A modern, open-source P2P file sharing client built on the eMule KAD network. Ground-up rewrite with Rust & Tauri for speed, safety, and simplicity.
No Spyware
No Ads
No Nonsense
GPLv3 Licensed
Ember is not a fork or reskin of eMule. It is a complete reimplementation of the eMule protocol stack in safe Rust, paired with a lightweight Tauri + Svelte shell. It speaks the same KAD wire protocol as eMule 0.50a and compatible clients (aMule, eMule Xtreme, etc.), participates in the same network, finds the same sources, and respects the same credit system. On first launch Ember can seed a community server.met from emule-security.org; you connect to KAD and ED2K servers when you choose (or enable optional auto-connect in Settings).
Ember also runs a network of its own. The Ember Network is an encrypted overlay with no servers and no central directory: Ember nodes find each other directly, publish the files they share, and look up sources for a download over their own DHT. It is on by default and runs alongside KAD and eD2K, so you keep the whole eMule network as well.
On top of that, EPX (Ember Peer Exchange) speeds up source discovery between Ember peers on the ordinary eMule wire, and an Ember-exclusive Friends system adds end-to-end encrypted chat, Noise-secured sessions, and privacy-preserving Friend Codes — all invisible to non-Ember clients.
Highlights
🧱
Modern Foundation
Built in Rust with Tokio async networking. No buffer overflows, no dangling pointers, no data races. The entire protocol stack runs in safe, memory-managed code.
🌐
Full Protocol Compliance
Wire-compatible with eMule 0.50a and the broader eMule ecosystem. KAD v8/v9, ED2K servers & peer exchange, credits, SecIdent, obfuscation, and AICH all work out of the box.
🔥
Ember Network (Beta)
Ember’s own encrypted overlay. No servers, no central directory, no shipped seed list — nodes find each other, publish shared files, and look up sources over their own DHT, alongside KAD and eD2K.
🔄
EPX Source Exchange
Ember peers share compact source lists with each other for faster downloads. Non-Ember clients silently ignore the extension—zero compatibility impact.
🔍
Advanced Search
Global, Server, KAD, and Ember keyword search with multi-tab results, type/size/source/extension filters, and built-in spam detection.
🛡
Security & Privacy
End-to-end friend chat encryption, signed anti-rollback updates, RC4 protocol obfuscation, IP filtering with automatic updates, private IP blocking, confirmed deep links, and strict CSP headers.
⚡
Lightweight Shell
Tauri v2 produces a small, fast desktop app (~15 MB installed) without bundling a full browser engine. Responsive UI powered by Svelte 5.
📦
Smart Transfers
Multi-source downloading with intelligent source management, real-time progress, health monitoring, queue tracking, and archive recovery.
📚
Library Management
Virtual-scrolling tables that handle thousands of files. Sort, filter, play media in-app, copy eD2K links, add comments and ratings, and create collections.
👥
Ember Friends
Share a Friend Code, connect through the rendezvous server, then chat end-to-end encrypted over Noise-secured sessions. Mutual friends also get remote browsing, friends-only shares, file offers, priority uploads, and transfers that can work without HighID.
Download & Installation
Get Ember 1.5.3
The latest release is available on GitHub for Windows 10 and Windows 11.
No external runtimes needed. No Java, no .NET, no browser engine download. Ember ships everything it needs in a single installer.
Getting Started
Install Download the latest release from the Releases page and run the installer.
Setup Wizard On first launch, the Setup Wizard walks you through essential settings — nickname, download folder, ports, speed limits, KAD auto-connect, and theme.
Connect Press Connect on the KAD Network page and/or connect from the ED2K Servers page. Optionally enable Auto-Connect KAD and Auto-Connect Server in Settings (or the Setup Wizard) so Ember reconnects on launch. A community server.met list can be downloaded from emule-security.org on first run. The Ember Network needs no connect step — it is on by default and joins on its own, but it finds its first peers through KAD and eD2K, so keep at least one of them available on a fresh install.
Share & Download Add folders to your library, search with Global / Server / KAD methods, open ed2k:// links, and start downloading. Ember handles multi-source transfers, queue management, and source discovery automatically.
Add Friends (optional) Open the Friends page, share your Friend Code, and add theirs. Once mutual and online, you get end-to-end encrypted chat, remote file browsing, and priority upload slots. See Friends.
Tip: For best performance (High ID), forward your TCP and UDP ports on your router, enable UPnP, or leave STUN port keep-alive on in Settings > Network. See the High ID vs Low ID section for details.
Features
Networking
Ember Network (Beta) — Ember’s own encrypted, server-less overlay for peer discovery, keyword search, publishing, and source lookup. On by default, joins automatically, and runs alongside KAD and eD2K. See the Ember Network section.
