
Probably not. There is no central pool to fetch peers from, so a fresh node fills its routing table on a maintenance cycle and the first connection can take a minute or two. If it stays empty, check that KAD is connected or that you have an ED2K server available — those are how Ember finds its first peers. Ember keeps looking for as long as it is switched on.
EPX (Ember Peer Exchange) is an Ember-exclusive extension that lets Ember peers share source lists with each other, speeding up source discovery. It activates automatically when two Ember clients connect — no configuration needed. It has zero impact on non-Ember clients. It is not the same thing as the Ember Network: EPX is an extra opcode on the eMule wire, while the Ember Network is a separate overlay with its own DHT. Both work independently of each other.
No. ED2K High/Low ID is assigned when Ember connects to an ED2K server and reflects TCP reachability. KAD Open/Firewalled is KAD's own firewall check, and it also measures whether your TCP port accepts inbound connections, so a server High ID clears KAD's Firewalled flag. UDP reachability is a separate check, shown on its own: with TCP open and UDP blocked you can be Open on KAD and still be UDP-firewalled.
Forward ports 4662 (TCP) and 4672 (UDP) on your router, enable UPnP, or leave STUN port keep-alive on in Settings > Network. Make sure your OS firewall also allows Ember through. On CGNAT or full-cone NAT without UPnP, STUN keep-alive can hold remapped public ports and advertise them for High ID. Symmetric or unstable VPN remapping still often needs a VPN with a fixed forwarded port.
Friends are an Ember-exclusive feature. Share a Friend Code from the Friends page with another Ember user. Ember finds them through its rendezvous server and sends a friend request. Once both sides accept and a secure Noise session is established, mutual friends unlock online status, end-to-end encrypted chat, remote file browsing, friends-only shares, file offers, priority uploads, and transfers that can work without HighID. You can also block a Friend ID to reject future contact. Non-Ember clients do not have a Friend ID / Friend Code and cannot participate.
Yes. Mutual-friend sessions use Noise IK secure streams with Ed25519 proof-of-possession. Chat messages then use static X25519 ECDH + AEAD end-to-end encryption; plaintext chat fallbacks are rejected after session setup. A lock icon in the chat window and on online mutual friends’ cards marks encrypted chat. Outbound messages queue until the friend is reachable again, and conversation history is encrypted in the local database. The rendezvous server only helps with discovery — it never sees message plaintext.
Credits reward users who upload. The transferred amount of data determines the credit you are given with a particular client. They are not global — they only apply on the client who granted them. Credits are a major modifier when calculating how fast you advance through other users' upload queues. Ember uses RSA-based Secure Identification (SecIdent) to prevent credit theft.
Linux, yes: every release ships for x86-64 Linux as a .deb and an AppImage, and both update themselves from inside Ember. macOS has no official build. The stack (Tauri + Rust) is cross-platform, so one may follow.
Ember checks for a newer version automatically whenever your chosen hourly, daily, weekly or monthly check is due, including while it stays open, and shows a non-blocking notification when one is available. You can install it in-app with one click — no need to download installers manually — and Ember restarts into the new version, back on the page and server you were using. You can also check anytime under Settings > About. If you would rather not be asked, turn on Silent updates there (not available for the MSI installer or the .deb package, which need administrator approval or your password to install): Ember then installs updates by itself once nothing is transferring and you are away, after a one-minute warning you can cancel. Every release is cryptographically signed, and Ember verifies the signature before installing, including a downloaded update that waited on disk for a quiet moment. Updates are also gated by signed security epochs (anti-rollback), so installs only advance when the signed epoch allows it.
Yes. Ember is released under the GNU General Public License v3 (GPLv3). The full source code is available on GitHub. This means anyone can use, modify, and distribute it, but derivative works must also be released under the same license.
No. Ember is a complete ground-up rewrite of the eMule protocol stack in Rust, not a fork or modification of the original C++ codebase. It implements the same protocols from scratch to ensure compatibility while using modern, memory-safe code.

Release History

Every Ember release, newest first. These are the same notes we publish on GitHub Releases. Ember can also update itself in-app once a signed release is published.

Ember v1.7.1

v1.7.1

Ember now keeps itself up to date: it checks for releases while it stays open, can install one by itself while you are away, and comes back the way you left it. One forwarded UDP port now carries everything, room offers no longer show a file’s name to the members passing them along, and Transfers gained categories, an Add links box and a rate graph on Statistics. Around that sat another round of audits — the Ember DHT, relays, sharing, updates and the interface — and their fixes.

Before you upgrade

  • The Ember DHT wire version is unchanged at version 4, so 1.7.1, 1.7.0 and every 1.6 release see each other on the overlay normally
  • QUIC now runs on your KAD UDP port. If you forward ports by hand, that one UDP port now carries everything. Ember still listens on the old QUIC port (your TCP port number, over UDP) for 1.7.0 peers and relays that dial it, so keep that forward if you have one. "quic_shares_udp_port": false in config.json brings back the separate socket
  • Room offers are now private. A member on 1.6.x, or one on 1.7.0 who has not shown it can read them, may not answer: after 10 seconds your transfer card asks whether to send a standard offer, which lets the members relaying it see the file’s name and size. Nothing is sent that way without your click, and files over 100 MB cannot go to a 1.6.x member at all
  • Max sources per file now limits each download, not only the source cache. At the default of 400 a download keeps at most 400 sources, and a saved value below 50 is raised to 50
  • Silent updates are off until you turn them on, in Settings > About. They work with the Windows installer and the AppImage; .deb and MSI installs show why they cannot

What’s New

Updates
  • Checks keep running while Ember stays open, hourly, daily, weekly or monthly, so an Ember left in the tray for weeks still hears about a release
  • Silent updates. A release downloads in the background and installs only when nothing is moving and nobody has touched Ember for ten minutes. A minute’s warning comes first: a dialog in a visible window, a notification and a Cancel update entry on the tray otherwise. Not now waits a day, Skip this version holds it, and a transfer starting stops the countdown
  • Coming back the way you left it. After an update Ember reopens at the same size and place, maximized, minimized or in the tray, on the same page, server and search tabs, with the chat still popped out, and peers waiting in your upload queue keep their place
  • An installer that never brings Ember back is covered: Ember starts itself again within about five minutes, on the old version, and says the update did not install
  • The tray menu is in your language
Transfers and Statistics
  • Add eD2K links from a box filled from the clipboard, which counts what it found as you edit, or press Ctrl+V on Transfers
  • Your own download categories. Make one from a download’s Category menu, for one row or a whole selection, and filter the list by category with chips; Pause, Resume, Stop, Cancel and Clear completed then act on that category alone
  • A transfer-rate graph on Statistics, over the last five minutes or the last hour
  • The status bar shows HighID or LowID while connected, and its speeds open Transfers
  • Long lists scroll smoothly. Servers, the upload Queue and Known Peers render only the rows on screen, and Known Peers shows every peer instead of stopping at 1,000
  • Max sources per file is in Settings beside the other limits and applies at once
Rooms and networking
  • Room offers are sealed to the member they are for, so the members relaying one no longer learn the file’s name and size
  • One forwarded UDP port is enough. Behind a VPN or router that forwards a single port, friend file transfers and relayed downloads now go over QUIC instead of the slower TCP fallback
Library and search
  • Sharing part of a folder hashes only what you chose, instead of indexing the whole tree, and a file you unshare from it stays in the Library explorer as not shared
  • Files deleted from a shared folder of more than 100,000 files stop being offered without a Remove missing
  • A folder scan that fails says so, and a search tab that drops its least available results at the cap says how many

What’s Fixed

Privacy and security
  • Files received in chat or in a room could be shared. When the download folder sat inside a shared folder, a new file in Chat Files or Channel Files was picked up by the folder watcher and offered to the network. Those folders are now refused however a file in them is found; sharing one of them on purpose still works. 1.7.0 had the same gap
  • The Ember DHT was audited again. A peer we merely answered can no longer pin itself onto every lookup, one host can no longer confirm a fake digest or aim every downloader of a popular file at addresses it names, a captured handshake can no longer replay its first message, searches refuse expired and future-dated records, and a few addresses can no longer crowd the neighbourhood of our own ID
  • Relays answer only once they have reached the source, can be told to bridge only to the node a record names, close a bridge after two idle minutes, and hold at most two sessions for any one requester
  • A peer’s goodwill can no longer cancel corrupt-data strikes, and a waiter for a file you have since unshared or made friends-only is no longer granted an upload slot
Sharing, downloads and uploads
  • Partial shares hold. Unsharing a file while its folder is still hashing works, one unreadable file no longer stops a large folder from moving on, a subfolder that is briefly unreadable keeps its files, and files dropped into a partly shared folder are picked up
  • An ed2k:// link with literal | characters handed to a running Ember on Windows, from a command prompt or another program, arrives whole instead of in pieces
  • A burst of relayed sources no longer gets a working friend relay dropped, and a relayed transfer delivers its last bytes before the bridge closes
  • Two Ember peers dialling each other at once connect at once instead of both waiting thirty seconds, and an idle Ember-only node notices when its public address changes
  • On shutdown, server.met and sources.met are saved before the saves that matter less, so a slow disk no longer costs them
Updates and the interface
  • A full disk can no longer turn one failed silent install into a restart every half hour, Check now answers during a background download, and waking from sleep no longer says Ember is busy again
  • Ctrl letter shortcuts work on non-Latin keyboard layouts, without taking AltGr text or a Dvorak comma for a letter
  • A category filter survives a restart onto Transfers, the rate graph stays whole when the clock is set back, and the categories dialog keeps focus where Escape can reach it

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.7.0...v1.7.1

Ember v1.7.0

v1.7.0

The first feature release since 1.6.0, and most of it is about sending someone a file. You can now send a friend a file straight from the chat, and a file offered in a room no longer crawls: rooms used to move files a kilobyte at a time at about 190 KB/s, capped at 100 MB, and they now use the same direct, checked stream as chat, up to 2 GB. Rooms also gained replies, pins, an announcement mode, a typing indicator, more reactions, formatting and a language flag; the chat can pop out into its own window; and an eMule or aMule install can be imported on first run. Around that sat a long run of audits — the eMule, KAD and server paths checked again against eMule’s own source so Ember stays on the right side of their ban rules, the Ember DHT, the rendezvous server, security, and finally a page-by-page pass over the interface so every screen looks and behaves like the others.

Before you upgrade

  • The Ember DHT wire version is unchanged at version 4, so 1.7.0 and every 1.6 release see each other on the overlay normally. This is a compatible update; anything older than 1.6.0 is still invisible to all of them
  • Friend codes now start with ember3:, and 1.6.x cannot read one. The new code carries a random secret, so a public key seen in a room roster can no longer be used to look up anyone’s address. If a friend is still on 1.6.x, ask them to update or to send you their code instead — 1.7.0 still reads ember2: codes and bare IDs. Friends you already have carry over; while one of them stays on an older build, Ember keeps the old lookup for them for a limited time and their card says so. Friends > Reset code makes a new secret
  • Sending a file in Friend Chat needs both of you on 1.7.0. A friend on 1.6.x will not see the offer
  • Room transfers between two 1.7.0 members use the new stream; with a 1.6.x member they fall back to the old block protocol. A 1.6.x member cannot accept a file over 100 MB and drops the offer without answering, and the offer says so when it expires. Received room files now land in a new, unshared Channel Files folder beside Chat Files instead of in Downloads, which is shared by default
  • The new room features degrade gracefully on 1.6.x. A reply reaches an older member as an ordinary line, formatting shows as the asterisks and backticks that were typed, the typing indicator and the new reactions are ignored, and the room’s language is relayed without being shown. Announcement mode is enforced by each member’s own app, so a member still on 1.6.x can post in an announcement-only room until they update

What’s New

Sending files to friends
  • Send a friend a file from the chat. The file goes directly between the two of you over QUIC and is checked against the hash it was offered with as each piece arrives, so a file swapped or corrupted on the way is refused rather than saved. Received files land in a Chat Files folder, open only from there, and small ones can download automatically up to a size you set in Settings
  • A firewalled sender still works. If the sender’s QUIC port cannot be reached, the file falls back to an encrypted stream on their TCP upload port after about three seconds, and two computers on the same home network find each other directly
  • Progress moves as the bytes do. The card shows speed and time left and updates as data arrives, instead of jumping once per 256 KB checked chunk and looking stalled in between
  • A warning on files that can run code. A program, shortcut or script — or a file disguised as something else, like report.pdf.exe — carries a note to open it only if you trust the sender, in chat and on room transfers
  • Free space is checked before a transfer is accepted, and a friend who is only reachable through a relay is shown as such, since files are not sent through relays
Room transfers
  • Room files move over a direct stream, up to 2 GB, encrypted to the member they were offered to and checked as they land. When the stream cannot be made, the transfer falls back to the block protocol and keeps what was already verified
  • Transfers live in a drawer under the member list, with speed and time left, an Open Folder button once a file arrives, and no offers from members you have ignored
Rooms
  • Replies, pins and more reactions. Reply to a line and it quotes what it answers; the owner can pin up to three messages to the top of the room; reactions grow to twenty; and messages support formatting
  • Announcement mode and typing. An owner can make a room announcement-only, and members see who is typing
  • A room can be renamed, and names can be up to 32 characters. The room list and header always show the whole name, wrapping rather than cutting it off
  • A default language for each room, chosen from a searchable flag picker and shown as a small flag in the room list, the header and Discover before you join. Room search matches language names too
  • Room settings open in their own window, with rename, topic, welcome, language, invite policy, announcements, slow mode, key rotation, succession and delete laid out as cards
  • The room list sorts, searches and sizes itself to the window, a room stays open while you look at another page, and a half-typed line is still there when you come back
Chat
  • Pop the chat out into its own window and back again. The dock slides in and out, remembers the width you give it, and finds a conversation as you type its name
  • Unread counts show the number, the same capped count everywhere, including on each friend’s Chat button, and declining a friend request now tells the other person
Library and sharing
  • Import from eMule or aMule on first run or any time from Settings > Import (#126)
  • Choose what to share without leaving the app, see how many files a folder will offer before you share it, and see subfolders marked as shared — or share a folder without them
  • File details were reworked: a type icon, who the file is shared with, priority and friends-only changed in place, copy buttons for the path, hashes and eD2K link, and the upload ratio
  • Friend Browse gained the Library’s categories, sorting, multi-select and ownership badges, and shows how many files a friend shares. Ember also tells you when someone views your shared files
  • Rename a download while it runs, and see which network each source came from, which client it runs, and when the download folder refuses a write
  • On Linux, an approved removable drive stays approved across a replug or reboot, recognised by its filesystem ID
Look and feel
  • One design language across every page. Type sizes, dialogs, spinners, banners, empty states, status badges, tables, network tiles, chat bubbles, avatars and page spacing now come from shared definitions, and every page collapses at the same window widths
  • Translations were filled in and tidied. Channel errors that seven languages still showed in English are translated, German uses the formal Sie throughout, counts read “1 file” rather than “1 files”, and the system file pickers are titled in your language

What’s Fixed

Staying in good standing on eMule, KAD and servers
  • One connection per peer, and re-asks paced across restarts, so restarting Ember no longer looks like a client asking too often. Handshakes match vanilla eMule
  • KAD traffic runs through an outbound governor matching eMule 0.72a’s tracker, and “New Connections / 5s” now limits the connections Ember opens rather than the ones it accepts
  • Server work moved off the event loop, with shared-file offers and source requests paced the way servers expect, and a re-share is no longer read by a server as a republish
  • One peer could end a keyword search that everyone else was still answering, and a pre-Unicode client could not read our folder names
Downloads and uploads
  • Large files on slow drives were re-hashed on every launch. A hash now gives up only after five minutes without reading anything, instead of five minutes in total, so a multi-gigabyte archive on a USB drive finishes once and is remembered
  • A download could strand just short of 100% on a gap smaller than 16 bytes, and a stall in the middle of a packet now ends the connection instead of reading on out of step
  • A waiting download no longer holds a connection slot while it dials, disconnected waiters keep their place in your upload queue while they re-ask over UDP, and a reachable node stays reachable while KAD is disconnected
  • Upload columns no longer add up to more than the limit, a live download no longer flashes Stalled, and a download no source has queued yet reads Waiting rather than Queued
  • Marking a search result as spam no longer freezes the table, and the tab is re-rated the way eMule does it
Security and privacy
  • Friends-only files stay friends-only on the friend who downloads them, instead of becoming public when they re-share
  • A stranger can no longer probe whether a file hash belongs to a friend, and an unknown or friends-only file is answered exactly as not found
  • Room message IDs are bound to their author, so an edit cannot claim someone else’s message, and hidden direction-changing characters are stripped from names in search results, collections and eD2K links
  • The rendezvous server is harder to crowd out: relay sessions and connections are capped per client network and per IPv6 /64, replay protection is kept per key, and sealed intro registrations are verified
  • Restoring a backup no longer sets the media player, and a network path is refused as one
The Ember DHT
  • An audit of the DHT closed a dozen gaps, including relay and callback caps that could be dodged by rotating node IDs, a lookup a single responder could stall, one node being able to mint a file’s publishers, a Max Size of 0 hiding every Ember result, a publish schedule lost on every launch, and a false “Direct” on the Ember page
  • Each incoming frame costs less, with junk and replayed records refused before any signature check, and a waking laptop keeps its contacts until they have had time to answer
Speed and the interface
  • The event loop no longer waits on the database or the disk, the Library rescans only what changed, and only changed transfers are sent to the window
  • Settings no longer waits for Save to apply the IP filter and private-address switches, which already took effect at once on the Security page
  • A page-by-page review fixed keys reaching lists behind open dialogs, errors wiped by background refreshes, a search query lost on return, a Clear filters that could not clear spam hiding, a friend rename that never reached its card, and a selected download that lost its highlight on a striped row

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.6.7...v1.7.0

Ember v1.6.7

v1.6.7

Two reports came back from 1.6.6. A Reload that still would not settle — the same library of 46,541 files, still rescanning hours after it should have finished — and an upload speed that still read higher than the router agreed with. Both were real, and both were the shape the last release was mostly about: work nobody asked for, or work counted twice. The Reload was a download quietly asking the Library to rescan every time it wrote to its own .part file. The speed was compression — we were reporting the size of what we read off the disk rather than the size of what went out the socket. Chasing the second one properly meant reading eMule’s source beside ours for the whole upload path, then the download path, then the wire format, then every timer and constant. Four passes. Most of what follows is what they found, and the verdict was better than the length suggests: every opcode, the framing, the credit formula and the queue arithmetic were already right. These are the places they were not.

Before you upgrade

  • The Ember DHT wire version is unchanged at version 4, so 1.6.7, 1.6.6, 1.6.5, 1.6.4, 1.6.3, 1.6.2, 1.6.1 and 1.6.0 all see each other on the overlay normally. This is a compatible update; anything older than 1.6.0 is still invisible to all eight
  • Your upload speed will read lower than it did in 1.6.6, and this time it is the true number. When a peer accepts compressed transfers — most do — Ember sends the compressed bytes but was counting the uncompressed ones, so anything compressible read high. Text, documents and already-loose archives could overstate by a wide margin; video and music, which barely compress, were close to honest all along. The limiter was always charged the real figure, which is why the cap held while the number above it disagreed
  • A few peers will move up your upload queue. Credits were being awarded on the same inflated figure, and because a peer’s standing is a ratio of what it gave you over what it took, over-counting what it took pushed it down the queue. Anyone who had been taking compressible data from you was being quietly penalised for it

What’s Fixed

The Library
  • An active download made the Library rescan itself, over and over. Ember watches your shared folders so a file you drop in appears without being asked; the watcher decided whether an event mattered by looking at what kind of event it was, and never at which file it concerned. A download writing into a shared folder therefore queued a rescan on every write to its own .part file — a file Ember will never share, checking a folder whose contents had not changed. One download was enough to keep a large library rescanning indefinitely, which is the Reload that ran for six hours and then kept going
  • A multi-part file with no recovery hash still held up the scan. 1.6.6 drew the line between “the Library is incomplete” and “the Library could be slightly better” and moved the whole-file digest to a background pass. The AICH root was left on the blocking side, though it is the same kind of thing: a file without one is complete by every measure, is served and searched normally, and only loses the ability to repair a corrupt 180 KB block without re-fetching the 9.28 MB part around it. It fills in from the same background pass now
  • Only the first page of a large library ever queued its background work. Records are loaded a page at a time on startup, and the check that asks “does this row still want a hash filled in?” ran on the first page alone — so on a library of tens of thousands of files, everything past the first few hundred waited for a full Reload it should never have needed
  • A reconcile could erase part hashes it had no reason to touch. When file metadata drifts, the two hashes beside it are preserved if they are still good; the part-hash list was overwritten unconditionally, so a drift that missed its cache dropped a list that was perfectly valid. The asymmetry with its two neighbours was accidental
Uploads
  • Upload speed counted the bytes before compression rather than the bytes that were sent, which is the report above. Payload and wire are separate counters now: your session allowance is still measured in payload, as eMule measures it, while the speed, the totals and the credits are measured in what actually left the machine
  • A transfer was interrupted every 9.75 MB even when a slot was standing empty. Rotation is meant to give a waiting peer a turn, but eMule only rotates when it cannot simply open another slot — with one free it opens it and leaves the running transfer alone. Ember rotated on the mere existence of a waiter, so an under-loaded node repeatedly told a peer to go away and come back, and the peer re-handshaked for a slot it already had. Ember’s own leecher detector had been seeing those forced returns and needed a rule to forgive them
  • Ember could earn a two-hour ban from a well-behaved eMule by following its own timer. The minimum gap between asking a peer about a file is ten minutes; ours was set to 590 seconds, and eMule counts a strike at anything under 600 — four strikes is a ban. Our own redial floor is this constant, so every dial on that path landed just inside the window. This is the second time the same bug has been fixed: the comment above it records a 60-second floor that “got Ember banned by its own peers”, and the fix for that landed on a number close enough that nobody checked it again
  • Compression was set to a level worth paying for. eMule uses zlib level 1 and says why in its own source — about 4% more compression for 1.5 to 2.5 times the time. Ember was paying level 6 on the serving hot path for a few percent that the uplink, not the compressor, is the limit on anyway
Talking to eMule and aMule
  • “View shared files” from an eMule or aMule never answered. There are two opcodes for browsing someone’s shares, and a client picks between them on whether it thinks it is talking to another mule. Because we identify ourselves as one, a stock eMule always asked with the one Ember had not implemented — so the request went unanswered and the window hung, and the entire browse responder, including the polite refusal when sharing is off, was unreachable for every client it was written for. Folder names are sent as the bare folder name, never the path it sits at
  • A peer you dropped from your upload queue was stranded for half an hour. Asked over UDP about a queue place it no longer had, Ember replied with a position of 65535 as a way of saying “not queued”. To the peer that is simply a very large position: it records it, believes it holds a place, and will not reconnect for another twenty-nine minutes, whereupon it does the same again. eMule stays silent precisely to force the peer to reconnect over TCP, and so do we now
  • Roughly one obfuscated connection in a hundred was dropped for no visible reason. Obfuscation begins with a random byte, and a handful of values are excluded because they would be ambiguous with a plain header. Ember excluded five where eMule excludes three, so two perfectly legal obfuscated connections in every 256 were read as plaintext, mis-parsed and closed — an intermittent failure with no pattern to it
  • Every vanilla eMule was recorded as not supporting Preview, because the capability was read from the wrong bit. Similarly, a peer using the compact form of the handshake tags — mods and non-eMule stacks do — desynchronised our reader, which then abandoned the rest of the packet and left the session believing that peer supported no compression, no source exchange and no extended requests. It failed silently, as a downgrade rather than an error
  • Ember promised secure identification it could not always perform. The level is meant to be declared as zero when no usable key exists — a state Ember already detects and reports in Settings — but we declared support unconditionally, so a peer would ask for a key, get nothing, and we would forfeit the credits the claim was meant to earn
  • The queue-position packet went to clients that cannot read it, including plain eDonkey clients that never claimed to speak the extended protocol, and it was sent with a position of zero to peers that were not on the queue at all. Both are things eMule explicitly refuses to send
Downloads
  • Rarest-first could not see the peers that had everything. A client sharing a completed file announces it in a compact form that Ember distrusts for choosing parts, for a good reason involving an old aMule quirk — but it was also being withheld from the table that counts how scarce each part is. On a healthy swarm most sources look like that, so the count sat near zero, every part scored as desperately rare, and rarest-first stopped telling parts apart for the rest of the download. Those peers count toward scarcity now, while still being distrusted for selection
  • A source that got faster was given a shallower pipeline. The number of blocks kept in flight is meant to rise with speed and did not: one band handed out fewer requests than the band below it, and a source with no measured speed yet — every source, at the start — took the slowest path. Small files were affected worst, asking for 540 KB of blocks to cover the last kilobyte of a gap
  • Preview could outrank a part nobody else had. Asking for the beginning and end of a video first is right, but not ahead of a part the swarm is nearly out of — if that part disappears the file cannot finish at all. Preview is now a band just below “very rare”, which is where eMule puts it
  • Ember asked each peer for more sources four times as often as it should, with no ceiling on a well-seeded file and no stop once it had plenty. The extra requests achieved nothing — the peer applies the same rule when answering and discards them — but they are exactly what anti-leech mods score you on
  • A friend on a restricted connection took the head of your upload queue and held it. Friends get priority high enough to outrank everything else, which is intended; but a peer behind a restricted connection cannot be called when a slot frees, so the front of the queue was reserved for someone who had to turn up on their own. Friends still have priority, and a friend you can reach still gets the next slot