KAD Network — Connect to the decentralized KAD DHT for peer discovery, keyword search, publishing, firewall checks, and buddy relay. Optional Auto-Connect KAD in Settings; otherwise press Connect on the KAD Network page. If KAD will not connect, Settings > Network can fetch fresh nodes.dat bootstrap contacts from emule-security.org.
ED2K Servers & Peer Exchange — Manage servers on the ED2K Servers page, download a community server.met from emule-security.org, and optionally Auto-Connect Server (last server, else eMule Sunrise). Once connected, peer exchange helps find sources.
EPX Source Exchange — Ember peers share source lists with each other for faster downloads. Non-Ember clients are unaffected.
NAT Traversal — UPnP automatic port mapping, firewall detection, KAD buddy relay for LowID peers, and EPX peer-relay (ERAT) for LowID↔LowID paths when attestations allow.
STUN Port Keep-Alive — Periodic STUN plus a TCP hold from your listen port keeps NAT mappings alive and advertises the discovered public TCP/UDP ports for High ID. Designed for CGNAT and full-cone NAT when UPnP is unavailable; auto-suspends on symmetric or unstable remapping.
Protocol Obfuscation — RC4-based TCP and UDP header encryption to help with ISP throttling.
Deep Links — Opens ed2k:// URIs and .emulecollection files from the OS (including while Ember is already running). Incoming links require confirm / review before opening, and pending links can be reviewed later.
Transfers
Multi-Source Downloads — Download from multiple peers simultaneously with part-level hash verification, automatic source rotation, and queue management.
Transfer Monitoring — Real-time progress bars, per-source detail drawers, upload tracking, health indicators, and archive recovery.
Bulk Transfer Actions — Tick rows (or use the header checkbox) to pause, resume, stop or cancel many downloads at once, or use the Pause / Resume / Stop / Cancel All commands in the toolbar's More menu. Completed and failed rows can be selected the same way and removed from the list together; the files themselves are kept.
Upload Speed Sense (USS) — Optionally adjusts upload speed from network latency to reduce congestion (requires an upload speed limit).
AICH — Advanced Intelligent Corruption Handling for part-level hash verification and recovery.
Search & Library
Advanced Search — Global, KAD Only, Server Only, and Ember Only keyword search with multi-tab results plus type, size, source, and extension filters. Global runs every network that is up, so Ember results arrive alongside KAD and server hits, de-duplicated into one list.
Spam Detection — Built-in spam detection with balanced and aggressive profiles. Configurable spam threshold and automatic result hiding.
Library Management — Virtual-scrolling tables that handle thousands of files. Sort, filter, bulk-edit priorities, scan for missing files, copy all eD2K links for the current view, and create collections.
Copy eD2K Links from Search — Copy the link for one result, for every ticked result, or for the whole result list at once, from the context menu, the selection toolbar, or Ctrl+C.
In-App Media Player — Play supported audio and video from the Library detail drawer, with Open Externally still available.
Comments & Ratings — Add metadata to your shared files for other peers to see.
Social
Ember Friends — Ember-exclusive friend system powered by a rendezvous server. Share a v2 Friend Code, exchange mutual requests, then enjoy real-time online status, remote file browsing, friends-only shares, file offers, priority upload slots, durable offline chat, and end-to-end encrypted messaging. See the Friends section for details.
E2E Friend Chat — Mutual-friend messages use static X25519 ECDH + AEAD end-to-end encryption after session setup. The chat UI shows an Encrypted badge; plaintext fallbacks are rejected. Conversation history is encrypted in the local database, and outbound messages queue until the friend is reachable again. Being a static exchange, it provides no forward secrecy and covers message bodies only — see E2E Encryption.
Noise-Secured Friend Sessions — Friend connections use Noise IK secure streams with Ed25519 proof-of-possession before chat, browse, offers, and verified friend privileges unlock. Friend file transfers can also run over the same secure path when ordinary HighID/callback routes are unavailable.
Credits & SecIdent — RSA-based Secure Identification prevents credit theft. Upload priority follows the standard credit ratio formula.
Security
Signed Anti-Rollback Updates — In-app updates are cryptographically signed and gated by security epochs, so installs only advance when the signed epoch allows it.
Safer File Opens — Deep links require confirm / review; Library drag-and-drop shared folders ask for a system folder-picker confirmation; media and upload paths pin approved handles to avoid path-swap races.
Security Page — A dedicated page for IP filter management: download the default list, import a file, fetch from an HTTPS URL, enable or disable filtering, add and remove custom ranges, and review how many times each range has actually blocked something.