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.6.6...v1.6.7

Ember v1.6.6

v1.6.6

A user with 46,541 shared files reported two things that turned out to be the same story told from both ends. His upload queue stopped growing at about 150 waiting peers where aMule reached 400 on the same library and the same server — because a peer that was merely waiting never gave its connection back, so the queue could not grow past the connection limit. And Reload ran for days, because an optional extra hash had been quietly filed as something the Library was incomplete without. Pulling on both threads turned into three full audits of the tree, and most of what they found has the same shape: work nobody asked for, repeated on a timer. An idle node with nothing to talk to was writing about 30 GB a day to save bytes it had already saved. A finished download was read end to end three times to check three hashes. A global search asked two or three of the hundred servers in your list and stopped. None of it was visible from the outside, and all of it was being paid for.

What’s New

Downloads
  • Downloads have a File Details window. It draws two maps of the same file — the parts that are on your disk, and the parts the swarm between them holds — so a download that is moving slowly can be told apart from one whose missing piece nobody has. It also names the scarcest part’s holder count, which is the number that decides whether a transfer will ever finish. Read only while the window is open, so nobody who never opens it pays for a per-part bitmap on every poll
  • A source row says which of eight things it is. “Connecting” used to cover four separate conditions and “Done” another four, which is why a screenshot of a stalled download and a screenshot of a busy one looked identical. Waiting on one of our own connection slots, and holding parts that are all already coming from somebody else, are now states of their own with their own summary chips — so five peers waiting on your connection cap no longer read as five peers dialling
  • Every source says which network found it, and what the peer runs. Those were one field before, and provenance was winning: the column that could have told you a peer runs eMule 0.60 was spending itself on the words “KAD Callback” instead. The sources drawer gets an origin chip in the same network colours the Library’s published-to badges use, and Download Clients gets a sortable Origin column
Settings
  • Settings has a filter across all eighty-six controls. Eleven sections is past the point where scanning works. Matching reads the rendered text of each control — label, toggle title and hint — so it cannot drift out of step with the page, and a section whose own name matches keeps all of its fields rather than showing only the rows that repeat the word
  • Max Connections and Max Connections Per 5 Seconds are in front of you, in Settings > Limits. The first decides how many peers can be waiting in your upload queue and eMule has always put it on the Connection page; the second is eMule’s MaxConnectionsPerFiveSeconds, which bounds how fast the listener opens sockets and is what keeps consumer routers from choking on a burst. Your eD2K server is exempt from it, so a burst can never cost you High ID
  • Preview can be pointed at a player of your choosing. 1.6.5 fixed Preview opening nothing at all; this is the other half of that report. Empty still means “hand it to the system”, which stays the default. The path has to come from the Browse button rather than being typed, because this field names a program Ember will execute — the same provenance rule the download folder is under, for a stronger reason
  • The section you are looking at is in the URL, so you can link to it, and arriving on somebody else’s link and moving elsewhere no longer leaves a reload jumping you back. Transfers’ eleven controls are in named groups, Web services is its own section rather than being filed under storage and concurrency, and the sidebar is a real tab list you can walk with the arrow keys
Around the app
  • The sidebar reads in three parts — wordmark, destinations, utilities — with the eleven destinations broken into titled runs: Networks, Files, Community, System. The grouping is a pure read of the order that was already there, because Alt+N is positional and reordering to suit the groups would have silently reassigned every shortcut. The current page now uses the same selected-row tint as the rest of the app, where a colourless grey plate had read as readily “disabled” as “current”
  • Complete Sources is shown by default in search results, and reads as a share rather than a bare count, as eMule’s does. Two complete sources out of three is a download that will finish; two out of two hundred is one that probably will not. It had been there since 1.5 and was reachable only through a button most people never found
  • The upload queue and the peer ledger can name people. Both could identify a waiting peer only by a user hash, while the Uploading tab beside them showed a nickname and client software the whole time — the data was parsed at the handshake and then dropped. Names are now kept and persisted, so a lifetime ledger is not a column of dashes
  • The server list shows Priority, which Ember has always read out of server.met, always used to decide auto-connect order, and never displayed — with eMule’s High / Normal / Low choice on the right-click menu. The Static column says No instead of an em-dash, and a server can be marked static or prunable from the same menu, in batches, which is how a freshly imported list is usually dealt with
  • Search results and the server log survive a page reload. Nothing replays a search — the backend streams results and keeps no copy — so a stray reload emptied the list with no way back but running it again. Tabs are now saved for the session, and the last 200 server log lines are kept by the backend and handed back on request

Before you upgrade

  • The Ember DHT wire version is unchanged at version 4, so 1.6.6, 1.6.5, 1.6.4, 1.6.3, 1.6.2, 1.6.1 and 1.6.0 all see each other on the overlay normally. This is a compatible update; anything older than 1.6.0 is still invisible to all seven
  • Max Connections now means what it says, and your connection count will read lower. The upload listener and the outbound download limiter each applied the whole number independently, so somebody who asked for 500 could be holding closer to 1000 — which is a miserable thing to diagnose when a consumer router falls over in the high hundreds. There is one pool now, with a quarter of it reserved for peers wanting to download from you so they can never be crowded out
  • Your upload queue will grow well past where it used to stop. Waiting peers now let go of their sockets after 40 seconds of silence and keep their place by re-asking over UDP, which is what eMule does, so the waiting list is bounded by the queue size rather than by the connection limit. If you have been sitting at a plateau, expect it to climb
  • Disconnecting KAD no longer disconnects your eD2K server. It used to take the server down with it, on the theory that this was the app’s single “go offline” button. It is not — it is the Disconnect button on the KAD Network page, and using one network without the other is ordinary in both directions
  • If Reload has been running for days, it will stop doing that. Records written before Ember had its own whole-file digest lack one, and filling it in means reading the file — which had been queued into the scan, so Reload read every byte of the library. That digest is an extra, not a requirement: a row without one is complete by every eD2K measure and is served, searched and published normally. It now fills in from a background pass at a duty cycle, which Stop really does stop, while the scan itself finishes in minutes
  • Your displayed upload speed now includes relayed bytes. If you donate peer-relay, the traffic you carry for other people was never metered and is now charged to the same limiter and the same total as your own uploads. Honest, but it will read higher than file uploads alone

What’s Fixed

The upload queue
  • A queued peer never gave its connection back, which is the whole of the plateau. Ember’s listener caps concurrent sessions, and a peer merely waiting its turn held one for as long as it cared to stay connected — so once the sessions were spoken for, new peers were dropped by the accept loop before they could even ask to be queued. eMule disconnects a plain waiter after 40 seconds and never touches its queue row, which keeps its place by re-asking over UDP; Ember had every piece of that arrangement already and was missing only the part where it lets go
  • The cap itself was hardcoded at a fifth of eMule’s. The listener used a constant of 100 while the max_connections setting beside it — documented in the source as eMule’s maxconnections, default 500 — reached only the download side. Existing installs pick the real number up with no action, because 500 is already what their config holds
  • A peer re-asking faithfully was evicted anyway, an hour after it first arrived. Three of the four purge paths key on when a peer last asked; the fourth keyed on when it first joined, and it ran from what reads like a read-only snapshot that the Transfers page polls every fifteen seconds. That bounded the waiting list by arrivals-per-hour, and it would have blunted the fix above
  • Every waiting peer’s position was a question mark. The rank was computed and then discarded whenever the peer had no open socket — which is nearly every row, since a peer told it is queued hangs up and re-asks later. eMule’s ? is for our place in a remote queue, which is genuinely unknown; our own queue is the one place the number never is. A disconnected row is dimmed instead
  • The country flag was blank for the whole queue, for the same reason: the address it resolved from is cleared when the peer hangs up, while the entry keeps its seniority. It falls back to the last address seen now — but the credit ledger deliberately does not, because handing it a stale address would re-flag every peer on a dynamic connection and floor their ratio with it
  • The Queued tab filled in once per visit. Its poll ran only while that tab was the visible one, and it is not the default, so arriving at Transfers read the queue exactly once and then left it alone — count and all. This is what the reporter was working around with a page reload, and why it had to be repeated
Uploads
  • Serving as somebody’s buddy cost every other peer their upload speed. Buddy sends ran inline on the one task that owns the KAD socket, under a ten-second timeout, so a firewalled client that stopped reading froze UDP receive, the DHT and all app communication for up to ten seconds at a time — while Upload Speed Sense read the stall as congestion and cut your upload cap twenty percent per tick. The keepalives themselves are a handful of 44-byte packets and were never the throughput sink. Each buddy connection now has its own writer
  • Relayed traffic oversubscribed the line it was sharing. The peer-relay bridge copied bytes on top of the token bucket rather than inside it, so upload slots still believed they owned the whole cap. High ID nodes that serve as a buddy are the same nodes that donate relay, which is why the two read as one problem
  • A partial file could serve bytes whose hash check had been withdrawn. An upload session caches what it knows about verified parts for half a second, which is safe when a part has just become verified and not when it has stopped being — a failed whole-file hash reopens parts, and until the cache expired the session went on reporting them good and serving them. That is precisely the corrupt-block propagation the check exists to prevent
  • One 22-byte request could be made to cost the whole uploader. A stale-entry sweep ran on every inbound upload request, inside the mutex every uploader shares, and past 50,000 entries also sorted the map — on every subsequent request, because trimming landed exactly at the bound and the next insert crossed it again. The hash comes straight off the packet with no possession check, so a peer cycling distinct hashes chose when that began
  • An upload slot could show more than your whole configured upload limit, and the rows in the Uploads tab could add up to more than the status bar beside them. They were measured on clocks an order of magnitude apart, and a slot that had just started was dividing its first burst by 200 milliseconds. Both now settle over about the same three seconds, pinned by a test rather than by a comment, and a row leads the total through a change rather than trailing above it
Downloads
  • A finished download sat waiting out a source’s read timeout. The row read 100.0% with no speed and a status of Downloading (Idle): one worker was parked in a read when another closed the last gap, and since completion is only re-checked between packets it kept its claim and the file never moved to verifying. Bounded rather than stuck — it would have released within 100 seconds — but a finished file has no reason to wait on a source at all, and the peer that merely lost the race is no longer recorded as having timed out
  • Ember was paying peers to send bytes it already had. A worker cut its request list once on entering a part and then streamed it out across the whole part, so a second worker on the same part re-requested ranges the first had already landed: the peer paid to send them and Ember dropped them on arrival. On an 8.7 MB file that read as 18.2 MB transferred. Every batch is now filtered against the live gap list immediately before it goes out
  • Rarest-first had quietly turned itself off. The table that tracks how scarce each part is was seeded once and drained by every source that exited, with nothing adding contributions back — so by the retry rounds it believed there were no sources at all, every part fell in the “very rare” bucket, and both rarest-first and the endgame tie-break stopped discriminating between parts for the rest of the download
  • Downloads could park forever waiting for a connection. The reserve that keeps the upload listener from being crowded out had a floor but no deadline, so on a node with a busy upload queue every outbound source dial could block indefinitely — each one holding a per-file source slot and reading “connecting” on screen. eMule does not wait here at all; Ember now yields after thirty seconds, which is already more patient
  • A finished download was read end to end three times. The three digests were checked one after another, each starting over at byte zero — three full passes over a multi-gigabyte file on the drive you are waiting on, on both the single-source and multi-source paths, and again on restore re-verification. One pass now, and it tells the library scheduler the drive is in use so a background scan does not read alongside it
  • The part hashes that verification had just computed were thrown away, and then recomputed by reading the entire file again. The callback and single-source path never obtains them from a peer, so it took that fallback every time — on a file it had finished reading moments earlier
  • The chunk map truncated past 10,000 parts while the legend beside it described the whole file, so a 593 GiB download drew its first 15%. Parts are bucketed now. Its screen-reader description also stated the opposite of what it drew, calling the swarm’s holdings your own
The Library
  • Reload was re-reading the whole library for an optional digest. Reload itself matches on path, size and modified time and re-reads nothing, exactly as aMule does; the difference was entirely a one-time hash that older records lack. Making the scan wait for it conflated “the Library is incomplete” with “the Library could be slightly better”. The banner now says what the pass is and that your files stay shared throughout, and the stop dialog works out whether there is actually anything to warn about before warning — in a pure migration there is not
  • A cold start hashed one file at a time across four drives. Startup indexing was the last hashing path still doing it the old way, with no per-device scheduling and no awareness of reads it did not start — on the path that runs before anything else works. It now reads one file per physical drive at once, and more only where a drive has positively reported that its reads do not seek
  • The digest pass read every copy of the same file. It queued by path, so a library holding the same content under three names paid three whole-file reads for one answer — on a pass whose entire design is about being gentle with the drives
  • Stop did not stop, and lost work while not stopping. The cancel path put back the batch it was holding but not the files queued behind it, and because nothing clears the seen-list, every one of those paths was skipped for the rest of the session — still published with no digest, with the interface reporting idle. Separately, a scan already past its own check could start the drives again moments after you pressed it
  • Exiting could half-write your shared-file catalog. Several entry points into scanning did not consult the shutdown flag, so a folder change made hours earlier could release a parked job during shutdown and start a fresh reload that updated the catalog behind the authoritative flush. The wait that promised to keep scans out of known.met “while we’re flushing it to disk below” was also running after that flush, where it protected nothing
  • Progress events were emitted per file with no throttle, so on a fast disk the interface received thousands of them a second and re-rendered for each — it got less responsive the faster your drive was
  • A wedged read bought one file rather than progress. The grace period that lets a scan stand aside for another reader was re-read from a value every hand-out clears, so against a read that never returns the pass advanced one file every two minutes, forever — on a large library, the exact hang it was written to break
  • A timed-out hash stopped counting against its drive while it was still reading it, so the drive looked free and another read started on top — one extra concurrent read per device per timeout, on precisely the failing storage the timeout exists for. Drives that cannot be identified at all, which is every network share on Windows, now count against one conservative group rather than being treated as invisible
What an idle node was doing
  • About 30 GB a day of writes to save bytes already saved. The credit ledger had no notion of whether anything had changed, so every 60 seconds it deleted and re-inserted both tables, vacuumed, and rewrote clients.met with an fsync — roughly 100,000 inserts and 33 MB a minute at the record cap, on a node whose peers had all gone quiet. The recovery-hash file was the same shape on a 120-second timer. Both now check first, and a write that fails keeps the record dirty rather than letting a later success clear a debt only half paid
  • The five-second refresh behind the Library held a write lock while doing 2.2 million string operations. It rebuilt every file’s statistics and badges from scratch whether or not anything had moved, and a library big enough to overrun the interval turned that into a continuously held lock starving hashing, scans and everything reading the library
  • The known-peers snapshot enriched 50,000 records and threw 90% away. Ident state, credit ratio, two hex encodings, an address parse and a country lookup each, sorted, then truncated to 5,000 rows — holding the credit lock throughout and parking the upload path behind it. It ranks first and enriches the survivors now
  • The A4AF sweep was quadratic in the number of tracked files, running inline on the network loop every eight minutes: at 500 tracked files with ten dry sources each, on the order of a hundred million comparisons in one tick. It is keyed by address now, so the checks it makes are probes rather than walks
  • A single inbound re-ask cloned the entire upload queue, thousands of allocations for one datagram, up to twenty datagrams per turn of the loop
  • Room maintenance ran four full database queries a second on the network loop, each one blocking, each one evaluated before the checks that decide whether any work is due — so the cost was paid whether or not anything happened. They share one five-second view now, and the presence write is batched rather than forcing 86,400 fsyncs a day
  • The rendezvous connection was rebuilt for every request. A fresh client per call means its connection pool dies with it, so there was no keep-alive reuse at all — about 86,400 DNS resolutions and full TLS handshakes per day against one server, plus an extra round trip before each one to re-ask a question whose answer never changes
  • Two caches evicted by scanning for the oldest entry — 8,192 comparisons on the network loop for every fresh handshake, which any unproven peer could ask for. Four more collections were insert-only and are now pruned where the rest of their family already is
Searching
  • A global search reached two or three servers out of a hundred. Both eD2K legs shared one result counter, and the connected server answers in a single large batch while the UDP sweep leaves at one packet every 750 milliseconds — so the first reply filled the budget and the sweep was cleared before it had asked anyone. What your connected server indexes says nothing about what the others hold, which is the entire reason that leg exists. The two are counted separately now
  • The server could never be asked for a second page. Asking required a full batch and a source count below a hundred, but the batch was charged before the count was read, so a full batch guaranteed the second condition was false. The five-page budget was unreachable on exactly the queries where the server said it had more
  • A KAD keyword walk stopped querying at 25 of its 45 seconds, holding back a flat twenty-second margin that was twice what the timeout it protects needs. That is forty percent more querying window on every keyword, source and notes lookup
  • Quoting a word could make a search return nothing. The boolean path had a word-splitter and a lowercaser of its own, and both disagreed with the one Ember publishes under in the two ways that matter — so a file published under one no-break-spaced word was searched for as two. An operator, a quote, a bracket or a leading dash anywhere in the query was enough to reach it
  • A decimal in a size filter broke every search on every network. The size boxes accept any number, and typing 0.1 with the default MB unit produces a fraction of a byte, which the backend rejects before the query runs — with an unhelpful error and no results. Worse, the value was saved, so it survived restarts
  • A file you are seeding could be hidden from your own search. The spam heuristics score a result set rather than a file, so a flood advertising many hashes under a name that collides with something you share pushed your own copy over the threshold — your file, in your own search, with the attacker choosing which one by choosing the name. A file whose bytes are on your disk and hash to exactly that id cannot be fake
  • Both source counts in the results list were aggregated by the wrong rule. Complete Sources took the maximum where eMule sums across servers, so two servers reporting three and five gave five rather than eight; KAD availability summed where eMule takes the maximum, so it climbed with the number of nodes that answered rather than with the size of the swarm. Kad-only rows now show ? for Complete Sources, as eMule does — a KAD publisher’s count is a claim about a swarm it cannot see, and showing it is how Ember could print more complete sources than sources
  • Disconnecting KAD left the search tab spinning for its ten-minute grace, kept the UDP queue draining, and left the Ember walk running. Replies also carry the request they were made for now, so a late answer cannot land in a tab that never asked the question
Networks
  • Disconnecting KAD took the eD2K server down with it. That was deliberate, justified by a comment calling this the app’s single Disconnect — but the command has exactly one caller, the Disconnect button on the KAD Network page, and there is no global offline switch anywhere. It also revived an upload exemption the old code admitted was dead, since it keyed on a server session that the same handler destroyed moments after checking for it
  • Leaving KAD threw away what a live server session still proved. It wiped the external address and declared the node firewalled, on the reasoning that a new KAD session has to re-establish both — which held only while the same handler also dropped the server. A High ID session proves your address by connect-back and proves your TCP port is reachable, so hole punching, relay and source records were left with no notion of where you are, and you were advertised as firewalled while a server was demonstrably connecting back
  • The KAD page says when it has left nothing that can answer “who has this file”. Sitting out KAD is a supported choice rather than a fault, so it gets a warning of its own rather than borrowing the error colour
  • Reputation bans could not expire. A fresh 24-hour ban was armed whenever the score sat at or below the threshold — including on a successful chunk — so a peer that was recovering pushed its own ban forward on every interaction and the path that restores a usable score never fired for it. Eviction under table pressure also shed the records closest to a ban first, which is exactly forgiveness for the worst peers
  • A source that had failed was retried against the wrong clock, and the bootstrap-cache tests could poison each other between runs, which is why two of them went red intermittently on a tree where nothing near them had changed
Channels and the rendezvous server
  • Room names were unique only up to case. There was no confusable folding, so Lobby and a second Lobby whose “o” is a Greek omicron were two separate claimable names — and since creating a room is unprivileged, anyone could stand up a room visually identical to an established one, have it served to every client’s Discover directory, and land it adjacent to the room it mimics, because the directory sorts by name. A retired name was exposed the same way, one homoglyph at a time, to a room with no owner left to object. Usernames were never reachable this way
  • The room name shown in Discover was covered by no signature. The claim was verified over the normalised key and the registry was then handed the raw name, which is what the directory publishes — so the bytes shown to every user were authenticated by nobody. Both strings are signed now, length-prefixed, under an opcode of their own so a legacy signature can never be reinterpreted as one of these
  • The rate limiter amplified the flood it exists to stop. Once its table filled, every request from a new address ran a full scan under the lock that gates every rate-limited endpoint — and the condition that fills it is a flood from many distinct addresses, in which every entry is fresh and the scan frees nothing. One request bought roughly 200,000 units of work with every other endpoint serialised behind it
  • A failed registry replace on Windows lost the registry entirely, releasing every username and room-name claim for anyone to re-take. The old copy is moved aside rather than destroyed now, so a previous registry exists at every point in between. Production runs Linux, where this does not arise; this is for anyone self-hosting
  • A destroyed room could be re-published by the owner-publish pass, which was reading a roster cache that nothing invalidated on delete. And a queued Ember friend lost its session every 40 seconds, because the keepalive sat below a branch that returned before reaching it
Linux and the desktop
  • “Open file location” did nothing at all on Cinnamon. The reveal path tried three file managers in turn with a --select flag; Nemo has no such option, and rejects the whole command line when it meets one — but it started, and the success test asked whether the process started rather than whether it did anything, so the fallback underneath was unreachable. Nemo is Linux Mint’s default. The freedesktop interface for this action is tried first now, which Nautilus, Dolphin, Nemo, Caja and Thunar all export, and which reaches the file manager you actually chose
  • The Library’s “Open folder containing the file” opened the grandparent, on Windows as much as Linux — it resolved the containing folder and then asked to have that revealed, which opens the folder above and highlights the one you asked for
  • A right-click in a transfers pane could only ever offer Reload, because the pane answered no right-click of its own and the webview supplied its own menu — where Reload throws away the page you were looking at. That is the stray reload behind the lost search results and the emptied server log. The panes have real menus now, including over an empty list, which is exactly where somebody with nothing in the list would right-click
Tables and the interface
  • The KAD Searches table slid sideways every five seconds. It was the last table outside the shared column system, so it declared no widths and the browser re-derived every column from its widest cell on each refresh — the whole row moved whenever a packet counter gained a digit. Its header now opens the same show/hide menu the other tables use, its columns drag and persist, and the Key column reveals more of the hash as you widen it rather than repeating the same prefix
  • The Queued tab’s headers did nothing when clicked, because that table had no sort at all — no state, no comparator, no handlers. All ten columns sort now, and the country flag column, which had no header text and did not sort in any of the four tables showing one, sorts everywhere
  • Eight Settings controls were unreachable through the new filter, including Open log folder, Choose Backup File and the updater’s Install button — a card was scored on its fields alone, and plenty of a card is not a field. The mirror image was also true: unmarked blocks leaked into every card that survived on some other match
  • The known-peer tab counts were frozen at whatever the page’s first fetch happened to see, because the poll behind them ran only while you were already looking at the tab the number describes. They also counted the whole ledger while the table they open is capped, so the label jumped on every tab switch
  • A transfer row bar could read 100.0% beside a still-downloading label, because progress deliberately holds a byte back until parts verify and rounding was turning that hold into a finished-looking bar. A row whose bytes are all on disk now reads Finishing
  • The IP filter page could leave you with no data, no error and no spinner, when a visible refresh was superseded by a quiet background fetch that then failed and suppressed its own error. Whichever request supersedes a visible one now inherits the obligation to resolve it
  • A pasted name carrying an invisible line separator was rejected with nothing to explain why, and the Ember join warning could re-arm its grace period forever on a connection oscillating around zero verified contacts, so the timeout never fired

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.6.5...v1.6.6

Ember v1.6.5

v1.6.5

A hotfix, from reading Ember’s transfer code against eMule’s line by line. Almost everything it turned up was about the peers Ember was quietly failing rather than the ones it was serving well: the slow ones it asked for more than they could send before their own timeout dropped us, the ones that all held the same piece of a file and were told they had nothing we needed, and the ones whose names Ember published to the network under keys no other client would ever search for. Uploads also still stopped when you turned KAD off, which 1.6.4’s notes said was fixed and was not.

Before you upgrade

  • The Ember DHT wire version is unchanged at version 4, so 1.6.5, 1.6.4, 1.6.3, 1.6.2, 1.6.1 and 1.6.0 all see each other on the overlay normally. This is a compatible update; anything older than 1.6.0 is still invisible to all six
  • Transferred will now read higher than Completed on some downloads, and that is correct. They were the same number before and are two different ones now, the way they are in eMule: Transferred is everything that came down the wire, and Completed is what is on disk. A part that fails its hash check has to be fetched again, and those bytes really did cross your connection, so they are counted. Everything that should be a fraction of the file — the percentage, the progress bar, the time remaining — uses Completed
  • Keywords are published the way eMule publishes them now, so a few files were reachable before this release and are not for a short while after it, until their old records lapse and Ember republishes them correctly. Nothing to do; it settles on its own

What’s Fixed

Downloads
  • The slowest peers were the ones that could never finish. Below about 9 KB/s eMule deliberately asks for one or two blocks instead of three, because a fast uploader hands over 540 KB in a moment and then waits for a slow downloader to drain it — and gives up after 40 seconds of that. Ember asked for three regardless, which is over two minutes of data at 4 KB/s, so the uploader timed out and dropped us. Being slow then put us on the same kind of slot next time, so the peers the smaller request exists for were exactly the ones that never got it
  • A download could sit at nothing with every source reported as having no needed parts. When the peers for a file all hold the same piece, which is the ordinary situation early on, the first one to arrive claimed it and every other one was turned away — including while that first peer was still sitting in a queue waiting for a slot, which can be hours. The status said “No needed parts” about peers that plainly had the part, so there was nothing to suggest it would ever resolve. It would not have
  • Two peers working on the same piece no longer fetch the same bytes as each other. Each one now knows what the others have asked for and works around them, so a file being pulled from several directions at once stops spending your connection twice on the same data
  • A peer that disconnects part-way through a block no longer costs the whole block. Compressed data was held until all of it arrived and only then written, so a peer that stopped mid-block took every byte it had already sent with it. What arrived is kept
  • Two more statuses stopped claiming a peer had nothing you need. One meant every piece it holds is already being fetched from somebody else, and the other meant the peer had simply used up the slot it gave you and put you back in its queue — which is where eMule puts it too. Both are ordinary and both pass; neither says the peer is useless now
Uploads
  • Disconnecting KAD really does leave your uploads running now. 1.6.4 said this was fixed. It was not: the exemption it added asked whether an eD2K server was still connected, but the same disconnect goes on to drop the server itself a moment later, which put the block straight back. eMule stops the server connection and KAD and never touches its listening port, so a peer already queued with you can still finish — and Ember matches that now. Uploads come down for shutdown and nothing else
  • A slow upload slot is no longer starved until its peer gives up on you. Every slot raced for one shared allowance, so a slot whose peer was slow could wait in that queue past the 40 seconds its peer allows before dropping the connection — and being dropped for slowness put it back in the same position. Each slot now gets its share of the line, and a slot that is being passed over still gets enough to stay alive, which is what eMule does with the ones it cannot afford to feed
Searching and publishing
  • Some files could not be found by anybody, including you. A file is published under each word in its name, and Ember disagreed with every other client about what a word is: it split names on any kind of space where eMule splits only on a normal one, so a name containing a no-break space — common in names copied from a web page — was filed under keys nobody searches. It also lower-cased names in a way that changed their length for some non-English letters, which changes the key outright. Names are broken up and folded exactly as eMule does them now, so what you publish is what other clients look for
  • Source exchange no longer hands out peers nobody can reach. Ember passed on firewalled sources, which can only be reached through the one server they happen to be signed in to; eMule leaves them out for that reason. They filled up the limited number of sources a client keeps per file and were counted in its source total while being unusable
  • A source that fails is retried on the right schedule. How long to wait depends on whether that peer is firewalled, and Ember was deciding from whether you are — so a reachable node re-dialled firewalled peers long before they could have come back, and a firewalled one waited the long interval on peers that had merely blipped
Linux
  • Preview and Open work from the AppImage. An AppImage runs with its own bundled libraries and data paths in the environment, and those were inherited by the file handler Ember launched, which then failed against the system’s own copies. Nothing opened and nothing said why. The handler is launched with a clean environment now
  • Playable media opens in your own player. The in-app player cannot read the internal address Ember serves media on when it is running under Linux’s webview, so the button was there and could not work. Video and audio go straight to whatever your desktop uses
The Transfers page
  • Transferred and Completed are two different numbers. They showed the same one, which made one of the two columns pointless. See the note above for what each means
  • The source list stopped discarding peers that were waiting for a queue slot. Once a download had more sources than the list keeps, it dropped whichever peer it found first with no transfer speed — which is every peer that is connecting or queued, not just the dead ones. So the oldest peer waiting its turn was thrown out and every failed row that arrived after it was kept
  • The counts under a source list add up now. The Failed count was worked out by subtracting the rows on screen from the rows known, rather than by counting failed ones, so it read zero on a paused transfer at exactly the moment failed rows were visible — and everywhere else it counted rows the heading had already left out, so the parts came to more than the total beside them
  • Source rows stop rearranging themselves while you read them. The transferring ones were ordered by speed, which is rewritten about once a second, so the rows most worth clicking were the ones that moved. Sort by the Speed column if that is the order you want
  • A finished or requeued source no longer shows the speed it had when it stopped. The row kept the last rate it was given, so a peer that had completed sat there reading “Done” beside a live-looking figure for the rest of the session
  • Pause, Resume and Stop cannot be left permanently greyed out. If one of those commands never came back — a wedged lock, a database that would not answer — the buttons stayed disabled for the rest of the session with nothing to say so. They give up after a while and tell you instead

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.6.4...v1.6.5

Ember v1.6.4

v1.6.4

A P2P client earns its keep in the hours nobody is watching it, and that is exactly when Ember was worst. A finished download, a friend coming online and a room mention were all announced by in-app toasts that vanish the moment the window goes to the tray. A six-hour transfer died when Windows reached its idle timer, and the Transfers page could not tell that from a stall. And the only speed limits were one pair of numbers, so the choice was between throttling all day or saturating the line during a video call. This release is about the unattended hours — and it is the first one Linux is actually part of.

What’s New

Linux
  • Linux is a published platform. Every release now carries an x86-64 .deb and an AppImage alongside the Windows installers, built on Ubuntu 22.04 for its glibc baseline, and signed with the same key. Install the .deb with your package manager, or mark the AppImage executable and run it
  • Both formats update themselves, the way the Windows build does. Ember notices which format it was installed from and updates with that one — a .deb install goes through dpkg and asks for authentication, an AppImage replaces itself in place. The release manifest and the package are both signature-checked before anything is installed
  • Ctrl+ and Ctrl− zoom the interface, so a compositor whose display scale never reaches the webview can be corrected by hand
Desktop notifications
  • Ember can tell you about things while you are not looking at it. A download finishing or failing, a friend coming online, a message from a friend, and — if you switch it on — a room mention. Every one is composed and translated in Ember and handed to the desktop, so they read in your language rather than the backend’s
  • Nothing fires for something you are already watching. A window that is on screen and focused counts as watched; one sitting behind an editor on a second monitor does not, which is the case that matters. Identical notifications collapse, a burst is capped, and room notifications pass every suppression the in-app toast already applies — a muted room or an ignored member can never reach the desktop
  • Each kind has its own switch in Settings > General, under one master toggle, with room messages off by default
Leaving Ember running
  • The machine stays awake while transfers are working. Only the system, never the display — an app that keeps a monitor lit all night to seed a file is worse than the problem it solves. A download with no sources does not count, and neither does one Ember has already called stalled, so a laptop is not pinned awake by a transfer that is going nowhere. Windows only for now; the toggle disables itself where there is nothing to hold
  • The tray icon reports the current rates while the window is hidden, which is the one status surface available from there
Bandwidth schedule
  • Day and night limits, as eMule had them. An ordered list of rules, each naming weekdays, a window of local time, and the upload and download caps that apply inside it. The first matching rule wins, and when none matches your manual limits apply unchanged
  • A window may cross midnight, and its days name the day it opens — so Mon 22:00 to 06:00 needs only Monday ticked, which is how a person reads it
  • Settings names the rule in force and the time it runs until, because a user whose overnight rule is open would otherwise see one number in the field and a different speed everywhere else, and conclude the limit was broken
Servers
  • The server list says how much room a server has. Max Users and Max Files/User sit beside the live counts, both sortable, with servers that advertise no limit held at the bottom whichever way you sort — and one inside a tenth of its user capacity is flagged, because nobody should have to divide two columns in their head on every row. Ember already read all three limits out of server.met and discarded two of them, so a large library now has something to pick a server on: a server that caps each user at a few thousand files cannot represent it, however many users it has

Before you upgrade

  • The Ember DHT wire version is unchanged at version 4, so 1.6.4, 1.6.3, 1.6.2, 1.6.1 and 1.6.0 all see each other on the overlay normally. This is a compatible update; anything older than 1.6.0 is still invisible to all five
  • On Linux, prefer the .deb. The AppImage needs FUSE — libfuse2 on Ubuntu 22.04 — to start at all, and it is built against glibc 2.35, so it runs on Ubuntu 22.04, Debian 12 and newer but nothing older
  • Notifications are on, room messages are not. A room you are in can be busy in a way a chat is not, so that one is opt-in; everything else follows the master switch in Settings > General
  • Adding a schedule rule copies your current manual limits into it, so a new rule changes nothing until you edit it. A rule set to zero means unlimited for its window, which is worth knowing before you type one

What’s Fixed

Security
  • A peer could put a working hyperlink in a desktop notification. Linux notification servers parse the body as markup, and Ember passed peer-supplied text — a file name, a chat preview — through unescaped, so a file named as an <a href> rendered as a clickable link that the desktop attributed to Ember, outside everything the app’s own content policy covers. Markup is escaped now on the platforms that read it
  • Peer-dialing diagnostics no longer exist in a release build. Two harness commands that dial an arbitrary address and ask it for sources were compiled into release binaries, unregistered but present; they and everything only they use are now debug-only, like the rest of that family
  • The webview no longer holds file-picker permissions it never used. Every dialog in Ember is opened from the backend, so the two IPC grants left over from a removed frontend binding are gone
  • A room file transfer could write outside your download folder. The channel receive path used plain filesystem calls by pathname — no approved-root check, no identity pin, no refusal of reparse points — while the name it wrote to was derived from a transfer id decoded straight off the wire. The sending peer therefore chose the path: a symlink planted there was followed and truncated, and a junction at the download folder was traversed on completion, landing a peer’s bytes under a peer-chosen name outside the root. It also wrote to a root whose approval had been revoked, which is the condition the re-approval prompt exists to gate. It goes through the same helpers every other download path does now, and a swap underneath a transfer is refused at completion rather than moved into place
  • Adding an eD2K server asks first. Logging in to a server sends your ed2k user hash, nickname and ports, exposes your public IP, and pushes your entire public share list — and any renderer request could previously introduce and attach to a server of its choosing. Ember already collects native consent for strictly weaker disclosures, so the destination is now confirmed natively when a server is added, showing the host both as typed and as resolved. Connecting is restricted to servers already in the list so the prompt cannot be stepped around, the default community server.met is exempt by byte-exact comparison, and asking on addition rather than on connect keeps reconnects prompt-free
  • Queue seniority is no longer inherited from a user hash alone. That hash travels in the clear, so replaying a disconnected peer’s hash collected its accrued wait and jumped the queue ahead of everyone who had actually been waiting
Transfers and limits
  • A schedule rule with an absurd speed would have killed every rate-limited transfer. Rule speeds reached the limiter without passing the ceiling the manual limits pass through, and a large enough one overflowed the token refill, stopped the task that grants bandwidth, and left every limited transfer to abort — once per session, each time that window opened, because the rule is saved. Rules are now held to the same 100 GiB/s ceiling, on save and on load
  • The limit shown in Settings is the one in force. While Ember’s upload slow-start is still finding your line speed it holds uploads below the configured cap, and the banner reported the cap rather than the throttle
  • An upload nobody is downloading from stops keeping the machine awake. An upload row holds its slot whether or not the peer is still asking for blocks, so a peer that connected and went quiet counted as work indefinitely — the same indefinite hold the stalled-download rule exists to prevent, on the side it could not see
  • Sleep is only reported as deferred when it actually is. If the OS refuses the request, Ember backs off rather than asking every second — and used to go on claiming the machine was being held awake for the whole of that window
  • A crash in the bandwidth machinery no longer takes your transfers with it silently. The task that grants bandwidth and the one that re-resolves the schedule had none of the panic containment the network task carries, so a fault in the first aborted every rate-limited transfer for the session with nothing on screen to say why, and a fault in the second left an open throttle window outliving itself. Both are contained now, and the schedule monitor restarts
  • A paused download could be brought back as active with nothing running it. A firewalled peer calling back was not checked against the pause, so the row went active, the worker died immediately on the cancelled control, and the failure was suppressed as a user cancel — leaving a transfer that reads Active, has no worker, and cannot be resumed, holding one of your download slots for the session. A late verification event could overwrite Pause and Stop the same way, and resuming a transfer that had stopped for disk space did nothing at all unless it was resumed on its own rather than with others
  • A finished download can no longer un-finish itself. A late duplicate failure from a worker that raced completion wrote a failure onto the completed row and queued a status write that outranked the completion, so the file came back as incomplete on the next launch and downloaded again
  • Healthy sources stopped disappearing from the source list. Three routine states — too many connections, every remaining part already in flight, and a firewalled peer that has just called back — had no entry in the table the interface reads, so they fell through to Failed, and the drawer deletes failed rows. Peers were being erased from view for being ordinary. Rows that stop for disk space or for having no needed parts also showed a frozen speed and a counting-down estimate forever, and a queue position was blanked by any update that did not restate it
Uploads
  • Uploads no longer stop because KAD did. The upload gate was keyed to KAD’s connection status, which has no part in serving a file — that needs the shared file, the listener, and for a LowID a server to relay callbacks. So on a session running a server without KAD, the first brief server drop stopped every upload and nothing turned them back on. An explicit Disconnect was also being undone about two seconds later by the reconnect logic, leaving a node that read “server connected” on screen and refused every upload for the rest of the session
  • Ember was banning the peers it seeded to. The bad-request counter only ever rose and its expiry was refreshed by every request, so an actively downloading peer’s entry never aged out and two infractions any distance apart were enough. Ember then manufactured those infractions itself: the uploader rotates a peer out when others are queued, and the peer’s own client answers by asking again. Roughly 19 MB of honest seeding reached a threshold that applies a seven-day IP ban surviving restart — so an unattended node worked its way through its own swarm. The counter falls again when a peer waits out the window, and a rotation Ember asked for is no longer charged to the peer that complied with it
  • One parts request can no longer be expanded without bound, and the set of ranges a long-lived session has served is bounded rather than growing for as long as it stays open
  • Three requests that each read an entire shared file to answer about 22 bytes are now metered per connection. They need no slot, no queue position and no identity, and the small caches in front of them miss every time against a peer cycling more hashes than they hold. A full share listing — which walks the whole index and can reach 500 KiB in reply to a six-byte request — is one per connection per minute
  • One peer can hold one upload slot. Slot admission counted slots without asking who held them, so a peer opening the three connections an address is allowed and identifying as the same client on each could take a slot per connection — three of four on a quiet queue. eMule merges a second connection from a known client into the first, so the slot belongs to the client; it does here now too. A waiting peer also can no longer name a high-priority share to inflate its queue score before we have agreed to serve it that file
  • Everyone behind one address is no longer banned for being busy. The per-file request tracker was keyed on IP with no client identity, so ordinary interleaved requests from two eMules behind one NAT, campus or VPN looked like a single peer re-asking too fast — and two strikes banned the whole address for seven days. eMule counts these against one client, and so do we. The connection-rate ban, which eMule has no equivalent of at all, is scaled to the number of clients an address is actually allowed
  • Answering a cached hash request no longer stalls the rest of the app. Once a file’s recovery data was cached, each 20-byte request for it rebuilt the whole-file hash tree on a runtime worker rather than a background thread, so a peer could loop the request and starve downloads, KAD and the connection accept loop. Duplicate sub-requests inside one packet also each produced a complete answer; thirty-two of them in 48 bytes produced thirty-two
Downloads
  • A verified part could be committed over another source’s repair. The hash is computed with no lock held, across an fsync and sometimes an 8s wait, and several sources verify the same part by design. In that window another source can find corruption and reopen the gap — and committing anyway erased the repair and flagged the part verified over bytes nobody had hashed in their current state. That flag persists, survives a restart, and decides what is safe to serve, so Ember advertised and uploaded the unchecked bytes to peers as verified. The commit re-checks inside the write lock and re-hashes instead
  • A cancelled download stopped writing when you cancelled it. The abandon message was sent in a way that is dropped silently on a full queue, and it was the only mid-queue exit, so a deep queue on a slow volume executed up to about 720 MB of unwanted writes, missed its cleanup budget, and orphaned the part file on Windows
  • Resuming a queued download keeps its place. With the concurrency cap full, resuming demoted the transfer behind every other entry of the same priority — invisibly, so it read as the resume having been ignored
  • A resume whose part file is gone starts over rather than trusting a tracker that still claims progress
  • Multi-source downloads stopped leaking part claims on the re-queue that fires about once per part, which had been defeating the anti-herding those claims exist for and leaving a download unable to settle. Abandoned compressed fragments are pruned at each exit too; sixteen of them were enough to drop an actively transferring peer, which reconnected and did the same thing again
  • Ember stopped asking peers for a file faster than eMule permits, which was earning it bans. A source that failed the handshake was re-dialled every 60 seconds, and eMule uploaders ban a user hash that re-asks inside MIN_REQUESTTIME — about ten minutes. Ember’s own uploader enforces that same rule, so a pair of Ember nodes could ban each other where two eMules would not. The floor is now the real interval, and the UDP re-ask no longer reads its “never asked” marker as decades overdue and pings seconds after the file request for the same hash
  • A peer that put us in its upload queue is no longer treated as a failed source. Queue full, dropped while queued, pushed back to a rank mid-transfer, and holding nothing we still need are ordinary eMule states, and marking them failed cost the peer reputation and dropped it out of the set the inbound slot-grant index is built from — so the sources closest to handing over a slot were made ineligible to receive it. An empty queue-full packet is also read as queue-full again rather than as a broken file-status exchange, which shares the same opcode
  • The handshake is byte-identical to eMule’s up to the file request again. Ember’s own identification packet was being sent between the client info and the file request, which is the window anti-leech mods inspect, and a stalling peer could hold a download at nought per cent for close to half an hour because every handshake read was given the 100-second budget meant for a transfer in progress
  • A download could park itself indefinitely with sources available. The wait for newly discovered peers was restarted by peers that turned out to be unusable, so the retry rounds — the only thing that re-dials a known source once its cooldown expires — never began. Separately, a cancelled write reservation could leave a gap in the file that no peer was ever allowed to fill, which made the download uncompletable until restart
  • Part hashes from peers that follow eMule’s known.met convention are accepted. For a file whose size is an exact multiple of the part size, eMule writes one extra empty-block hash; Ember rejected that form outright, which silently disabled per-part verification for the file’s whole life, left error recovery with nothing to work from, and meant one bad block surfaced only at the final whole-file check. That check now re-opens just the parts that actually mismatch instead of the entire file, and the recovery hash we ask every capable peer for is no longer discarded on arrival
  • A part file’s sidecar is no longer trusted to say which of its own bytes are good. Archive recovery read both the part hashes and the verified map out of the same unauthenticated file it was checking, so a stale or edited sidecar could have its contents “verified” against its own hashes. Two ways a corrupt sidecar reported never-received bytes as present are closed as well, and both now fail towards re-downloading rather than towards serving
Notifications
  • A conversation open on a second monitor now notifies. Having the chat or room on screen was treated as reading it, even with the window unfocused behind something else, so the one case a desktop notification is for was the case that stayed silent
  • One unusable notification no longer silences the rest of the session. A message Ember could not title was treated as proof the desktop had stopped accepting notifications at all, and there was no way back short of restarting
  • The burst ceiling counts correctly under concurrent notifications, rather than letting a handful arriving at once each see a full allowance
  • A notification held back by the burst ceiling no longer suppresses the real one. The duplicate check recorded as a side effect and ran before the ceiling, so a flurry registered entries for notifications that were never shown and a genuine re-send was then swallowed as a duplicate of something invisible
Linux
  • Sharing a folder no longer rescans it forever. Linux reports a directory being opened, and the indexer’s own walk of a shared folder therefore looked exactly like a user adding files: scan, event, rescan, once every couple of seconds, rewriting settings and re-announcing to KAD each time. Events are read by kind now — a finished copy still rescans, reading a folder does not
  • A desktop with no notification area still starts. A tray icon that cannot be built is an ordinary Linux environment rather than a failure, and it was aborting startup
  • Checking for updates no longer reports a failure when the published release carries nothing for your platform. The check said it had broken; it had simply found nothing
  • The .deb declares the packages it shells out to for opening files and registering ed2k:// links
Settings
  • Save says which rule it is waiting on. A schedule rule the backend would refuse now blocks Save with the reason on the row, rather than failing the whole save with a message that named no rule — and a rule the backend would have accepted no longer blocks it, which a label of emoji used to do
  • Turning the schedule off takes effect on screen immediately, instead of leaving the old rule named in the banner for a second after the limits behind it were gone
  • A hand-edited schedule cannot cost you every other setting. A malformed rule is dropped on load, as a shared folder or an out-of-range number already was, rather than resetting the whole profile to defaults
  • The timetable is hidden while the schedule is switched off. It was dimmed rather than hidden, and a card of day pickers and speed fields governing nothing is a card the reader has to work out is inert. The rules are kept, not discarded — switching the toggle back brings them straight back — and the editor still appears, dimmed, when a rule would block Save, so there is no way to be refused a save with nothing on screen to fix
Shared files
  • A corrupt catalog could be replaced with an empty one on the next launch. A crash partway through saving known.met leaves no catalog in place and every byte of it in a backup file. Ember read that absence as “new install, nothing shared yet”, treated the answer as authoritative, and the first periodic save wrote an empty catalog over the recoverable one. It now detects the interrupted save and recovers instead
  • A damaged catalog keeps the records it could read. A parse failure partway through, or trailing garbage, used to discard everything; and an unrecognised tag no longer aborts the record it appears in. The safety copy taken at startup is also no longer remade on every launch — it was producing roughly a gigabyte of timestamped backups per launch against a large catalog — and a copy that fails can no longer pass itself off as having succeeded
  • A failed catalog save withdraws the sharing it could not record, so a crash between two stores can no longer leave a file offered to peers against a catalog that says otherwise
  • Picking a folder that is already shared says so. The folder picker is the operating system’s own dialog, which cannot mark what you already share, and re-picking a shared folder looked exactly like adding one: a scanning banner, then nothing new. Ember now tells you which of the two happened
Rooms and friends
  • A room relay could go one-way for the rest of its life. Two sessions to the same peer overlap as a matter of course — both sides offer a relay over the same roster, so a mutual offer is normal rather than a race — and a close reported by the losing session deleted the surviving one’s outbox. Its reader and socket stayed alive, so messages kept arriving from that peer while everything sent to them was silently discarded. Closes are now matched to the session that owned them
  • Changing the spam filter with search tabs open no longer freezes the network. A rescore accepted 15,000 rows and walked every learned name for each one while holding a lock the network loop takes on the download-complete path — and because it blocks inside that loop, UDP receive, every timer and all app communication stopped with it. The work is chunked and yields between chunks now
KAD
  • Publish rows in KAD > Searches say what they are publishing. The Name column was a dash for every “Publish file” and “Publish keyword” row, which left nothing to tell them apart: their target is a hash, and the maps holding the readable name are cleared the moment the operation finishes while the row stays listed for another fifteen seconds. Each publish now carries its file name or keyword from the moment it is scheduled
  • Buddy endorsements expire by date rather than by arrival order, so a flood of short-lived ones can no longer push out live ones, and an endorsement dated implausibly far ahead is refused
  • Disconnecting KAD no longer stops your uploads. The fix above covers the half of this where a server dropping on its own killed them; turning KAD off by hand still did, because it raised the same gate on the theory that leaving KAD means going offline. It does not in eMule, where KAD and eD2K are independent and running without KAD is an ordinary way to use the client — serving an upload needs a shared file, the listening port, and for a firewalled node a server to relay callbacks, none of which involve KAD. Uploads now stop only when the last thing connecting you goes, whichever one that is
Servers
  • Server messages survive leaving the tab. The log belonged to the page, which is destroyed on every navigation, so a server’s greeting was gone the moment you looked at anything else — and anything that arrived while you were away was never recorded at all, because the listener went with the page. It is kept for the session now, with a timestamp on each line, and follows new messages unless you have scrolled up to read
Windows and tables
  • The transfer tables stopped resizing themselves. They asked for fixed column widths and for a width derived from their contents in the same breath, and the second wins — so columns were sized by their longest cell rather than by the widths you set. One long upload name took the name column from 260 to 549 pixels and pushed two columns off the edge, which is why the layout slid sideways every time a transfer with a long name started or finished. Long text is truncated now, and the columns stay where you put them. All five tables on the page shared the fault
  • The source list of a download sorts, and stays sorted. Clicking a column in Download Clients did nothing: the rows were always ordered by activity, which sorts the transferring ones by speed, so they rearranged themselves every time a speed ticked. Those columns are sortable now and the choice is remembered, with a tie-break that keeps equal rows in the same order rather than letting arrival order show through as movement. A third click returns to the activity ordering, which is still the more useful one while a download is running
  • Copy and paste work on Linux. Pasting an eD2K link reported the clipboard as unavailable however much text was on it: the webview Linux uses refuses to read the clipboard programmatically, and refuses the fallback too, and Ember had no other route to it. Both directions go through the operating system’s clipboard now, which also makes copying behave the same way everywhere rather than depending on how the click arrived
  • Preview stopped stacking whole-file hashes. The guard meant to allow one preview at a time was released by the caller’s 30-second timeout while the work it was guarding — a hash of the entire file — carried on in the background, so clicking Preview again after each timeout started another one. Preview temporary files, up to 64 MiB each, are also no longer kept forever: the previous one is deleted once the new one is written, and a startup sweep clears any left behind by a crash
Everywhere else
  • The bundled country database is September 2026’s, so peer flags and country columns reflect current address allocations
  • Dead code that had no consumer on either side is gone, along with a Settings button that existed to prove notifications worked