IP Filtering — Load ipfilter.dat / ipfilter.zip with automatic update support. Incoming connection filtering is off by default because VPN IP ranges commonly appear in ipfilter.dat hosting blocks, silently blocking legitimate peers. Outbound filtering remains active regardless of this setting.
Anti-Leech Filter — Reject incoming connections from known leech client patterns (customizable regex list in Settings).
Private IP Blocking — Prevents connections to reserved IP ranges.
Content Security Policy — Strict CSP headers in the Tauri webview.
First-Time Setup Wizard — Guided configuration on first launch: nickname, download folder, ports, speed limits, optional KAD auto-connect, and theme.
Clean UI — Modern, responsive interface with real-time transfer monitoring and inline search filtering.
Close to System Tray — Choose what the title-bar close button does — ask each time, minimize to tray, or exit. The tray icon stays available either way, so you can reopen Ember from there.
Keyboard Shortcuts — Press ? for a shortcut cheat sheet, and Alt+1–9 to jump straight to the first nine sidebar pages.
Backup & Restore — Settings > Backup saves your whole profile to a single passphrase-encrypted .emberbackup file: identity and SecIdent keys, upload credits, settings, shared-folder list, known files, friends, chat history, transfer list, server and Kad contacts, IP filter, and learned spam data. The files you share and part-finished downloads are not included, so a backup stays small. Encryption is mandatory because the archive contains your private keys, and a lost passphrase cannot be recovered. Your identity keys are unwrapped from Windows DPAPI into the encrypted archive and re-wrapped for whichever Windows account restores them, so a restore on a new machine keeps your user hash, credits and friendships instead of silently rotating them. Restores are prepared immediately and applied while Ember next starts (the files being replaced are in use while it runs); the replaced originals are kept in a pre-restore-<timestamp> folder beside them, and a pending restore can be discarded from the same screen before it is applied. A restore that has sat waiting for more than a month is dropped rather than applied on top of the profile you have been using since; the backup file is untouched, so you can simply import it again. Two things to expect after restoring onto a different machine: shared and download folders need re-approving in Settings, and if the backup carried the database without chat-history.key, existing chat history stays sealed.
Statistics — Session and cumulative transfer statistics, connection uptime, network health indicators, and a peer reputation snapshot.
Automatic Updates — Ember checks for new versions on launch and installs cryptographically signed, anti-rollback updates in-app with one click. You can also check manually under Settings > About.
Languages — Full UI localization for English, Spanish, French, Brazilian Portuguese, German, Simplified Chinese, Italian, Russian, and Traditional Chinese, with a Settings language picker and system-language detection.
GeoIP — Country identification for connected peers via bundled MaxMind DB.
Ember Network Beta
The Ember Network is Ember’s own peer-to-peer overlay: a second network that Ember nodes run between themselves, in parallel with KAD and eD2K. Nodes find each other directly, publish the files they share, and look up sources for a download over their own DHT. There is no directory server, no tracker, and no shipped seed list, and every frame between nodes travels inside an encrypted session.
It is on by default and joins on its own — there is no Connect button. You can turn it off (and back on) from the Ember Network page or Settings > Network; the change is applied live, with no restart. Because it runs alongside the eMule networks rather than replacing them, turning it on costs you nothing on KAD or eD2K.
What it does not change: Ember finds the source; the file itself still transfers over eD2K client-to-client. An Ember search result downloads through the same multi-source engine, credits, and AICH verification as any other result.
How a node joins
There is no bootstrap server to ask and no address list in the installer. A cold node gets in through whichever of these arrives first:
The KAD rendezvous key Ember nodes advertise themselves under one fixed KAD key, as an ordinary source record carrying their Noise public key. A node with a near-empty routing table simply runs a source lookup there. Nodes re-advertise every 5 hours, and only while reachable and already publishing something, so a node that shares nothing never generates publish traffic just to list itself.
The KAD bridge Ember peers noticed in ordinary KAD traffic get pinged on the Ember DHT; their signed reply folds them into the routing table. Rate-capped per maintenance cycle and quiet once the table is healthy.
eD2K transfers A peer that advertises Ember capability during a normal eD2K transfer is cached with its UDP port and bridged in. This is the way in for a client running with no KAD at all.
Gossip and the saved contact file Once a node has been online before, peers learned from other peers plus a persisted contact file (up to 200 entries) get it back in without help.
The first three paths all assume either a live KAD connection or an eD2K transfer with an Ember-capable peer, and the fourth only helps a node that has been online before. That is deliberate: Ember rides eMule’s bootstrap rather than standing up infrastructure of its own. The practical consequence is worth knowing — a first run with KAD off and no servers has no way in.