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.6.3...v1.6.4

Ember v1.6.3

v1.6.3

Finding things is the theme. Ember can look for the other episodes of what you are watching, ask an availability site why a download will not finish, and return search rows that fill the same columns an eD2K server fills. The repair that matters most is older than any of it: a failed hash check was re-downloading the whole file instead of the small piece the recovery data had already narrowed it to.

What’s New

Related files
  • Search Related, without needing a server that supports it. eMule sends the request to your connected server and greys the menu out unless that server advertises support, which most do not — so the feature usually does nothing. Ember keeps that request as one signal and adds the one eMule never had: release names are structured, so the season and episode marker, the disc or part marker, the year and the title are read out of the file’s own name and turned into searches that run on every network. Right-click a search result, a transfer or a shared file; the tab is named after what it went looking for, and the seed is kept out of its own results
Web services
  • Look a file up on the web, the way eMule does. Right-click > Web services opens a site with the file’s details filled in — most usefully one that reports how many complete sources the network has seen, which is the question a stuck download raises and the one Ember could not answer from inside the app. All six of eMule’s placeholders work, and an existing webservices.dat can be imported
  • An availability lookup is configured out of the box, because a lookup you have to go and set up first is one you will not have on the day you need it. Nothing is contacted until you click it, adding a site of your own asks you to confirm it once, and any entry can be changed or removed in Settings
Ember search
  • Ember results fill the columns a server result fills. Duration, bitrate, codec, artist, album and title now travel with a published keyword record, so an Ember hit is no longer the row with the blank Length and Bitrate. Your library is probed once and the answer is kept — including “nothing to find”, which is the answer for most of a library
  • Ember hits report complete sources. Only complete public shares are published under a keyword, so the number of distinct publishers who signed a record is a floor on the complete sources — a firmer number than a swarm estimate one peer passed on. They used to report zero, which the Min Complete filter read as none and dropped, and which sorted every Ember row to the bottom
  • The Sources column says what it counted. One column, two measurements: a server or KAD node reports a swarm estimate it was told, while Ember counts publishers it verified. Three next to fifty read as a file barely anyone has, when the three are confirmed to hold all of it
  • Searching by extension no longer needs the extension to be indexed. .mp3 as a published key would be the hottest key on the network, competing for one key’s slots on the twenty nodes nearest it. It travels as a constraint on the search instead, which costs no key, no publish traffic, and no hotspot
  • A busy keyword is answered a page at a time. One datagram carries only a few records, so a searcher can now ask the same peer for the next page. A peer is held to a quarter of the search while the walk still has somewhere to go, and may serve the rest once there is nothing left to ask — so a single node holding an uncommon word can hand over its whole index rather than the first slice of it
  • An Ember-only search reports its progress, rather than sitting behind a bare spinner for up to a minute on a cold routing table
Search, everywhere
  • Results already in your library are shown instead of counted and hidden. The table dropped every hit whose only source was your own library while the tab badge still counted them, so a search reporting 31 results displayed 13, and one reporting 605 displayed 3
  • A row shows every source its networks found, not the largest single batch one of them sent. A file thirty KAD nodes published arrives as a dozen small batches, and the row read three or four sources until the search finished
  • A hit says which server sent it, and ed2k:: and related lookups go only to the servers that can resolve them — both used to be walked to the DHTs as if they were ordinary words, spending a search slot to answer nothing
  • Find Sources asks every connected network and puts what they find into the download. It only ever asked KAD, and then handed the addresses back to the interface rather than to the transfer, so the row said “KAD found 3 sources” while the download stayed on the sources it already had. It also held the toolbar disabled for the whole search — up to two minutes
Interface
  • Every right-click menu has one look and one placement rule. Six menus each carried their own copy of the styling and their own hardcoded guess at their own height, so a menu opened near the bottom of the window was placed at the pointer and lost everything below the fold. They now measure the panel that actually rendered, flip when there is no room, group their entries so each separator means something, and keep destructive actions at the bottom
  • The Ember page counts published files against the total to publish — “200 out of 1,240” — so a library that has finished announcing itself is distinguishable from one that has barely started, and the peer count says it is peers connected

Before you upgrade

  • The Ember DHT wire version is unchanged at version 4, so 1.6.3, 1.6.2, 1.6.1 and 1.6.0 all see each other on the overlay normally. This is a compatible update; anything older than 1.6.0 is still invisible to all four
  • Media on search results needs both sides on 1.6.3. Older builds ignore the block rather than mishandling it, so nothing breaks — you simply see no duration or bitrate on their files, and they see none on yours, until they update
  • A web service is configured by default. Opening one tells that site which file you are looking for, which is why nothing contacts it until you click it; remove it in Settings > Downloads if you would rather it were not there
  • A moderator ban in a private room is refused while the room owner is offline. Only the owner can issue a new key, so the ban was being presented as an eviction while the banned member went on decrypting everything sent afterwards. Refusing says something true; the ban works as soon as the owner is reachable

What’s Fixed

Security
  • The peer relay would carry traffic for strangers. Relaying defaults to on, and a signed relay request only had to name a public address — but the attestation it signs travels onward in ordinary peer-exchange blocks, so anyone who had ever seen one could have your node dial an address of their choosing, four sessions wide, two hours and eight gigabytes a direction. A request is now admitted only when the connection’s proven identity is the one that signed it and that identity is a friend, and targets are refused for port 0, non-public space and self-bridging
  • The one transport that could be told to dial an arbitrary host was the one ignoring your block lists. Ember’s QUIC accept path held no handle on ipfilter.dat or the ban set; it reads both now, on the way in and on the way out
  • Opening a link from a message asks you natively first, and refuses hosts that are — or resolve to — loopback, private or link-local addresses, so a link cannot reach your router’s admin page or a cloud metadata endpoint. The prompt the interface used to draw is gone, because a compromised one would simply not draw it
  • Re-approving your download folder needs this session’s file picker or a native confirmation, rather than a flag the interface can set on any save. Re-approval re-captures whatever object now sits at that path
  • Replacing your IP filter from a URL says how many entries it is about to install and waits for an answer, since replaced wholesale means unprotected for that one file
Transfers
  • A failed hash check repairs the part that failed, for real this time. 1.6.2 shipped this fix on the wrong branch — every download that actually runs took the other one — so the completion check still tore down the recovery round-trip it was waiting on, turning a re-fetch of about 180 KiB into a failed whole-file verification and a fresh 9 MB part
  • Pausing a download can no longer leave it Active with no worker, where it sat doing nothing until the app was restarted
  • The Sources column counts the way eMule does. It read active and total off the transfer worker, which only knows about peers whose connection got as far as a request — so peers sitting on a remote queue were missing, and a download with seven of them reported 2/14. Peers on queue are counted, the transferring number is in parentheses, and the total can no longer render below the count beside it
  • A wedged disk fails the download and releases the part file instead of parking it forever on a write that cannot be cancelled, and a file whose size is not representable is refused rather than crashing the app
  • Trust badges no longer break unrelated actions. They were one request per row against a queue the rest of the app shares, which surfaced as other things failing with “Network busy”; batching them also let the rotating window go, so rows stop sitting on “--” for eighty seconds
Backup and restore
  • A restore that failed part-way came back as a half-applied profile. Staged files were moved into place rather than copied, so when one failed — an antivirus holding the database is enough — the rollback put the originals back but the staged copies were already gone. The retry could not tell “rolled back” from “already applied”, skipped them, reported success, and left your machine’s own identity beside the backup’s database: orphaning exactly the credits and friendships the feature exists to carry over
  • A restore that will not fit is refused before it starts, and says how much room it needs, instead of failing halfway through
Search and links
  • A truncated ed2k:// link is rejected instead of crashing Ember. Anything shorter than the prefix being tested — ed2k:// on its own, or a link cut off mid-character — reached the parser from the clipboard or from a click
  • An ed2k:// link on a website imports when you click it. Modern Firefox percent-encodes the separators before handing the link to the OS, so what arrived did not look like a link at all and had to be copied and pasted by hand
  • A crowded results tab stops discarding every Ember row first, and a corrected Ember digest replaces one an earlier batch had guessed — which used to fail the file’s content check on every retry, permanently
Channels and rooms
  • Rooms stop stalling the app. Eleven defects in one subsystem: a relay session that lost bytes whenever a message length arrived split across two reads, a counterpart that finished connecting and then went silent while holding one of the room’s relay slots for the life of the process, and room views rebuilt from the database on every poll
  • An edit or a reaction takes its place in the queue before the write it cannot undo, so a busy moment is a refusal rather than a message only its author can see
Everywhere else
  • The same two search results merge the same way whichever half of the app merged them. File type, rating, comment and the recovery hash were resolved in opposite directions by the interface and the core, so the answer depended on which one got there first
  • A checkbox stops keeping its focus ring after a click, which left a stray outline on rows you had merely ticked

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.6.2...v1.6.3

Ember v1.6.2

v1.6.2

Ember is what the app opens on now, and the networks it needs connect themselves. Two of the repairs matter more than the rest: a compromised interface could have read any file on your disk, and two downloads of one file could write to the same part file at once and corrupt it.

What’s New

Ember is the front door
  • Ember opens on the Ember Network page. It used to open on a table of eMule DHT contacts — the second entry in its own sidebar — and the setup wizard never mentioned Ember at all. KAD has moved to its own page alongside the other networks, and old bookmarks still resolve
  • KAD connects on launch, with no switch to forget. It defaulted to off, which left a fresh install disconnected from the network the rest of the app reads its peers from, while the setup wizard quietly answered the same question the other way. Connecting to an eD2K server stays opt-in, because that is one operator’s machine seeing every request you make
  • “Can people reach me?” is answerable without leaving the page you land on. External IP, firewall verdict, port state, port mapping, STUN and buddy now appear on both the Ember and KAD pages
Friends
  • Accepting a friend request now finishes the friendship. Adding somebody is the approval, but their accept came back to you as a fresh request to approve a second time. The setting behind that is gone; requests from people you have not added still queue
  • You are told when somebody accepts. The reply you were waiting for used to arrive with no sign at all
  • Cancelling a friend request takes it off their screen. Cancelling was purely local, so the other person kept a prompt you could no longer answer, describing an upload priority that somebody who never accepted never had. If they are offline when you cancel, it is retried for up to seven days
  • 1:1 chat shows when a friend is typing, and whether they have read you. Receipts are on by default and the switch is symmetric — turning them off means you neither tell friends you have read theirs nor see when they have read yours
  • Every friend is checked when Ember comes up, rather than the first three, so the list opens with real online state instead of filling itself in over the following twenty minutes
Channels
  • Rooms have a live presence signal. Presence was inferred entirely from DHT polling, so somebody sitting quietly in a room showed offline, somebody arriving took up to five minutes to appear, and somebody who had left held a green dot for twenty. Talking masked it, which is why it was the quiet members who went dark
  • The room list stays up when you walk into a room, and if you close it, it stays closed — including next time you open the app
The Ember Network page
  • Seven counters that say why a routing table is not growing. A node stuck at three contacts looked identical whether its announcements were going unanswered, its peers had nobody to introduce, its IP filter was refusing what arrived, or the addresses it learned never answered — four faults with four different fixes and nothing to tell them apart
  • The contact count is split into the three things it was quietly adding together, and now says when a peer can never become a contact at all. Only one of the three is ever liveness-checked, so the single headline number reported a healthier overlay than the one you had
  • A cold node can join through a friend it is already talking to. A friend is the strongest signal the app has that somebody real is out there, but the only route from a friend to a DHT contact ran around the session rather than through it, so a friend reached over a relayed or NAT-traversed connection was never even attempted
Everywhere else
  • Dark mode reaches the parts that were still light — window chrome, scrollbars, selected rows that vanished into the background, and white glyphs sitting on pale fills — and the window no longer flashes light before the first paint
  • The network dots in the status bar go somewhere. A red dot is the app’s commonest sign that something is wrong, and it was a dead end: the detail was tooltip-only, and you had to already know which of the three networks owned the problem before you could act on it
  • An empty friends list is distinguishable from a list that failed to load, and silenced or removed rooms can be restored one at a time, rather than by a single Clear that wiped preferences you had built up a room at a time
  • The keyboard shortcut sheet matches the shortcuts. It numbered them against the full sidebar while the app counted only the visible entries, so on a profile with the Ember overlay off it named the wrong page for everything below Channels. Settings was the only click-only page and takes Ctrl/Cmd+,
  • Screen readers get names for the things that only had a colour. Presence dots, progress bars, and Library’s star rating, which announced “black star” and “white star” and never said what it was set to. “Copied to clipboard” no longer interrupts mid-sentence

Before you upgrade

  • The Ember DHT wire version is unchanged at version 4, so 1.6.2, 1.6.1 and 1.6.0 all see each other on the overlay normally. This is a compatible update; anything older than 1.6.0 is still invisible to all three
  • Typing indicators, read receipts and request cancellations only reach friends who are also on 1.6.2. Older builds ignore them rather than mishandling them, so nothing breaks in a mixed pair — you simply get no typing signal, no receipt, and a cancelled request stays on their screen until they update
  • The friend approval setting is gone, and its toggle with it. It only ever gated the accept coming back from somebody you had added yourself, and it defaulted to on, which is what turned that accept into a second request. Requests from people you have not added always queue for approval

What’s Fixed

Security and your data
  • A compromised interface could have read any file on your disk. Offering a file to a room took a path from the interface layer and hashed and sent whatever it named, with no check that it sat inside a folder you had shared. Choosing a file is the permission, so the picker now runs in the core, where the rest of the app’s file dialogs already were
  • Two downloads of one file could write to the same part file at once. Restarting a download aborted the previous worker, but aborting does not close the file — the writer keeps the handle until it has drained and flushed, and six of the eight restart paths never waited for it. Two writers on one part file interleave, and the damage surfaced much later as a failed hash check and a full re-download
  • A bootstrap list fetched from a URL could choose which peers this node trusts. Contacts from a downloaded file were taken as already verified and went straight into lookups and publishing without ever having answered us, which is the exact case the bootstrap path exists to prevent. They are unproven seeds now, promoted the ordinary way once they reply
  • Disconnect said “all activity stopped” while it had not. The Ember overlay has no off switch by design and kept publishing, kept dialling friends, kept sending global searches to the server list, and could restart a download you had just stopped. It also reported friends as offline while chat and file offers went on working against them
  • A finished download could be recorded as complete at 95%. Completion wrote its progress, status and history as four separate steps, and a periodic progress write queued beforehand could land after all of them — by which point the file that would have repaired the row was already deleted
  • A relayed callback is refused for a file nobody asked this node to carry, and the long-lived keys behind Ember’s encrypted connections are wiped from memory rather than left there until the process exits
Transfers
  • A failed hash check repairs the part that failed instead of re-downloading the file. A part whose hash has just failed still has every byte on disk, so the file read as byte-complete for the whole of the round trip that would have narrowed the fault down, and the download aborted its own repair — turning a ~180 KiB re-fetch into a failed whole-file verification
  • Preview stops copying the whole file. On a nearly finished download, the run of verified data it copied out was the entire thing
  • A room transfer no longer freezes the app as it completes. The receiving side hashed the finished file on the same task that reads every datagram and runs every timer, so up to 100 MB of hashing on a cold disk cost traffic with peers that had nothing to do with it
  • A room transfer that finishes as you quit is not reported to the sender as a failure. The file arrived intact, but the frame saying so was dropped during shutdown, and the sender has no other way to find out — so its own timer eventually called a completed transfer failed
The Ember network
  • A connection to a peer that has restarted is no longer treated as live. Sessions aged from our last send rather than from the last thing we actually heard, so a peer that restarted or forgot its half stayed “connected” for as long as we kept talking at it
  • One missed ping stops costing somebody else their neighbour. Dropping a silent contact tore down every session on that address, so two peers behind one NAT could lose a working link because of a third
  • Peers behind a busy shared address stop getting stuck half-connected. When a per-address limit shed a session, the handshake answered anyway: the far side believed the link was up, everything it sent arrived here to no session, and it had no reason to handshake again something it thought was working
  • A node that had a full overlay and then lost it recovers without a restart. Suspend, a new network, or a wave of evictions left it enforcing full-network limits against bootstrap-sized numbers for the life of the process
  • A truncated contacts file stops making the loss permanent. Every launch that recovered fewer contacts than the one before wrote the smaller set back over the file
  • Your own searches stop being refused in silence. Background work — room presence, source lookups, table refresh — could hold every search slot, and a keyword search you typed was turned away with nothing said. Background searches yield now, and a slot is released when its search finishes rather than held to the end
  • A node trying to join retries in a minute rather than five. The slow back-off is right for a healthy node deciding what to keep spending on an address that will not answer, but below a working table those addresses are not one candidate among many, they are the whole join
Friends and rooms
  • A read receipt no longer marks the wrong message. Receipts name a line by a hash of its text, and short replies repeat — “ok” sent twice resolved to the copy still waiting to go out, and flagged it and everything before it as read
  • A cancelled friend request is not lost if the other person was offline. The cancellation cleared itself from the retry queue on a local write the far side may never have read
  • The typing indicator stops vanishing on a stale online flag, and delivery status sits under the message rather than inside it
Everywhere else
  • The app stops stalling on its own database. Every authenticated room datagram wrote a row of its own, bulk clear and cancel ran a transaction per row with no limit of their own, and compacting the database held the single connection the network loop also waits on
  • A single forwarded port is no longer reported as a misconfiguration. Setting the TCP and UDP ports to one number is what a VPN forwarding one port requires, and what the setup wizard tells you to do — and the log then advised you to undo it
  • Staying reachable between packets no longer lapses for two minutes at a time. The keep-alive that holds your public port open reused the same connection details every twenty seconds, against the two-minute cooling-off period Windows puts on a closed connection, so it locked itself out of its own targets

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.6.1...v1.6.2

Ember v1.6.1

v1.6.1

Mostly repairs. Four of them lost or exposed something a user cannot get back: a file sent to one person in a room was readable by the whole room, and three separate paths could throw away your identity or your message history without saying so.

What’s New

Channels
  • Edit your own message for fifteen minutes, so a typo does not sit in the room forever. Every receiver checks the author’s signature and two clocks rather than trusting the sending client, and a member who was away is handed the corrected line rather than the original followed by a revision
  • React to a message with a thumb up, a thumb down or a heart, so agreement no longer has to be written as a reply. Reactions travel as a batch, so a room you have been away from does not spend a packet on each one
  • Names on every message and a proper room surface, rather than a handle only on the first line of a run
  • Type @ to complete a member’s handle, so addressing somebody no longer means knowing how they spell it
  • A marker for where you left off, and re-entering a busy room lands you on it instead of at the newest line
  • A way back to the newest message when you have scrolled up, and a resend on a message that never left, so reading history no longer means silently missing lines and a failed send no longer means retyping it
  • Links in a room are clickable behind a confirmation and a scheme check, and slow mode counts down in the composer rather than only refusing the send
Search
  • File details open as a dialog rather than a pane pinned under the results, so opening one no longer scrolls the row you were reading off the bottom of the window
  • Your own library appears immediately when you search, instead of waiting on the network round trip — and stopping the search no longer hides it

Before you upgrade

  • The Ember DHT wire version is unchanged at version 4, so 1.6.1 and 1.6.0 see each other on the overlay normally. This is not the hard break 1.6.0 was; anything older than 1.6.0 is still invisible to both
  • Channel file transfers only work between 1.6.1 peers. The old block format put the payload in reach of the whole room, so it is refused rather than reinterpreted. Offers and downloads between a 1.6.1 and a 1.6.0 client will not complete until both sides update
  • Message edits and reactions only reach members who are also on 1.6.1. A 1.6.0 client does not recognise them and drops them rather than passing them on, so in a mixed room they travel only as far as the updated members can carry them between themselves. The message being edited is unaffected; older members simply keep showing the words it was sent with
  • Turning UPnP on or off now asks for a restart instead of reporting a change the running app had not made. The setting is read once at startup, and restarting is also what removes an existing port mapping

What’s Fixed

Security and your data
  • A file sent to one member of a room was encrypted to the room, not to them. The blocks only ever travelled inside the gossip envelope, and that is sealed with the room’s content key — which every member holds, and which a public room derives straight from the address in its own listing. So sending somebody a file put the bytes in reach of every member of a private room, and of any stranger who could find a public one, while the app said it was going to one person. Blocks are now encrypted to the recipient alone
  • A profile that had only ever used rooms could have its message key replaced. The check that refuses to rotate a lost key only looked at direct messages, so a room-only profile read as having nothing encrypted — and a new key was generated and written over it, taking room history, private-room invites and room key history with it. Chat now locks and waits for the key to come back instead, and a check that cannot answer counts as a reason to stop rather than permission to continue
  • A missing identity file could hand you a brand-new identity. If identity.json went missing while the marker beside it remained — which is what antivirus quarantining one encrypted file looks like — Ember generated a fresh keypair, resetting your KAD ID, user hash, Ember identity, friendships and upload credits. It now refuses and tells you what to restore
  • An old data folder could overwrite the one in use. The one-time migration from Ember’s previous data location ran on every launch, and a stale copy with a newer timestamp replaced the live file — identity, message key, or the database itself, which could be left paired with the wrong write-ahead log and then rebuilt empty. It now only fills in what is missing
  • A download that was interrupted while verifying could finish unverified. Recovering from a crash re-checked the eD2K hash but skipped the stronger content hash a link can pin, which is the check that exists because the eD2K hash alone can be forged. Both are checked now, and a mismatch is final rather than retried forever
  • Transfers with a member who has just been banned now stop. They ended when a moderator’s message named somebody, but not when the owner’s room settings did — which is how a device usually learns of an owner’s ban, so a download from somebody who had just been evicted carried on, and so did an upload to them
  • A stranger can no longer have their uploads charged to somebody else. The publishing allowance on the Ember DHT was tracked by network address, and an address can be claimed by anyone who mentions it — so one peer’s traffic could exhaust another’s allowance and get that person’s own files refused
Channels
  • Missed messages actually arrive now. Asking the room for history you missed was answered with the newest thirty-two lines every time, and storing them moved your place past everything still missing underneath — so a gap wider than thirty-two lines could never close, and those messages were gone from that device for good. Catch-up now works forward from the newest line you hold
  • An edit made while you were away reaches you, and is drawn when it does. The revision used to be sent under the same identifier as the message it replaced, which is exactly the identifier every peer worth sending it to had already filed away, so it died in their duplicate filter — and if it did arrive for a line you had never seen, it was stored without ever being shown until the room was reopened
  • Removing a message from this device keeps it removed. The next copy that came round the room put it straight back
  • Members stop fading to offline while they are sitting in the room, and a newly claimed handle reaches the room instead of waiting out a republish interval
  • A message reaches the whole room rather than the members nearest it in address space, and answering a catch-up or a file transfer no longer looks like flooding to the peer you are answering
  • A muted room stays quiet. It still interrupted whatever page you were on to announce an incoming file, and it did the same for a member you had ignored
  • Unread counts move while the window is hidden. With a room open behind a minimised window nothing counted, and coming back cleared it, so messages that arrived while you were away left no trace
  • Room file transfers respect your upload limit. They were bounded only by the protocol’s own pacing, so a configured limit did nothing for them and they went uncounted in the transfer statistics
  • A repeated file offer cannot swap the file behind Accept. A second offer reusing the same transfer identifier replaced the first, so the prompt could describe one file while Accept fetched another
  • Room settings survive closing the app. A pending key rotation and the notice that you had left a room were held in memory and lost by quitting at the wrong moment
  • A failed send says so — including when you have already moved to another conversation, where it previously appeared nowhere at all — and no longer costs you a turn under slow mode or reverts your text on the next read. An owner-only invite switch that fails to save now goes back to what the room actually says, and removing a room from this device no longer hides it when the removal failed
Search, transfers and library
  • A search result can no longer have its verified hash or its size overwritten by a later, less trustworthy sighting of the same file. Both are handed to the download when you click, so a size could arrive as zero and start a zero-byte transfer, and a content hash from a single anonymous claim could replace the one your own library knew was right
  • Firewalled Ember users can be reached again. A LowID node published the wrong port for the peer relaying its callbacks, so eMule clients called back to a dead port: the source appeared in search results and then never connected
  • Preview plays what has actually downloaded. It assembled every verified piece into a full-length file and left the gaps between them as silence, which players read as the real duration
  • Names keep their bracketed tags, so [PORTABLE] and friends are no longer deleted from every filename before you see it, and a file is downloaded, reshared and published under the name it was actually shared as rather than the tidied label in the results list
  • Unsharing or deleting a file withdraws it from the Ember DHT instead of leaving your own copies answering searches for it until they age out, which is what kept the published count above the shared count after every launch
  • Cancelling a download cleans up after itself rather than leaving .part files behind in Temp, and Pause and Stop no longer skip the flush that makes a paused download resumable
  • The Completed column and the speed reading tell the truth after a failed hash check, where they previously showed the bytes and the rate from before the download rewound
Friends
  • One unusable friend entry no longer hides you from all of them. A single stored key that did not match its own identity made the whole list fail, and the failure was swallowed, so presence was advertised for nobody
  • Pasting a friend code from somebody who has already asked accepts their request rather than creating a second one, remove and block still succeed once the entry is gone, and Ember advertises the port it actually listens on
  • Disable Friend Browse no longer locks your own Browse button — hiding your share list is not the same as opting out of looking at theirs
Everywhere else
  • Reading a long conversation is no longer interrupted by new messages arriving, which used to jump the view and drop the line you were reading once the room hit its display limit
  • The Transfers queue and Known Clients tabs report a failure to load instead of showing an empty list, a bulk library action shows how far it has got, and a toast holds its countdown while it is being read
  • The Friends setting describing the Verified badge now matches what earns one. It claimed an ordinary file transfer could earn it through an identity check that is in fact replayable; only proof of possession on the session counts

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.6.0...v1.6.1

Ember v1.6.0

v1.6.0

Channels: group rooms carried over the Ember Network itself. No server hosts them, and nobody publishes their IP address to the room.

What’s New

Channels (beta)
  • Public and private rooms. A public room is listed in Discover and anyone who finds it can read it, because its key comes from the address in that listing. A private room is never listed and needs an invite. Pick private if the conversation should stay with the people you invite — the choice cannot be changed later
  • A Channel username. Two to twelve letters or numbers, claimed across Ember, so two people in a room are never the same name. Separate from your friend nickname, and needed before you create or join
  • Room tools for the owner. Topic and welcome, up to 6 moderators, up to 12 bans, and owner-only invites for when a link should not be re-shared. A private room’s key can be rotated, which cuts off anyone holding an older invite
  • Slow mode. Set how long members wait between messages, from 5 seconds to 5 minutes, when a room needs calming down. Off unless you turn it on, you and your moderators are exempt, and everyone in the room can see it is on
  • Hand a room over instead of sharing your key. Transfer ownership to a member, or nominate a successor who can claim the room if you go quiet for a window you choose
  • Send a file to one member, up to 100 MB and only after they accept. An unanswered offer lapses after five minutes. An offer that arrives while you are on another page now says which room it came from
  • Mute a room or ignore a member, both private to your device and both undoable from Settings > Channels, which now lists who you have ignored by name

Before you upgrade

  • Ember DHT moves to wire version 4, and it is not backward compatible. A 1.6.0 client and a 1.5.9 or earlier client will not see each other on the overlay at all. The version byte makes that a clean refusal rather than a stream of errors, but neither side is told why, so a client left behind just watches the network shrink as everyone else updates. eD2K servers, KAD, search, and downloads are unaffected. Upgrade together if you share with a fixed group — and because Channels ride the same overlay, a room only reaches members who are also on 1.6.0
  • A mismatch now tells you to update. When this install meets a newer overlay it says so and points at the update, instead of reporting the other peers as the problem
  • One device can own 10 rooms at once. Deleting a room gives the slot back. Joining rooms is not limited. New room names are also rate-limited per connection, so creating many in a burst will be refused

What’s Fixed

Security
  • A signed Ember frame is no longer a bearer token. It proved that its sender had once signed those bytes, not that whoever handed them over was that sender — so anyone who had ever received a frame from you could replay it inside their own connection and have the receiver record you as living at their address, then keep replaying to hold the entry there. Every frame is now bound to the encrypted session it arrives on. This is the change that moves the wire version
  • A stranger can no longer make every member of a public room do their work for them. Asking a room for missed history was answered with up to thirty-two messages, and nothing limited how often it could be asked — one small request from anyone who found the room turned into thirty-two replies from each member who heard it. Catch-up requests now have their own budget, well above what normal use needs
  • A single message can no longer be pushed across the whole network. The hop limit that keeps a message in its own neighbourhood was taken on trust from whoever sent it, and is now capped on arrival
  • Moderators stop disappearing from busy rooms. In a room near its 256-member limit, the people holding the moderation tools were first in line to be dropped from the local member list, so their bans stopped being honoured until the room’s settings arrived again
Channels and chat
  • The composer is disabled when chat history is locked, instead of letting you type a message that could never send
  • Create and Join are disabled until you have a Channel username, rather than accepting the click and then refusing the action
  • A failed send no longer costs you a turn. A run of network errors could use up a room’s send allowance and lock you out of a room you had said nothing in
Everywhere else
  • The collapsed sidebar shows the unread-chats dot again instead of hiding it along with the labels
  • A slow first load of a large library no longer spins forever. The result it was waiting for was thrown away at five seconds; it is now kept, and a retry is offered rather than an endless spinner
  • Settings only offers Save when something has changed, matching Discard beside it
  • Destructive confirmations start on Cancel, so Enter no longer completes the dangerous action
  • A failed speed test in the setup wizard reads as a failure rather than being coloured like a success, and the download-folder box opens the picker it looks like it opens
  • Connect on the Ember Network page shows that it is working while a connection is being made, instead of looking idle
  • Transfers offers Clear filter when a filter has hidden every download, matching the known-peers list
  • The peers Ember remembers survive a restart. They shared a store with short-lived entries, so each launch started with a smaller address book than the one it saved
  • Share Ember copies the official site and opens only known social destinations, rather than handing a link to whatever is registered to open it

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.5.9...v1.6.0

Ember v1.5.9

v1.5.9

What’s New

  • The Ember Network is simply on. It was already always-on with a switch you could not turn off, so the switch and the BETA badges are gone. The overview shows how many peers have actually answered you, and source exchange moved into the Ember status-bar tooltip instead of pretending to be a fourth protocol
  • Firewalled peers can reach each other. A download from a peer who cannot accept connections now asks that peer’s relay to bounce a connect-back, and when both ends are unreachable Ember brokers the two together instead of giving up
  • Keyword lookups page properly on busy keys. Two clients searching the same popular word no longer push each other along the same result window, so a common term returns more of what is actually stored

Before you upgrade

  • Ember DHT moves to wire version 3, and it is not backward compatible. A 1.5.9 client and a 1.5.8 or earlier client will not see each other on the overlay at all, and neither side is told why — a client left behind just watches the network shrink as everyone else updates. eD2K servers, KAD, search, and downloads are unaffected. Upgrade together if you share with a fixed group
  • Firewalled sources take longer to appear right after a start. Ember now refuses to contact a relay peer it has not independently reached at that address, which is what closes the forgery below, so on a cold contact list fewer firewalled sources are reachable until it fills in. It retries on its own; nothing is lost, it just arrives later
  • Two Ember diagnostics read lower than before. The withheld and truncated counters on the Ember page used to include records the same reply had just sent. They now count only what was genuinely held back

What’s Fixed

Security
  • A malicious peer can no longer aim Ember at a stranger’s address. The permission slip a firewalled peer publishes to name its relay was signed with a key that peer supplied itself, so it proved nothing: anyone could forge one naming a third party and have every client that found the record open an unsolicited connection there. Ember now also requires the named relay to be a peer it has reached at that exact address
  • A briefly unreadable identity file no longer destroys your upload credits. If antivirus or a backup tool held cryptkey.dat open for a moment, Ember read that as a first run and wrote a brand-new key over the real one — permanently, with no copy kept. Every peer that had recorded credit against your old identity stopped recognising you. Only a genuinely absent file creates a key now
  • A peer cannot get an address you blocked dialled for you. An address that only ever arrived as a firewalled peer’s own claim is never handed to the connector, even after the connect-back attempts run out — including addresses in your ipfilter.dat
Responsiveness
  • Pause and Cancel no longer freeze the app. Pausing or cancelling a screenful of downloads used to stop the whole network stack for seconds at a time while each one finished shutting down, long enough to drop search and overlay traffic. That waiting happens off to the side now. Disconnect on the KAD page had the same problem, for up to thirteen seconds
  • Pause All and Resume All stop competing with hashing. On a long queue they used to start one background write per row and starve file hashing and progress saves until they drained
Transfers
  • A download you paused stays paused across a restart. A status update already in flight could land after yours and win, so the next launch read the old state and started the transfer again by itself
  • Failure and health text is translated. Why a transfer failed, why it is unhealthy, and why a search result was scored as spam were all written in English regardless of your language
  • A transfer whose Ember digest fails verification still shows the red badge in every language, rather than relying on the wording of an English sentence
Sharing and privacy
  • A friends-only file no longer answers strangers during startup. Between launch and the library catalog finishing loading, an unauthenticated probe that knew the file’s hash could confirm you had it. That answer now waits for the catalog, as the other sharing paths already did
  • The Library’s Ember badge means the overlay is live, matching the KAD and eD2K badges beside it. It used to light from the previous session’s publishes while the status bar still said Connecting
Ember overlay
  • A relay that never answers stops pinning your library. A firewalled client whose relay went quiet could pin every shared file and publish nothing for the rest of the session
  • Busy keys cost far less to serve. A single batch of stored records used to scan the whole contact list once per record, and popular keywords rebuilt their result set on every request
  • Peer reputation and anti-leech patterns survive a crash the way identity files already do. An interrupted Windows save left the only copy under a backup name, and the next launch treated that as a clean slate
Search, settings, and updates
  • Search is not disabled because a status check stalled. When Ember’s own diagnostics stopped responding, Search greyed out and blamed the overlay for having no peers. It now says the status is unavailable and lets you search anyway
  • The updater tells you when it could not verify a new release. If it re-offered an installer it had already staged, the reason was never shown — you saw only that something was waiting
  • A download folder that resolves to nothing is refused rather than quietly saved, which used to leave downloads landing next to the program

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.5.8...v1.5.9

Ember v1.5.8

v1.5.8

What’s New

  • The Ember Network actually joins after a fresh install or a restart. A first overlay contact used to be flooded with publish traffic, or dropped after a few missed lookups, before it had answered. Ember now talks to that peer first, then publishes. Friends you are already connected to also introduce you to the overlay, so you are not waiting on KAD alone
  • Friend connections get through Windows Firewall. Hole-punches and relays arrive on Ember’s own UDP port, but Windows was only allowing the KAD port. Those packets were dropped even when UPnP had forwarded them. Direct punch also starts at the same time as the relay, instead of waiting for the relay to fail first

What’s Fixed

Before you upgrade
  • Friend chat needs 1.5.8 on both sides. Mixed versions with 1.5.7 or earlier cannot decrypt each other’s messages, and there is no plaintext fallback. Upgrade together. Search, downloads, and the Ember Network still work with older clients
  • Same Ember DHT as 1.5.7. No protocol bump: 1.5.8 still speaks Ember DHT version 2. Your library and settings move between 1.5.7 and 1.5.8 in either direction
Starting up
  • A missing download folder no longer kills the app. If that folder is on an unplugged USB drive, an offline NAS, or an unmapped share, Ember used to exit immediately with no window. It now opens so you can pick a new folder, and a drive that comes back mid-session is used without a restart
  • The Friends page no longer claims you are discoverable when registration failed. A failed presence update used to look like success
Ember overlay
  • Shared files stay findable. One peer refusing a keyword used to hide the rest of that file’s names for hours. A replica that never stored the record no longer parks the whole file
  • Searches walk peers that have actually answered, not gossip that has never been heard from. A lookup that never left the machine still finishes instead of hanging until the backstop
  • Your overlay contact list survives a crash the way identity files already do. An interrupted Windows save could leave the only copy under a backup name, and the next launch treated that as a first run
  • Contacts remembered from last time are not thrown away while the IP filter is still loading. LAN peers you already have a session with can still gossip
Transfers
  • An interrupted save of a download’s progress file no longer restarts the download at 0%. The same Windows replace path that 1.5.7 fixed for identity files was still open for .part.met, which is how a multi-gigabyte partial could vanish
  • A silent uploader no longer stalls a part forever. If they drop a requested block, Ember lets go of that range and asks someone else
  • A peer that never answers an obfuscated handshake can no longer wedge buddy setup or use up the connect-back pool
Search, library, and security
  • A search no longer drops the last three-letter word. A query that ends in a short word actually uses that word
  • Unmarking one spam result no longer unmarks others that were marked with it
  • Your server list is left alone while the IP filter loads, and permit rows in that list are kept
  • A library larger than 100,000 files pages instead of stopping until you reload
  • The Security page stays usable with a long list instead of fetching everything in one shot

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.5.7...v1.5.8

Ember v1.5.7

v1.5.7

What’s New

  • The shared chrome is quieter. Buttons, toasts, the splash, Settings, and the tables share a softer palette and rounder corners. Dark mode uses layered charcoal instead of hard outlines, so panels separate by depth. Menus and dialogs sit above the chat dock and the status bar instead of disappearing under them
  • Known Clients is two ledgers now. eD2K credits and Ember-bound peers used to share one list, so an Ember friend could show up as if they were an eD2K client with a blank hash. Each network has its own table
  • Settings is on Alt+0, the same way the other pages already have a digit shortcut. Alt plus the numpad digit is ignored, so typing numbers with Num Lock on does not jump you around the app
  • The Ember DHT specification matches this build. The protocol PDF is rebuilt from the same local fonts the rest of the docs use, with no wire change from 1.5.5

What’s Fixed

Before you upgrade
  • Same Ember network as 1.5.5. No protocol bump: 1.5.7 still speaks Ember DHT version 2. The library database is unchanged, so you can move between 1.5.5 and 1.5.7 in either direction
Connections and publishing
  • KAD still publishes you as firewalled when TCP is not actually open. Clearing the Firewalled badge because UPnP mapped the port also used to change the KAD source record to HighID. Peers then tried to dial a port that could not accept connections. The badge can still go green; the publish type follows a LowID or a failed connect-back
  • Bootstrap requests back off once the table is growing. Hardcoded seeds already slowed down. Sampling known contacts with BootstrapReq every ten seconds while the table was under 200 did not. That path uses the same backoff now
  • The IP filter covers KAD while it is still loading, except for the handful of well-known seed IPs that have to answer or a first launch never starts. Random contacts wait until ipfilter.dat is applied; contacts already restored from nodes.dat stay
Transfers
  • A peer that switches files mid-slot no longer keeps the old file’s sent-block map. Progress was only reset when a UI row already existed, so a later request for the new hash could skip ranges that had never been sent for that file
  • aMule-style padding no longer looks like a dead slot. Those clients re-ask for ranges we already sent, padded out to three. Ember counted that as idle and dropped the upload. Asking again for something already delivered now keeps the slot alive, without sending the same blocks twice
  • A finished download’s completed size matches the file size. Completing a row snapped transferred bytes to the full size but left the unique-coverage counter short, so the parts bar could disagree with 100%
  • Paste link works when the async clipboard API is denied. Copy already had a fallback. Paste now tries the same path, and says so if the clipboard is unavailable instead of failing silently
  • Upload rows show session bytes, not file size as if it were transferred. Size and Transferred were paired the way a download is. An upload almost never sends the whole file this session
  • A live friend session stays live. Auto-connect used to treat an open session as stale and tear it down, which looked like the friend went offline while you were still talking
  • Disk-full and a trusted AICH miss stop retrying forever. Those failures are not going to succeed on the next tick
  • Remove from List keeps a failed partial. You can put the download back later instead of starting from zero
Search, library, and keyboard
  • Escape no longer closes chat while it is dismissing page chrome. Column menus, filters, a dirty library comment, the stop-hashing banner, and the friends card menu now keep the dock open. The same contract was already applied to search columns, friends search, security, servers, and transfer filters
  • Clear filters also turns Hide spam off. When spam hiding had emptied the table, that button did nothing because Hide spam is on by default and was not part of the reset
  • Ember-only search waits until there is a peer, or the join attempt has timed out. Starting a tab against zero contacts produced a bare “No results” with no explanation. The joining hint was already on the page; the search itself now respects it
  • A hash that timed out no longer overlaps a second hash of the same file. The scan moves on after five minutes, but the next pass skips that path until the abandoned read finishes
  • Unsaved library comments ask before they disappear. Changing row no longer drops a comment you were still typing
Ember overlay
  • A STORE still sitting behind a Noise handshake is not expired at five seconds. FIND already waited twelve. Publish used the short budget, so a first contact could be marked failed before the record ever left
  • Queued batch stores no longer burn the send window. Handshake-queued frames were counted as delivered. The ACK path still tracks them; the rate window only charges bytes that actually went out
  • EPX handshake replies count as EPX overhead. Incoming Exchange* already did. The automatic replies were billed to Ember DHT
  • The Ember Network toggle says it is on, not “Enable Ember Network”, which was leftover from when it could still be switched off
Persistence
  • An interrupted save no longer mints a new identity file. A crash in the Windows replace path can leave the only copy under a backup name. cryptkey.dat, share-intent, known.met, and clients.met restore that backup before treating a missing file as a first run. Without that, the next save could write empty or freshly generated data over the recovered original

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.5.5...v1.5.7

Ember v1.5.5

v1.5.5

What’s New

  • Paste a whole list of ed2k links at once. Copy as many links as you like, one per line, and use Paste link. Every one is queued and you get a summary of what was added, what was already in the list, and what could not be read. Pasting several links used to look like it worked while quietly keeping only the first
  • The anti-leech filter can actually see VeryCD and easyMule. Those names live in the peer’s mod tag, not in the Software column, which is usually just “eMule 0.50”. The filter now matches both. It is still off unless you turn it on
  • A failed Ember content hash is visible, and it stops the download. The green Ember badge already meant the BLAKE3 check ran and matched. A mismatch used to look like a generic hash failure and then re-download parts that were already correct. It now fails for good, with a red Ember badge

What’s Fixed

Before you upgrade
  • Same Ember network as 1.5.4. No protocol bump: 1.5.5 still speaks Ember DHT version 2. The library database is unchanged, so you can move between 1.5.4 and 1.5.5 in either direction
  • Anti-leech stays off unless you enable it. If you never edited the pattern file, the built-in list drops the old LEECH token (it was matching honest Anti-Leech mods) and adds easyMule. A file you customized is left alone
  • Pausing a download during “Verifying” now stops the check. It used to read the finished file all the way through before noticing. On a large download that could take minutes. The partial file is kept, so the download resumes normally
  • A search tab keeps its best 15,000 results. A broad search on a busy server used to grow until the tab crawled. Beyond that ceiling the least-available hits are dropped as new ones arrive. Use a narrower search, or the collection importer, if you genuinely need more
  • Some credential files are no longer shared. If a shared folder contains things like .env, .pem keys or an .aws folder, they are skipped from now on and disappear from your Library on the next scan
Connections and ports
  • Ember no longer reports Firewalled while UPnP is working. If your router mapped the port but something else on the network also remapped outgoing connections, Ember advertised the wrong port. Every peer and every server then tried to reach a port your router was not forwarding, so nothing could connect in and Ember called itself firewalled — while the router’s own UPnP page showed the port wide open. The port your router actually forwarded is now the one Ember hands out
  • Except when the server says otherwise. If you get a LowID even though UPnP claims a mapping, that mapping demonstrably is not carrying traffic — usually a second router or carrier-grade NAT above your own. Ember now falls back to the port it observed from the outside and retries, instead of insisting on the one that has already failed
Transfers
  • Upload rows no longer show 100% while parts are still missing. Session bytes (including re-requests) were capped at the file size and used as progress, so a half-empty parts bar could still read complete. Unique coverage drives the bar now; transferred bytes can exceed the file size when a peer asked twice
  • A resumed download re-checks the part hashes it saved. Those were trusted purely because they came off your own disk. If they were damaged, every part failed its check, a good copy could never replace them, and the download re-downloaded itself forever with no way out
  • Resume data belonging to a different file is rejected. A .part.met whose file hash or part count does not match is discarded instead of being adopted along with its part hashes. Resume files written by eMule for exactly-sized files are now read correctly rather than thrown away
  • Uploads no longer freeze on a part we will not send. Ember was telling peers it had parts that had finished downloading but not yet passed their hash check, then refusing every request for them. The peer kept asking and the transfer sat still
  • Stopping a download during verification keeps the partial file. Previously the cancel path could mark every part incomplete, throwing away a download that was seconds from finishing
  • Large downloads stay responsive near the end. Working out which parts are complete was re-scanned from scratch for every source on every completed part, which got slowest exactly when a download was nearly done
  • One slow eD2K server can no longer stall the whole app. Callback requests for LowID sources were sent inline and unbounded, so a server that stopped reading could freeze transfers, searches and the interface for up to 30 seconds per source
Search
  • A long-running search stays smooth. Results were re-indexed and re-sorted in full on every incoming batch, so a search got slower the longer it ran. The list is now updated incrementally and the table refreshes on a steady cadence
  • Kad stops silencing its own answers under load. When the flood-protection tables filled up, replies to searches you started were dropped along with the flood, so a keyword search could quietly return nothing. Peers you are already talking to now keep getting through
Ember search and publishing
  • Keyword publishing remembers its schedule across a restart, the way source publishing already did in 1.5.4, so an update or a crash does not republish the whole library at once
  • Connected means a peer has actually answered. Gossip in the routing table used to light the Ember status as if you had joined. Search, the status bar, and the Ember Network page now wait for a verified contact
Ember sessions
  • Two identities at the same address no longer overwrite each other. Transport sessions are keyed on address plus the peer’s static key, so a first contact is not dropped because someone else already spoofed that IP

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.5.4...v1.5.5

Ember v1.5.4

v1.5.4

What’s New

  • The Ember Network stays on during beta. The switch is still on the Ember Network page and in Settings, but it cannot be turned off. A new install finds its first Ember peers through Kad and eD2K, so if people who are already on the overlay could switch it off, there would be nobody left to bootstrap from

What’s Fixed

Before you upgrade
  • Ember cannot be switched off in this build. That is the bootstrap rule above, not a protocol change: 1.5.4 still speaks the same Ember network as 1.5.3. The library database is unchanged, so you can move between 1.5.3 and 1.5.4 in either direction
Friends
  • Add Friend on an upload actually reaches the other Ember user. Choosing it on someone currently downloading from you sent the request against the wrong identity, and the download side dropped it because friend requests were not accepted on a file-transfer connection. The notice now uses their Ember hash and goes out on the live upload
Firewalled nodes
  • Finding a buddy is no longer aborted by an unrelated search. A publish or source lookup finishing was treated as “the buddy search reached nobody”, so a firewalled node kept giving up and waiting longer each time — eventually ten minutes — with nothing said on screen. The outcome is now decided only by the search that actually is the buddy hunt
  • Hole-punch uses the address your QUIC socket actually has. Two names of the same STUN host were treated as two independent views of your public address, and we advertised the wrong UDP port. Punching now follows the mapping the socket itself received, which is what a remapping NAT actually honours
  • We no longer dial a firewalled Ember source as if it were reachable. That connection cannot land, and a forged record could aim downloaders at a host the sender never owned. The row stays visible; the punch and relay path is what actually connects
Ember search and publishing
  • Junk cannot crowd a keyword search off the rails. A peer could fill the result budget with unsigned blobs and end the walk before real records arrived, so a search looked empty. Results are checked before they take a slot, and no single peer may fill more than a quarter of the budget
  • A late publisher is not stuck behind the oldest handful of answers. Replies now rotate, so a file announced later still shows up in search instead of sitting behind the same first records every time
  • Source publishing remembers its schedule across a restart. After an update or a crash it could look as if nothing was due, so your source records went stale until the next full cycle
Transfers and backup
  • Clear completed follows the filter box, the way Pause All and Resume All already did, so it no longer wipes finished rows the current view was not showing
  • A failed restore no longer leaves a new identity sitting on the old database. If anything goes wrong mid-apply, the files that were swapped are put back and staging is kept so the next launch can retry

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.5.3...v1.5.4

Ember v1.5.3

v1.5.3

What’s New

  • Drag folders onto Ember to share them. Dropping folders on the window used to name what you dropped and then open the folder picker anyway, so dropping five folders still meant choosing one of them by hand. They are shared as they land now, however many you drop at once, and the folder picker accepts more than one selection too. Dropping a file offers to share the folder holding it, since sharing here works a folder at a time. We still ask first in the two cases worth asking about: when a drop would include your user folder, which would offer your documents, desktop and pictures to other users, and when it carries far more folders than anyone means to share in one go
  • The downloads list does more without leaving it. Right-clicking an empty part of the list opens the actions that apply to the whole list: pause, resume, stop or cancel everything, copy every download link, paste a link, clear finished rows, select all, and open your Downloads folder. Selecting rows also puts a Copy Link button next to Cancel, which reads Copy All Links once you have selected more than one
  • Ember search results appear as they are found. We used to hold everything a lookup gathered until the whole search finished, and an Ember lookup deliberately keeps asking further peers rather than stopping early, so on a cold start you watched Kad fill the list while Ember showed nothing until the very end. Results now arrive as they are found, the first one straight away and the rest in batches. A file both networks know about updates the row you already have instead of adding a second one
  • The Ember Network page shows when answers are being cut short. A peer replies to a keyword query with as many records as fit in one packet, which is about five, so a busy word can hold far more than anyone can see. There was no way to tell that apart from a quiet network. The page now counts the answers we had to trim and the records that did not fit
  • Four new figures for judging whether your node is healthy. An estimate of how many nodes are out there, how many of your contacts have actually answered you rather than just been mentioned by somebody else, how far behind republishing is, and how long it has been since any Ember packet arrived. Between them they separate still joining from joined and quiet from stuck

What’s Fixed

We compared Ember’s network against our own Kad implementation, constant for constant, and audited every change made since 1.5.2. Most of what follows is the result. The theme is silent failure: several of these switched a feature off completely and reported nothing.

Before you upgrade
  • Nothing to do. We didn’t touch the library database, so you can move between 1.5.0, 1.5.1, 1.5.2 and 1.5.3 in either direction. 1.5.3 also speaks the same Ember network protocol as 1.5.2, so the two find each other normally while everyone upgrades
Publishing and search
  • Your files stop quietly leaving search. Keyword publishing could switch itself off entirely, and did so after every restart on a well-connected node. Sources kept publishing the whole time, so your files stayed downloadable by anyone who already had the link while their keyword records expired and they disappeared from search. Nothing reported it, because from the inside it looked like there was nothing due
  • Searching your own library returns all of it. When Ember read your own node’s index it applied the limit that exists only because a reply has to fit in one packet, so it offered about five of your files. That bit hardest on a small network, where your node holds much of the index and the local read is most of the search
  • A search result can’t leave a download impossible to finish. In 1.5.2 we made a content hash learned from the network need two publishers to agree before we hold a file to it, and covered the path that finds sources. A hash arriving with a search result took a different route and kept the old rule, so one wrong value still meant a download that failed its final check, reopened every part, and started again forever
  • A popular word can’t be taken over and locked. When a keyword filled up we displaced whichever publisher held the most entries, which reads as fairness until you notice that a publisher identity is a free keypair: an arrival holding nothing always outranked an established publisher, so a few hundred keys could strip a word bare and then keep it. A full word now turns new records away, and no single publisher may hold more than 45 of its 300 entries
  • A full word frees up the moment its records expire. Every limit counts records that are still resident and the tidy-up only ran every five minutes, so a word at its limit turned away genuine records for that long after the records blocking it had already died
The Ember Network
  • What you store for other people survives a restart. We dropped all of it on exit. Replication refills it within the hour and publishers re-announce on their own schedules, so nothing was lost for good, but on a young network, and especially when an update restarts many nodes at once, that leaves a window where content is simply missing. The saved file isn’t trusted: every record goes back in through the ordinary checks
  • Publishing addresses peers that are still there. We cached whole contacts for four hours and never rechecked them, so a publish kept talking to peers the routing table had already dropped. We now look up who is closest at the time we publish
  • A contact that never existed can’t end a lookup early. Contacts arrive unverified, so a peer could answer with an invented address one bit away from what we were looking for, pin the front of the queue, and make every later answer look like no progress. A lookup now only counts a peer that has actually replied
  • Half the background traffic is gone. Records held on other publishers’ behalf were re-sent to twenty peers every hour, which was the single largest thing Ember put on the wire, about double everything else it sends. Re-sending cannot extend a record’s life, because expiry is computed from the publisher’s signed timestamp and every copy is identical. What it genuinely buys is reaching nodes that joined recently, and two hours buys that just as well
  • Changing address doesn’t leave people dialling your old one. Source records carry the address to connect to and were only refreshed on a two-hour cycle, so a DHCP lease change or an ISP reconnect left every record we had placed pointing downloaders at whoever holds that address now
  • Source records expire on their own clock. They borrowed the keyword record’s twenty-four hours. A source names a peer to download from, so it stops being true the moment that peer leaves, while a keyword record stays true whoever is online. Six hours survives two missed refreshes and clears a departed peer four times sooner
  • A node with Kad switched off can tell whether its port is open. Only Kad’s probe could establish it, so an Ember-only node marked every source record it published as firewalled for as long as it ran. That is the safe direction, but it relays connections that never needed relaying and hides exactly the open nodes that make the best relays for everyone else
  • A spoofed address can’t get a real peer’s session dropped. When we had to shed a session both rules picked the wrong one: a peer pushed aside while it was busy looks idle, so it always seemed the right one to drop. Refreshing a peer’s liveness also outlived its session by half, so every scheduled check found a dead session and paid for a fresh handshake
  • Your node paces itself by how big the network is. A node among two hundred peers and a node among two hundred thousand ran identical timers. Ember now estimates the size of the network from how tightly packed its neighbours are and scales what it checks and how often against it
Library
  • Copy All Links copies in the order you are looking at. The button took files in the order they were scanned rather than the order on screen, so sorting by name, size or folder changed the list in front of you and made no difference at all to what landed on the clipboard
Transfers
  • Pause All and Resume All follow the filter box. Stop All and Cancel All already applied to the downloads you could actually see, but these two reached every download regardless. With a filter typed in, two commands sitting in the same menu meant different things by All, and the pair that reached rows you could not see was the dangerous half
  • A long upload stops freezing at 100%. An upload counts the bytes actually sent, and a peer that re-requests data pushes that past the size of the file, routinely and by tens of megabytes over a long session. We trimmed the figure to the file size before it reached the speed calculation, so from that moment every sample looked identical and the row froze: no speed, the counter stuck exactly at the file size, and a status of Complete. One session here carried on serving at over a megabyte a second for another half hour behind a row that said it had finished
Updating
  • Ember tells you when an update handed off to an installer that never ran. Installing ends by launching the installer and exiting, so nothing of ours is left to see whether it started. Our installer isn’t Authenticode-signed yet, which makes every release an unknown program to SmartScreen, and a refusal there is indistinguishable from success from inside Ember: the app closes and nothing happens. The verified installer is now kept on disk and the attempt recorded, so the next launch can see the update didn’t land, say so, and offer to run it
  • That offer survives the routine update check. The check a few seconds after startup wiped the notice, then found the staged version again and offered to download the very same bytes and repeat the hand-off that had just failed, so the feature disabled itself in the exact situation it was built for
  • A staged installer is still held to the rollback floor. Rechecking the signature answers whether these are the bytes we verified, which is a different question from whether that version is still one we will install. A staged build now has to beat the running one, and anything below the floor is deleted rather than offered

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.5.2...v1.5.3

Ember v1.5.2

v1.5.2

What’s New

  • The Ember Network has its own light on the status bar. We only showed it once Kad was up, which made the two look like the same thing. They aren’t. You can now see whether the overlay is running and how many peers it is holding
  • Finished downloads say when their Ember hash was checked. If we verified a completed file against the content hash published on the Ember Network and it matched, the row gets a badge. It only appears when the check actually ran, so a file recovered after a crash, or one with no Ember hash to check against, won’t have it
  • File properties show the Ember content hash next to the ed2k and AICH hashes, so you can see the digest your downloads are checked against
  • The Ember Network page shows what you’re holding for other people. Your node stores records on the network’s behalf and there was no way to see how many. We count only records somebody else published, so the number is what you’re actually contributing rather than your own entries coming back to you

What’s Fixed

Our third audit since 1.4.0, this time seven passes reading in parallel over everything we had changed. It turned up 28 findings. 26 held up and are fixed here; two were our own false alarms.

Before you upgrade
  • Nothing to do. We didn’t touch the library database, so you can move between 1.5.0, 1.5.1 and 1.5.2 in either direction
Friends and the Ember Network
  • Your friend code can’t be used to take over your presence. An ember2: code is meant to be public, and it’s enough to work out where your presence is registered. Anyone holding yours could claim that spot with their own key, so friends looking you up reached a stranger or found nothing at all. One request was enough, and it worked every time. A presence slot now belongs to the identity it was derived from and to nobody else. This one is server-side and already deployed, so 1.5.0 and 1.5.1 are covered too
  • Your node can relay for friends again. We tied the relay offer to Kad being connected, and Kad is off in a default install, so a default install advertised nothing and turned away every friend that tried to use it. Relaying is the one discovery path that works for two friends who share no downloads, which is the case we built it for
  • Relayed transfers survive both ends going quiet. Our 1.5.1 fix kept the second peer’s side of a relay alive and missed the first, so a quiet relayed session was still being closed at thirty seconds. Also server-side, also already deployed
  • A spoofed packet can’t stop a peer reaching you. Someone forging a peer’s address could displace that peer’s half-finished handshake over and over, so when the real reply turned up there was nothing left to match it against and first contact never completed. Both halves of the handshake now survive a forged packet
  • One unverified claim can’t fail a download forever. A single node could assert the content hash for a file and we would enforce it at completion. If the claim was wrong the download failed, found nothing to repair, and started again from the top, indefinitely. A hash we learn from the network now needs two publishers to agree before we hold a file to it
Talking to other clients
  • Obfuscated connections don’t corrupt themselves after a stall. If a peer stopped reading for a minute, the next packet could put part of the previous one back on the wire. It decrypts cleanly at the far end, so nothing looks wrong until the framing has drifted and the connection is finished
  • One byte can’t hold an incoming connection slot. A connection that sent a single byte and then went silent was waited on with no timeout at all. Around thirty-four of those filled the listener and shut out every real peer, upload and port test
  • Source swapping runs with Kad off. Moving a peer from a file it can’t help with to one it can was gated on Kad, even though it only ever deals with ordinary ed2k sources. Nobody running server-only ever saw it work
  • A peer can’t make us hold hundreds of megabytes. We bounded the corruption-recovery buffer by bytes in one download path and by packet count in the other. The one we missed is the path a single-source download takes
Search
  • The name you see is the name you get. Two different rules picked the filename for the results list and the filename written to disk, so a result could show one name and download another
  • Peers send a full page of results. Our budget for how many packets one answer may use was smaller than a single page, so the 1.5.1 fix couldn’t take effect and each peer still returned a slice of what it held
Kad
  • One peer can’t block all publishing on your node. Comments, ratings and source records shared one space with keyword records, and only keyword records could be trimmed to make room. Whichever of the other two filled it first locked the whole store and refused everything else in the meantime: five hours for sources, a full day for comments
  • A refused publish can’t delete somebody else’s records. Our 1.5.1 fix covered new records and not updates to existing ones, so a peer could still make us drop another publisher’s entries to clear space for a record its own limits were about to turn down
Your data
  • An interrupted save doesn’t reset your settings. Replacing a file on Windows sometimes needs the old one moved aside first. In 1.5.1 we taught the identity file to recover from that and left every other file as it was. For settings it meant a launch that looked like a fresh install: every preference back to default and every shared folder gone
  • Approved folders stay approved, and stay yours. The record of which folders Ember may use failed the same way, and it failed open. An empty record looked like a first run, so whatever was sitting at each configured path got approved again without anyone asking you
  • An interrupted save doesn’t lock you out of chat history. The chat key could be left under the set-aside name, and we would then report the history sealed and tell you to restore a backup, with the key sitting right next to the database
  • Backups are never shared, whatever you call them. Our rule for keeping a profile backup out of your shared folders matched the extension exactly, so a file saved as .EmberBackup went straight past it and got indexed and offered to peers like anything else
  • Restoring an old backup can’t stop Ember opening. A chat message that happened to start with the text we use to mark encrypted messages made the upgrade of a pre-1.4 database fail, and then fail again on every launch after that
  • The last saves on exit aren’t skipped. One save finishing at the wrong moment consumed the signal another was waiting on, and the wait that followed ate the time the reputation, source list and server list saves needed
  • Two smaller ones: file permissions on Windows are applied through a handle that can’t be redirected between the check and the change, and the peer credit counters saturate instead of wrapping when a stored value is out of range

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.5.1...v1.5.2

Ember v1.5.1

v1.5.1

What’s Fixed

No new features in this one. It’s our second full audit, read in parallel across the network loop, each eD2K path, Kad, the Ember overlay, storage and security, the command layer, the interface and the rendezvous server. Twenty-two findings held up and all of them are fixed here.

Two of them were costing people something every day. If you run Ember server-only, which is what you have if you’ve never pressed Connect on the Kad page, every reply peers sent you was being thrown away, so queue positions never moved while we kept asking for them. And roughly one in every 250 incoming connections from a stock eMule client was dropped before it started, over a byte we assumed eMule would never send and it turns out picks at random.

Before you upgrade
  • Nothing to do this time. Unlike 1.5.0, we didn’t change your library database, so you can move between 1.5.0 and 1.5.1 freely
Talking to other clients
  • Queue positions update again with Kad off. Replies from peers all arrive on the socket Kad uses: your place in their queue, whether a source is still alive, the answer to the UDP port test, reask relaying for firewalled peers. We discarded the lot whenever Kad wasn’t connected, and we kept sending the questions, so the traffic went out and nothing ever came back. Peers waiting in your queue got no acknowledgement either, and had to fall back or give up
  • eMule clients connect reliably. Our private friend handshake opens with a byte we believed eMule’s obfuscation could never begin with. It can: eMule picks that first byte at random and rules out only three values. Every collision sent an ordinary eMule client into the wrong handshake and dropped the connection, usually after making it wait ten seconds first
  • One peer’s “I don’t have that” doesn’t count against your other downloads. A peer declining one file was marked failed on every file you were getting from it, and any queue position you had just learned went out with it. Peers commonly serve several of your downloads at once, so this cost people working sources
  • Server names show up instead of an address. A server that sent its name in the compact form the eMule protocol also allows wasn’t parsed, so the list kept showing a bare IP for it
Uploads
  • A single peer can’t pin your disk and a CPU core. One small request asked us to hash an entire shared file start to finish, and nothing remembered the answer, so repeating the request cost the same work every time. It needed no upload slot, no queue position and no identity. On a large share a handful of packets could make the app unresponsive for minutes and stall your downloads with it
  • More upload slots on a slow connection. We guaranteed two upload slots where eMule guarantees four, and since the number comes from how fast you’re actually uploading, two slow peers kept it at two. You now serve as many peers as eMule would, and two trickling peers can’t hold your whole upload
Downloads
  • Peers that compress aren’t dropped mid-transfer. When another source finished the part you were working on first, a compressed block already in flight arrived with nothing to match it against, and we treated that as the peer misbehaving, closed the connection, then sat out a cooldown of nearly half an hour before trying again. Nothing is wrong at either end when this happens
  • Invented identities can’t push out real sources. When a file’s source list is full we drop the least valuable entry rather than the oldest. Which entries counted as least valuable depended on a name the sending peer chose, so a peer that made one up for each source it offered could push out sources you had already used, and its replacements were what we wrote to disk for next time
  • Repeated junk sources don’t displace working ones. A firewalled source offered with an id of zero can never be contacted, and zero was the one value our duplicate check couldn’t recognise, so the same packet sent again added another dead entry every time
  • A peer can’t make us hold hundreds of megabytes. While waiting for a corruption-recovery answer we set aside a fixed number of packets regardless of how large they were, and a peer could inflate them on purpose
Search
  • Each peer contributes everything it holds. Asking a peer for another page of results was meant to happen once it had sent a full page, but we compared a single network packet against the size of a whole page, and a page always arrives split across many packets. No peer was ever asked for a second page, so popular keywords returned only the first slice of what each one actually had
Friends and the Ember Network
  • Relayed transfers survive a quiet moment. When both sides are firewalled, traffic can go through the rendezvous server. A relayed connection that went quiet for thirty seconds was closed by the layer underneath even though the relay itself allows three minutes, and quiet is normal here: a peer parked in an upload queue says nothing for close to half an hour. This is a server-side fix and is already deployed, so it applies to 1.5.0 too
  • Kad storage can’t be filled by one peer. Comments and ratings published to your node had no per-publisher limit at all, so one peer could fill the space shared with keyword and source records. After that no new source could be stored, and honest keyword records were discarded to make room. Separately, a peer whose own record was about to be refused could still make us delete somebody else’s to clear space for it
Your data
  • An unexpected exit doesn’t discard the session. Our save-on-exit sequence ran against a deadline set forty-five seconds after launch. If the app closed any way other than being asked to, that deadline was long gone and every step was skipped: peer list, library checkpoint, credits, reputation, server list. The log blamed a slow disk. The library checkpoint on its own is what saves you re-hashing your whole share on the next start
  • Your identity survives an interrupted save. Replacing a file on Windows sometimes needs the old one moved aside first, and if the app died in that instant the only copy was left under a name nothing ever looked for again. For the identity file that meant the next launch generated a brand new one, silently resetting your Kad id, your friendships and your credit with every peer
  • A locked settings file doesn’t unapprove your folders. If we couldn’t read the record of which folders Ember may use at startup, and a backup tool or antivirus holding it open is enough for that, we treated it as damaged and replaced it with an empty one. Every shared folder and your download folder then had to be re-approved by hand
  • Backups are never shared to the network. Saving a profile backup into one of your shared folders got it indexed, hashed and offered to other peers like any other file. It holds your keys, so it should never have been publishable, however strong the passphrase
  • Two exports at once can’t destroy a backup. Starting a second export to the same file before the first finished interleaved the two and reported success, leaving a backup no passphrase could ever open where a good one used to be
  • The brief hitch every few minutes while we wrote the Ember peer list to disk is gone, and a slow save no longer eats into the time the other saves have

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.5.0...v1.5.1

Ember v1.5.0

v1.5.0

Our first full read-only audit of the app, plus the work that was prepared for 1.4.1. There is no 1.4.1 release; all of it ships here instead.

The headline is a bug that had been in 1.4.0 from the start: no file larger than 4 GiB could be downloaded at all. Most of the rest you had no way of seeing from outside the app. Uploads capped at a tenth of their limit, friends unable to find you, a source exchange that never answered, and several paths that failed without leaving a trace.

Before you upgrade
  • This release upgrades your library database, and 1.4.0 can’t open it afterwards. The upgrade is automatic and keeps your data, but it only goes one way. If you want the option of going back to 1.4.0, copy your Ember data folder somewhere safe before you install

What’s New

  • Diagnostics on the Ember Network page. Counters for source exchanges, how many offered sources we use versus filter out, replies too large for UDP, and storage rejections. Every one of them covers a path that used to fail without saying anything

What’s Fixed

Downloads
  • Files larger than 4 GiB download again. We rejected the very first block of data every source sent for a large file, because we believed the packet couldn’t describe a position that far in. Every source disconnected immediately and the download never started. Nothing above 4 GiB could be fetched from anyone, eMule or Ember
  • Less re-downloading after corruption. When a peer asked us to help pinpoint which small piece of a part was damaged, we built the answer wrong for most file sizes and it was rejected. That peer then had to fetch the whole 9 MB part again instead of the 180 KB block that was actually bad
  • Damaged archives salvage what they can. A single unreadable entry threw away the entire recovery, including everything already checked and rescued
  • Finished parts are on disk before we trust them. A part could be recorded as verified while its data was still only in memory. A power cut at that moment left us convinced the data was good, and we would then serve it to other peers
  • Progress doesn’t jump backwards. The bar could drop by a whole part near the end while the last piece waited to be checked
Uploads and sharing
  • Uploads aren’t stuck at a tenth of your limit. Upload Speed Sense briefly lowers your upload to measure a quiet connection before it starts managing speed. If it couldn’t find a peer to measure against, which is the normal case with Kad disabled, a failed bootstrap, or a restrictive router, it never finished measuring and stayed there for the whole session. Nothing in the interface said so
  • Your credit with other peers survives a restart. Credit earned by uploading was reset the first time each peer verified itself after we restarted, costing you the queue position you had built up
  • Credit is harder to steal. Our protection against a stranger claiming another peer’s identity to inherit their credit could never actually fire. Separately, anyone who knew a peer’s identifier could strip that peer’s standing by failing a single check on their behalf
  • Large libraries scan without stalling the app. We matched each finished file by scanning every file already indexed, which on a big share held up uploads and the interface for the length of the scan. Watching offline network shares doesn’t block the window any more either
Search
  • Nobody else can rename your download. When several peers answered for the same file we kept the longest name offered. Anyone can pad a name, so a single peer could rename a file in the results, and since that name is what we save the download as, on your disk too. The name most peers agree on now wins
  • Inflated results sink. A peer claiming an impossible number of sources sorted above every honest result
  • Turning Ember on takes effect immediately. Enabling the Ember Network from its own page left Search still convinced it was off, refusing Ember searches until you restarted the app
  • Searches find more. A popular file is held by many peers, and every copy it returned used one of the 300 result slots. Copies are counted once now, so a common file doesn’t crowd out everything else
Friends and the Ember Network
  • Friends can find you again. Registration with the rendezvous server restarted every ten seconds and threw away its own result each time, so it never completed. For most setups that meant you were never discoverable, friend transfers couldn’t start, and we re-registered forever
  • UDP source exchanges get answered. We built the reply for a connection where size isn’t limited, so on any client with a real download list it was too big to send and got dropped. It’s built to fit now, and sends fewer files rather than nothing
  • Your own address isn’t accepted back. Sources travel peer to peer, so one eventually came back pointing at you and left a download trying to connect to itself
  • Relay offers are charged to whoever sent them. A single peer could fill the relay list with entries it made up and push out relays learned elsewhere
  • A missed reply isn’t the end. A peer that failed to answer once was dropped from that search for good, and one lost packet is enough to cause it
  • Known-good peers stay known-good. Peers that had answered were pushed aside by ones we had merely heard about, so the connections actually in use went stale and were dropped
  • Downloads can’t be misdirected. Any peer could publish a false fingerprint for a file. We would finish the download, find it didn’t match, find nothing actually wrong with it, and start over from scratch, forever. Fingerprints now need agreement from several peers, and they never override one we worked out ourselves
Network protection
  • Ember isn’t usable as a reflector. Two of our handshakes replied to whoever a packet claimed to come from, with a response larger than the request. Both prove an address is real now before spending anything substantial on it, which also stops one peer being locked out of another’s connection list
  • Flood defences cost less than the flood. The tables protecting against packet floods searched tens of thousands of entries per packet, and chose the busiest peer to forget, which let an attacker reset the very limit meant to catch it. One tracker grew without limit
  • Shared storage can’t be monopolised. A single peer could fill the space we offer the network and lock out every honest publisher for a day, and could sidestep its own quota by changing port
  • A stalled server can’t wedge reconnection. A server that answered slowly but never finished logging in could hold us on “Connecting” for close to an hour with no fallback
Files, folders and updates
  • Changing a folder’s properties doesn’t break downloads. Compressing your download folder, turning off search indexing on it, or a cloud client marking it, all looked identical to the folder being swapped out. We revoked our own access, every download failed, and there was no way to restore it from inside the app. Saving Settings restores it now, and ordinary property changes are ignored
  • Installing an update doesn’t lose progress. The installer shut us down in a way that skipped saving, so every update discarded the resume data for downloads in progress, the library checkpoint that exists to avoid a full re-scan, and the peer and server lists
  • “Up to date” instead of a security warning. If the published release was older than the version installed, every check failed with a warning rather than telling you there was nothing to install
  • Chat day separators stay correct across daylight saving changes, and remote text can’t use invisible characters to disguise how a name reads

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.4.0...v1.5.0

Ember v1.4.0

v1.4.0

The Ember Network beta. 1.4.0 turns on our own encrypted overlay by default, so peers can find each other, publish what they share, and discover download sources without a central directory. File bytes still move over the familiar eD2K path.

What’s New

Ember Network (beta)
  • On by default. The overlay joins on its own. Profiles that still had it switched off from an older default are migrated on, and we tell you if anything was flipped
  • Finding other Ember users. Nodes meet through a well-known KAD rendezvous key, through Ember peers we notice in ordinary KAD traffic, and through eD2K transfers with Ember-capable clients. There is no central bootstrap pool and no seed list shipped in the build
  • Publish and search. Shared files are published so other Ember users can find them, and keyword search and source lookup run on the Ember DHT alongside KAD and servers
  • Downloads still use eD2K. Ember finds the source; the file transfers client to client over eD2K. Keep KAD or servers available so a fresh install can join
  • Ember Network page. Redesigned to show whether you’re connected, whether people can reach you, and whether your shared files are published, with the technical diagnostics kept collapsed
  • A versioned wire format. Incompatible peers refuse each other cleanly instead of looking like packet loss
Library
  • Ember share badges. The Library’s Shared column shows when a file has a live Ember source record

What’s Fixed

  • No full re-hash on every launch. An idle startup doesn’t re-hash the whole library when nothing has changed
  • An audit pass over everything added since 1.3.5: publish, search, store replay limits, table admission, and the edges around them
  • Disabling Ember stops advertising under the rendezvous key, so other nodes don’t spend bridge pings on a peer that won’t answer
  • The developer-only Ember console is out of the shipping build

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.3.5...v1.4.0

Ember v1.3.5

v1.3.5

What’s Fixed

A reliability release, and the result of a full audit. Most of what it fixes was quiet by nature: settings that didn’t apply, messages that were never shown, and a library that could stop indexing without telling you.

Library and sharing
  • One slow file doesn’t empty your library. A file that took more than five minutes to hash cancelled the whole scan and discarded everything not yet indexed, and it happened again on every launch, so files went missing from your share with no explanation. Large files on a network share, an external drive or OneDrive are left for a later attempt now, while the rest of the scan carries on
  • Adding a folder can’t wedge. A file whose read never returned could hold the scan lock for the rest of the session, blocking every later folder add or reload and delaying shutdown. That wait doesn’t hold the lock any more
  • Copy All Links on large libraries. Copying every link failed outright above 50,000 files. It’s sent in batches now
  • Accurate scan warnings. The “only the first 100,000 files were indexed” notice appeared on ordinary reloads of any large folder. It only shows up when the limit was actually hit
  • Excluded files stay excluded. Part-finished downloads, our own temporary and backup files, and anything inside the Ember data folder could come back into your share through the known-files list
  • Failures are visible. When the library failed to load, we rendered an empty library with an invitation to add a folder. It reports the error now
Friends and chat
  • Privacy toggles take effect. Turning off incoming chat or browsing did nothing at all if the save failed: the switch stayed on and the setting never reached the network. The switch reverts now, and you get told
  • No more missing messages. Sending the same text twice in quick succession delivered both and showed one, and the second stayed invisible until you reopened the conversation
  • Queued messages reach their friend. A message typed while a friend was offline could stay marked queued indefinitely after they came back, if the reconnect reused a connection that was already open
  • Abandoned messages say so. A queued message we’ve given up on shows as failed instead of reading “queued” for the rest of the session
  • Unread badges while minimised. Messages that arrived with the window minimised were marked read and raised no badge, so they were easy to miss entirely
  • Browsing a friend. A friend sharing two copies of one file could blank the browse window
Transfers
  • Archive recovery works again on large files. Recovery of a part-finished archive ran out of time before it began on anything multi-gigabyte. Those are the files people actually want it for
  • Lighter Known Clients tab. Trust badges issued one lookup per credit record every few seconds, which on a mature client list meant thousands at once and could crowd out other work
Search
  • Preferences are saved. Search method, filters, sort order and column choices were never written to disk and reset on every launch
  • Stop actually stops. Results kept arriving in a search that had been stopped, and a stop that failed to reach the network said nothing
  • Held Enter. Holding or repeatedly pressing Enter opened an unbounded number of searches and tabs
  • A failed notes lookup was indistinguishable from a file that genuinely has none
Settings
  • Unsaved changes are protected. Clicking away to another page discarded pending edits without asking
  • Empty number fields. Clearing a box and saving stored that field’s factory default, including the listening ports, and could prompt a restart for a change you never made
  • Choosing a language. Arrow keys committed a language and restarted the app mid-selection, so you couldn’t browse the list from the keyboard
  • Bandwidth fields. After typing in a speed box, Apply Recommended and Discard didn’t update what was shown, so the value saved wasn’t the value on screen
Security
  • Fail closed on durable state. Closes silent data loss from unsaved transfers, mixed backup restores and chat that vanished after a reload, and bounds resource exhaustion in rendezvous admission, relays and oversized friend requests
  • Stricter URL checks. Our rejection of credentials embedded in a URL could be sidestepped by leaving out the slashes after https:, which would let a download link display a trusted host while fetching from somewhere else. IPv6 addresses are handled properly again too
  • Deep links. An ed2k:// link that failed once stopped every later link from being handled for the rest of the session. The confirmation prompt also shows the file name, size and hash on separate lines rather than running them together
  • Archive recovery limits. A deliberately crafted archive could keep recovery scanning past its own time limit and ignore a cancel
  • Relay stability. Live relay sessions were torn down by ordinary congestion instead of waiting for it to clear
Smaller things
  • Two crashes that blanked a page outright: repeated lines in the server log, and duplicate entries in a friend’s file list
  • Error notifications appeared behind the dialog whose failure they were reporting, so the message was invisible at the moment it mattered
  • The “TCP port already in use” warning disappeared a few seconds after appearing, while uploads stayed broken
  • The update notice did nothing once an update had downloaded or failed, leaving the banner on screen until restart
  • A security notice was unreadable in the light theme, and several error messages ended in the word “undefined”
  • Re-selecting a played audio or video file restarted it from the beginning without being asked
  • A folder priority we had rejected stayed on screen as though it had been applied

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.3.4...v1.3.5

Ember v1.3.4

v1.3.4

What’s New

Backup and restore
  • Move Ember to a new PC. Settings > Backup writes your whole profile to one passphrase-encrypted .emberbackup file and restores it on another machine or after a reinstall. Your identity, secure-identification keys and upload credits come across, so your standing on the network survives the move
  • What it covers. Identity and SecIdent keys, credits, settings, the shared-folder list, known files, friends, chat history, the transfer list, server and KAD contacts, the IP filter, and learned spam data. The files you share and part-finished downloads stay out, so the backup stays small
  • Always encrypted. The archive holds your private keys, so a passphrase is required rather than optional, and Windows-bound key material is re-wrapped for whichever account restores it. A lost passphrase can’t be recovered
  • Safe restores. A restore is prepared immediately and applied while Ember next starts, because the files it replaces are in use while Ember runs. We keep the replaced originals in a pre-restore folder, and you can discard a pending restore before it’s applied
Transfers
  • Stop All and Cancel All. Both sit beside Pause All and Resume All in the toolbar’s More menu. With the Filter box narrowed they act only on the downloads you can see, and the confirmation says which filter it matched
  • Bulk actions on finished downloads. Completed and failed rows can be selected like active ones and removed together, instead of one right-click at a time. Your files are kept; only the list entries go
  • Clearer selection. Each bulk button reports how many rows it would affect and greys out when none apply, so a mixed selection can’t silently do nothing
Search
  • Copy eD2K links for one result, for every ticked result, or for the whole list at once, from the right-click menu, the selection bar, or Ctrl+C. No need to start a download just to get its link

What’s Fixed

  • We stopped looking like an eMule that misreports its version. Our MuleInfo packet carried a real version byte where eMule expects a sentinel, which is what anti-leecher mods treat as a spoofed client, and it could cost you upload slots or credit score

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.3.3...v1.3.4

Ember v1.3.3

v1.3.3

What’s New

Friends
  • Friends-only shares. Mark Library files as friends-only so they stay out of public search and only mutual friends can request them. Non-friends are refused at the protocol layer
  • Friend file offers. Push a specific shared file to a mutual friend from the Friends page. Offers arrive as notifications the recipient can accept or decline, with rate limits and expiry
  • Friend transfers without HighID. Mutual-friend downloads can use the Noise-secured friend session when ordinary HighID or callback paths aren’t available. We can also discover optional peer relays through friend gossip for harder NAT cases
  • Friend block list. Block a Friend ID and future requests, chat, browse and offers from that identity are rejected. Blocking also removes any existing mutual friendship with it
  • Durable offline chat queue. Outbound friend messages stay queued across reconnects and app restarts, then retry when the friend session is back. Undeliverable messages surface as failed instead of hanging forever
  • Knowing when you’re reachable. The Friends page warns when you aren’t currently discoverable on the rendezvous network, and a friend card can show when a peer is online but not reachable for a direct connection
  • Optional friend relaying. Help friends connect (Settings) controls whether you advertise willingness to assist LowID↔LowID paths. Turn it off if you’d rather not relay for other people
  • Friend chat polish. Clearer conversation grouping, day separators, and tab scrolling in the chat dock

What’s Fixed

  • Friends-only share flags survive Library rescans and resume paths, and are enforced for downloads already in progress rather than only fresh requests
  • Friend relay discovery works in both directions on secure friend sessions, with safer candidate caps and clearer failure attribution, so we don’t drop a good relay because the far side refused
  • Friend file offers are harder to spam, and friend-connect hints don’t mis-attribute progress to the wrong peer

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.3.2...v1.3.3

Ember v1.3.2

v1.3.2

What’s New

Friends
  • Friend cards redesigned. One compact row per friend, presence shown once, and the secondary actions (Browse, Reconnect, Copy Friend ID, Remove) collected in an overflow menu with the Friend ID and last address
  • Friend browse redesigned. Download controls are clearly visible, and a filter box narrows a large shared library
  • Fewer interruptions. No toast when a friend comes online or goes offline, since the card already shows it. Actionable notices, like a friend being behind a firewall or needing a newer Ember, still appear
Diagnostics
  • Panics are written to ember.log, so a crash during startup records its cause instead of closing silently
Transfers and statistics
  • Known Clients shows a friend’s nickname, last address, country and last-seen, instead of just a name
Interface
  • Fits laptop screens. The sidebar auto-collapses on narrower windows, the status bar and Transfers columns compact, and the Library folder drawer overlays instead of squeezing the file table. 4K layouts are unchanged
  • The default window is 1400×900, so the app fits without scrolling on a 16″ laptop
  • Unread chats show a blue dot rather than an orange count
  • KAD page: we removed the redundant Ember peers and EPX sources tiles. Both are still in the status bar

What’s Fixed

  • Ember starts when a shared or download folder’s filesystem identity has changed, for example a folder that was deleted and recreated, or a re-imaged drive. We revoke the affected folder instead, and you can re-approve it from Settings, so a stale record can’t keep the app from launching
  • Unreadable folder-approval state is quarantined instead of being treated as fatal
  • Friend downloads reconnect after both clients restart. A rediscovered friend’s address is reseeded into your existing download sources
  • Statistics: File Requests protocol overhead is measured now. It used to always read zero

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.3.1...v1.3.2

Ember v1.3.1

v1.3.1

What’s Fixed

Friends
  • One-sided Add Friend when both peers are online. Friend-code intro presence lets you find someone before mutual pairwise capabilities exist
  • Adding or accepting a friend forces a rendezvous presence refresh, so discovery doesn’t wait about two minutes
  • Clearer “not found” messaging when the peer is offline or still needs to add you back
Ember and EPX
  • EPX and Ember mesh peer discovery unlock on the HELLO hash↔pubkey binding. Legacy proof-of-possession is disabled and was blocking the status bar EPX count and the KAD Ember peer count
  • Friend privileges (chat, browse, verified requests) still need a secure friend session or PoP

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.3.0...v1.3.1

Ember v1.3.0

v1.3.0

What’s New

A security and Friends release: end-to-end friend chat, hardened sessions and updater, safer file opens, and a batch of Library, EPX and connectivity fixes since 1.2.3. Please tell us if anything here misbehaves.

  • Friend chat is end-to-end encrypted (static X25519 ECDH plus AEAD), and plaintext chat fallbacks are rejected once a session is set up
  • Chat shows an Encrypted badge, and errors point you at reconnecting when encryption fails
  • Friend sessions use Noise IK secure streams, with chat history encrypted in the local database
  • v2 Friend Codes and privacy-preserving rendezvous capabilities (pairwise presence). The Friends page explains how mutual chat and browse unlock
  • A signed anti-rollback updater with security epochs. An install only advances when the signed epoch allows it
  • Deep links need confirming before they open, and you can review a pending link later
  • Dragging a folder into Library asks you to confirm in a system folder picker before sharing it
  • Queued downloads over the safety budget are quarantined rather than deleted, with a notice in the app
  • A corrupted or unreadable ban–reputation policy prompts an explicit acknowledge and reset before networking continues
  • The default window is 1920×1200 on first launch
  • The updater treats a missing manifest or signature (HTTP 404) as “no update”, so a check doesn’t fail while release assets are still uploading
  • The first-run and Settings IP filter download uses the live ipfilter.zip mirror, the same one Security uses, and remembers the enable preference

What’s Fixed

Library and media
  • Library activity, collections, media playback and bulk actions persist and clear busy state correctly
  • Media serve doesn’t reopen files by path after approval, which was a TOCTOU. Reads stay on the approved handle
Friends, EPX and transfers
  • EmuleInfo no longer clears Ember identity during EPX auth
  • AICH trust is scoped to the local file hash, and AICH upload requests use the pinned open handle
  • Oversized UDP exchanges are refused, ERAT trailer space is reserved, and UDP ingest is rate-limited
  • Attestation expiry is honored, reserved EPX versions are rejected, and mesh discovery requires PoP
  • Friend and Ember upload-queue priority flags reset correctly across sessions, so there’s no sticky queue boost
  • Archive recovery hashing opens the recovery file handle-safe instead of reopening by path
  • Upload and completion paths pin approved handles so a path-swap race can’t slip through
Connectivity and rendezvous
  • NAT TCP mappings are discovered over TCP instead of inferred from UDP STUN readings
  • Friend punch doesn’t fail open on legacy proof v3 during v4 sessions, and rendezvous filters legacy entries on v4 polls
  • Mailbox delivery is page-cached with idempotent replay, so a crash mid-page can’t permanently skip messages
  • Rendezvous and friend flows stay compatible across protocol v3 and v4 without breaking stock eMule traffic
Updater, deep links and setup
  • Install stays offered when a verified pending update is retained after the native updater clears pending state
  • Deferred deep links survive handler remounts without reopening twice
  • Windows shared-folder prepare doesn’t delete an opened directory entry on a path or type mismatch
  • Added the missing translation for invalid terminal deep links (deeplink_terminal_invalid)

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.2.3...v1.3.0

Ember v1.2.3

v1.2.3

What’s New

A connectivity fix for STUN and NATMAP keep-alive: we advertise the remapped public TCP port again, and a LowID session reconnects so the eD2k server learns it. Please tell us if anything here misbehaves.

  • When STUN keep-alive confirms a remapped public TCP port while you’re still LowID, we reconnect to the eD2k server, with a 60-second cooldown, so it can retry HighID connect-back with the corrected port

What’s Fixed

  • STUN keep-alive advertises the twin-probe’s public TCP port again, gated on stability (corroborated immediately, or after two matching readings), instead of always mirroring the configured listen port. HighID and public port status can improve behind full-cone NAT and CGNAT
  • A remapped TCP port discovered after login isn’t left unused on an already-connected LowID session

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.2.2...v1.2.3

Ember v1.2.2

v1.2.2

What’s New

A reliability release: Library sharing and large-collection workflows, download source counting, Settings save hangs, relay and friend connects, and KAD publish validation.

  • Library warns clearly when a shared folder hits the 100,000-file per-folder indexing cap
  • Settings and Security report whether saves, nodes.dat and IP filter updates were applied live, deferred, or need a restart
  • Collection create and load use native OS dialogs, so exports aren’t forced into shared or download folders
  • ed2k:// links and collection opens are persisted until they’re handled, so they survive relaunches and setup-wizard restarts

What’s Fixed

Library
  • Stale pending share and priority intents don’t silently re-share or flip priority after a rehash
  • Share, unshare and priority changes persist more safely, with rollback, and apply hash-wide across identical copies
  • Bulk share, unshare and priority actions work on large selections (batched IPC)
  • Remove missing keeps clearing until the scan has actually finished, so no missing rows are left over after the 10k batch limit
  • Large collections: Download All queues in chunks instead of failing wholesale, with skip, oversize and failure feedback
  • Top Uploads de-dupes by hash, shows total uploaded, and explains unattributed older history when only aggregate totals exist
  • Keyboard shortcuts work again with the collections panel open, and are blocked correctly during stop-hash confirmation
  • In-app media playback uses a scoped ember-media protocol that re-checks shared and download roots per request
  • Duplicate library copies don’t force unnecessary rehashes of non-canonical paths
Downloads and sources
  • Ephemeral callback and push-grant ports are session-only, so they don’t inflate per-download source counts across relaunches
  • Resume and reasks prefer dialable listening ports and skip undialable ephemerals
  • Max download file size is aligned to the ED2K wire limit (593 GiB), and large-file part-count and hashset handling doesn’t truncate into bogus values
  • MultiPacket parsing is more tolerant of peer extended-request variants
Sharing and settings
  • Saving Settings doesn’t hang behind long library hashes and scans when shared folders change; folder reconcile runs in the background
  • Removing a shared folder cancels in-progress scans under that root sooner
  • Clearer save and download messaging when a live network apply has to wait for a restart
Relay, rendezvous and friends
  • Friend relay tickets hardened (v3 candidate polling, quota and reservation cleanup, legacy v2 cursor sweep) for more reliable LowID friend connects
  • Browse friend cancels and correlates by request ID, so stale or swapped results don’t land in the wrong dialog
  • Friend sessions close and evict cleanly, and relay tickets are limited to manually known friends
  • STUN keep-alive doesn’t override your configured TCP listen port in Hello and advertising. The UDP mapping stays UDP-only
KAD and protocol
  • KAD keyword publishes without a filename, size or tags are rejected, so there’s no more empty junk served back to searchers
  • Published source entries with UDP port 0 fall back to the packet’s real source port, which is what eMule does
  • Safer .part.met save-path guard cleanup after a download is removed
Search and UI
  • Backspace doesn’t delete a hovered saved search. Only Delete removes recent entries
  • Deep-link handling doesn’t double-apply or drop links across restarts and HMR
  • The setup wizard reports deferred or failed live apply for nodes.dat and the IP filter more clearly
  • Library table rows support Enter and Space activation, and we filled assorted i18n gaps

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.2.1...v1.2.2

Ember v1.2.1

v1.2.1

What’s New

Connectivity and Library quality of life: STUN and NATMAP port keep-alive for CGNAT and cone NATs, a Simplified Chinese interface, and a few Library and chat fixes.

Network and HighID
  • STUN port keep-alive (Settings, on by default) keeps NAT mappings alive with periodic STUN plus a TCP hold from your listen port, and advertises the discovered public TCP and UDP ports for HighID. Useful behind CGNAT or full-cone NAT without UPnP
  • It auto-suspends on Open or Symmetric NAT, or on unstable port remapping, then falls back to your Settings ports
  • Home status shows when keep-alive is active and which public ports are being advertised
Library
  • Copy all eD2K links for the current Library view in one shot, as a single IPC batch, so it works on large libraries
Localization
  • Simplified Chinese (zh-CN), including the Settings picker and system-language detection (zh and zh-Hans map to zh-CN)

What’s Fixed

  • Library Missing stays greyed out until a scan actually finds missing files
  • Closing an active chat tab doesn’t resurrect its wiped draft when you reopen a chat later
  • The rendezvous-server Docker image builds again; the Rust toolchain pin is aligned with rust-version

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.2.0...v1.2.1

Ember v1.2.0

v1.2.0

Stability and accuracy across transfers, search, KAD, Security and Statistics, Settings and Library.

What’s New

  • Internal protocol knobs and the rendezvous URL are out of the Settings interface
  • Friend session encryption is always on
  • The misleading obfuscation “Restart” badge is gone
  • Incremental auto_vacuum is enabled on the database (schema v21)
  • i18n updates across en, de, es, fr and pt-BR

What’s Fixed

Downloads and uploads
  • A final hash failure can be retried instead of staying permanently failed
  • Stop doesn’t race into a false Failed state
  • Disk space checks use remaining bytes, so a large near-done resume doesn’t false-flag Insufficient
  • Uploads end on unique coverage, and soft rejects preserve queue seniority
  • Pause and cancel teardown, and concurrent-slot promotion, hardened
  • Better soft disk probe and startup hash timeout behavior
Sources and discovery
  • Soft-dropped peers can re-inject, and LowID callbacks flush for active downloads
  • Pause and resume reseed from per-file sources, and pause-offline source rows stay visible
  • Source counts and offer tracking corrected
Search
  • Cancel and KAD keyword results are preserved across capacity eviction
  • Hardened filters, notes, source safety, download gating and spam overrides
  • Fixed Clear Results and bulk UX races, and improved method-specific search hints
KAD and network
  • A fail-closed IP filter doesn’t block KAD bootstrap or routing-table admission while ranges load
  • A quiet KAD timeout doesn’t tear down eD2K
  • Fixed eD2K reconnect and the related filter side effects
  • The server list and routing table aren’t wiped during a filter load
Security and Statistics
  • The IP filter Hits column tracks per-range blocks, not only the header total
  • ranges_ready is shown, enable refresh and poll work, and fail-closed load failures are visible
  • KAD upload overhead and status-ping wire bytes are counted correctly
  • Fake overhead estimates are gone, and uptime, ratio and locale formatting are cleaned up
Library and Settings
  • The Library Peers column updates live, clears when peers drop, and counts complete copies and KAD publish acks only
Friends and UI
  • Friend connect slots and firewall rules clear correctly, and the settings toggles work
  • The source drawer empty state is authoritative, plus minor search and transfers polish

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.8...v1.2.0

Ember v1.1.8

v1.1.8

What’s Fixed

Startup and connectivity
  • Heavy network startup I/O (UPnP, ipfilter, known.met, GeoIP) is deferred so splash IPC stays responsive
  • The IP filter fails closed until ranges finish loading, so peers can’t slip through an empty enabled list
  • Fixed HighID port-test and firewall sticky LowID, preferred-server auto-connect, and auto-ban edge cases
Transfers and bandwidth
  • Upload Speed Sense requires an upload limit, and we fixed RTT throttling and the single-sample USS ratchet
  • Cancelled downloads don’t briefly flash red
Persistence and sharing
  • Fixed silent friend loss, disk-full state wipes, settings resets, orphaned KAD searches, and share and indexer leaks
  • Hardened the related UI races and the friend-connect proof-of-possession test mocks

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.7...v1.1.8

Ember v1.1.7

v1.1.7

What’s New

Search
  • Global, Server and KAD search line up more closely with eMule: UDP eligibility and reply auth, Arc/Iso→Pro wire types, KAD AND stripping, availability merge, and stop-cap accounting
  • We request more server results (OP_QUERY_MORE) automatically when a page is full, up to the eMule-style limits
  • Shared and downloading files are skipped when counting toward the ed2k search stop limit. The results still appear
  • Hide spam moved into Advanced Filters, and the empty-server “retry” banner is gone
Uploads
  • HighID waiting peers are dialled to grant upload slots (AddUpNextClient / push-grant), with concurrency and backoff limits
  • Soft-zone admission judges newcomers by credit and file priority instead of a zero-wait score
Downloads and transfers
  • KAD, TCP and UDP source discovery start for queued and add-paused downloads, so sources are ready when you resume
  • Resume All includes Stopped downloads
  • Pause All, Resume All and Clear Completed are collapsed into a More menu, which closes on Escape and on an outside click
Library and status
  • Redesigned Library detail drawer, with sections, missing and hashing banners, and context Properties
  • Total shared size sits next to the shared-file count in the status bar
  • Better missing-file scan feedback and bulk selection toasts
Statistics
  • Completed Uploads counts only when a peer received the entire file in that session
  • Cumulative counters don’t roll backward across save races, zero durations show as 0s, and empty overhead bars are hidden

What’s Fixed

Connectivity and firewall
  • Reconnect backoff and per-server cooldowns are honored, and LowID stays sticky against a false “Open” from UPnP
  • Mid-session OP_IDCHANGE (LowID to HighID) is handled without a full disconnect where possible
  • A known Open or Firewalled status is preferred over a stale Unknown in the interface
Transfers
  • Batch cancel always removes the database rows, so cancelled downloads don’t resurrect after a restart
  • Spam-filter saves are serialized to avoid lost or out-of-order writes
Installer
  • The desktop shortcut isn’t recreated during in-app updates (/UPDATE), which was making duplicate desktop icons

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.6...v1.1.7

Ember v1.1.6

v1.1.6

What’s New

Library
  • An in-app media player for playable audio and video
  • Playable files open from the detail drawer, with Open Externally still there
Search
  • Polished the search tab stop and close controls
  • KAD store, search and verify paths line up more closely with eMule: wire publisher IDs, verified contact seeding after a cold start, legacy Hello challenges, and dropping oversized KadRes

What’s Fixed

Security and trust
  • Peer-relay (ERAT) requests require Ed25519 proof-of-possession, and legacy hash-only RELAY_REQUEST payloads are rejected
  • EPX trust hardened: PoP required on TCP source exchange, KAD Noise keys pinned, and ERAT TTL handling aligned
  • Bare-nonce Ember auth is gone in favor of domain-separated signed auth only
  • IP filtering hardened: the live filter is kept during an async reload or enable, we fail closed on reload errors, always reject bogus inbound TCP, and honor block_private on source inject paths
Downloads and sources
  • IP filter, ban and reputation checks are unified across dial and inject paths
  • Insufficient-space downloads are kept across a restart
  • Mid-download disk-full is classified as insufficient space instead of a generic failure
  • Friend-related and settings hot-reload fixes from the audit pass: live friend toggles, browse and chat gates, and nickname, max-sources and filter-server updates without restart noise

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.5...v1.1.6

Ember v1.1.5

v1.1.5

What’s New

Languages
  • French, Brazilian Portuguese and German interface translations
  • Country flags on the Settings language picker cards
Dependencies
  • Frontend stack updated (Vite 8, SvelteKit, TypeScript 5.9, Tauri JS packages)
  • Rust crates updated, including rusqlite, reqwest, directories, lofty and zip, with the lockfile refreshes that go with them
  • Rust MSRV raised to 1.94 for the newer crate requirements

What’s Fixed

  • Removed duplicate search_bitrate_value keys from the English, Spanish and French catalogs

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.4...v1.1.5

Ember v1.1.4

v1.1.4

If you’re on 1.1.3, this is the one to install. 1.1.3 migrated the database on first launch and then refused to open it again.

What’s New

  • A link to the Ember website from the About dialog and Settings → About

What’s Fixed

  • Fixed the schema version gate so Ember can open databases after the v20 migration (credits.ember_hash). 1.1.3 migrated on first launch, then refused to start on every later launch

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.3...v1.1.4

Ember v1.1.3

v1.1.3

What’s New

  • A row context menu on Known Clients for copy hash, add friend and ban
  • A Release History section on the docs site, with GitHub-style changelogs
  • Expanded .gitignore for runtime data, installer copies and tooling artifacts

What’s Fixed

KAD and eD2K
  • Cleared store, FindBuddy and routing failure modes that could stall discovery and publishing
  • Restored callback peer caps and source-search capacity handling
GeoIP
  • Refreshed the bundled DB-IP country lite database (July 2026)
  • Updated the MaxMind reader dependency
Known Clients
  • Friend markers match on the Ember hash, not only the eD2K user hash
  • The trust badge reflects manual bans
  • Reputation refreshes on each poll, and the friend list keeps the same cadence
Library
  • Stop hashing stays stopped against filesystem-watcher rescans
  • Windows folder filters are case-insensitive
  • KAD and eD2K badges mean published, not merely connected
  • The missing-file scan reports when results are truncated
Statistics
  • Session and connection time use monotonic elapsed time, so a clock jump can’t affect them
  • Download completions are counted only after the transfer is confirmed complete
  • Status bar and protocol-overhead labels match their real scopes (payload, session)
  • The transfer-stats cache refreshes every second, and session versus all-time upload ratio is clearer

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.2...v1.1.3

Ember v1.1.2

v1.1.2

What’s Fixed

Search and downloads
  • Search results with a file hash but no embedded peer IPs can be downloaded again; the backend discovers the sources
  • Batch cancel doesn’t fail the interface after transfers are already cancelled. An incomplete teardown retains the partials and logs a warning
Sharing and settings
  • Overlapping shared folders from older configs are soft-deduped on upgrade instead of resetting all your settings
  • A temporarily unavailable shared folder doesn’t block saving unrelated settings
  • Share, unshare and priority updates succeed even if network persistence is briefly busy (best-effort reconcile)
Reliability and compatibility
  • A corrupt known.met keeps the records we already parsed instead of wiping the whole catalog
  • A corrupt ember.db still recreates safely, and now shows a recovery toast with the backup path
  • Ember auth works across mixed versions (transitional bare-nonce emit, dual verify retained)
  • The network command send timeout is longer, which reduces false failures under load
  • A slow KAD ack on a note publish softens to “queued” instead of a hard error

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.1...v1.1.2

Ember v1.1.1

v1.1.1

What’s Fixed

Persistence and transfers
  • Stale persistence can’t write outdated transfer and settings state
  • Fixed a divergence between on-disk progress and the in-app transfer tracker
KAD and networking
  • Dropped KAD work doesn’t silently stall discovery and publish paths
  • Hardened relay networking while keeping eMule-compatible behavior
Frontend
  • Closed state races that could leave the interface out of sync with the backend

Full Changelog https://github.com/untaimed18/Ember-P2P/compare/v1.1.0...v1.1.1

Ember v1.1.0 Initial Release

v1.1.0

What’s New

Networking
  • Full eMule KAD v8/v9 participation, with automatic Security-server ED2K peer exchange
  • Credits, SecIdent, protocol obfuscation and AICH
  • EPX (Ember Peer Exchange) for faster source discovery between Ember clients
Transfers and library
  • Multi-source downloads with queue management, health monitoring and live progress
  • Multi-tab search with filters and spam detection
  • A virtual-scrolling library with priorities, comments and collections
Friends and security
  • Ember-exclusive Friend IDs with rendezvous discovery, mutual requests, chat, remote browsing and priority upload slots
  • IP filtering, private-IP blocking, path traversal protection and a strict webview CSP
Desktop app
  • A Windows 10/11 installer, a first-run setup wizard, statistics, GeoIP peer countries and signed in-app updates

Support

Report an Issue

To report a bug or suggest an improvement, please use the GitHub Issues page.

What to include in a good report

  • The exact Ember version (shown in the About dialog).
  • Your operating system and version (Windows build or Linux distribution), and how you installed Ember (installer, MSI, .deb or AppImage).
  • Clear step-by-step instructions that reproduce the problem.
  • What you expected to happen and what actually happened instead.
  • Relevant screenshots or log excerpts if applicable.

Community & Source Code

Visit the Ember GitHub repository to browse source code, review open issues, or contribute. Ember is GPLv3-licensed and contributions are welcome.