The rendezvous server has no role here. The server behind Friends is not involved in joining the Ember Network, and a server-hosted bootstrap pool is explicitly not planned: it would hand whoever runs the server an identity-to-IP roster of every participant. Hardcoded seed lists and DNS SRV seeds are ruled out for the same reason — joining stays the rendezvous key, the bridges, gossip, and your own saved contacts.
A fresh node can legitimately sit at zero peers for a minute or two while its first maintenance cycle runs the bridge. The status page shows Connecting during that window rather than pretending something is wrong.
Search and publishing
The files you share are published to the Ember DHT as keyword records (so people can find them by name) and source records (so people can fetch them). Publishing happens automatically once the node has peers, and republishes on a cycle to stay alive.
Searching — The Search page has an Ember Only method, and Global queries Ember alongside KAD and servers, merging everything into one de-duplicated result list. If KAD and eD2K are both offline, Global quietly falls back to Ember alone.
Source lookup — Downloads ask the Ember DHT for sources in addition to KAD and servers, so a file can gain Ember sources even if you found it elsewhere.
Publish badge — The Library marks a shared file with an Ember badge once it has a source record placed on the network, which is the point at which other Ember users can actually fetch it.
Publishing while firewalled — A node that cannot be reached directly publishes through a buddy relay instead, so sharing still works behind a restrictive router.
BLAKE3 integrity — Ember records carry a BLAKE3 digest, and a download verifies against it whenever one is known (from a search hit, a DHT source record, or your own library). Links opened without a digest still download normally and are hashed for future sharing.
Multi-keyword search is approximate. A query with several words uses a sparse DHT intersection plus a filename match on the results, not a strict worldwide AND of every keyword. Recall can differ from KAD on the same query.
Encryption and identity
Ember DHT traffic shares the KAD UDP port (4672 by default) and is told apart by a two-byte marker, so forwarding that port covers both networks. Everything past the marker is encrypted.
Property
Detail
Session encryption
Noise with ChaCha20-Poly1305 and BLAKE2s. Noise_IK when the peer’s static key is already known, Noise_XX for first contact.
Node identity
A 128-bit node ID derived from BLAKE3 of the node’s Ed25519 public key. DHT frames are Ed25519-signed, and a contact is only trusted once it has answered directly.
Routing
Kademlia with k = 20, α = 5, and at most 20 contacts per response.
Wire versioning
Version 2. The decoder accepts a version range and refuses anything outside it at the version byte, so an incompatible peer is a clean rejection rather than a stream of malformed-packet counters that read like packet loss.
Abuse resistance
Per-IP and per-subnet admission caps that scale with table occupancy, return-routability checks before a node spends anything substantial on a request (so Ember cannot be used as a traffic reflector), retry cookies for unproven addresses, and per-publisher storage quotas so one peer cannot fill the space this node offers the network.
The Ember Network page
The page leads with the questions a user actually has — is it on, am I connected, can people reach me, are my shared files findable — and keeps the protocol detail behind a disclosure.
Status — Off, Connecting, Connected, or No peers found, with the on/off switch beside it.
Peers and Published files — How many nodes you are in touch with, and how many of your shared files are findable.
Health checklist — Whether you are on the network, whether people can reach you directly or through a relay, and whether your shares are published.
Technical details — Collapsed by default: your node ID and public keys, around twenty protocol counters (search hits and misses, store acks and failures, average replication, buddy publishes and forwards, malformed frames, observed address votes, EPX exchange stats, storage rejections), plus live tables of contacts, in-flight searches, and the keys this node is serving to others.
Beta limits
The overlay is on by default and in daily use, but it is labelled Beta for concrete reasons:
Bootstrap depends on eMule — A first run with KAD off and no servers cannot join, as described above.
Version mismatches are silent — Incompatible peers refuse each other cleanly, but neither side is told why and there is no upgrade prompt. They simply never appear in each other’s routing tables.
Multi-keyword recall is approximate — See the note above.
A busy keyword shows only a slice of what is out there — Each peer answers a keyword query with about as many records as fit in one packet, roughly five, and there is no way yet to ask it for the next page, so recall under a common word is bounded by how many peers the search walks. The same ceiling applies to publishing: one person may hold at most 45 entries under any single word across the whole network, so if you share 200 files that share a common word, not all of them are findable under it. 1.5.3 adds counters for how often this is actually biting, which is what decides whether we spend a protocol change on it.
Gossip is unverified until it answers — A peer another node told us about is a lead, not a fact, until it replies directly. Admission caps bound the damage, but there is no reputation scoring on gossip itself.
Content still moves over eD2K — The native Ember transfer path is written but not switched on, so the eMule wire is still doing the actual file transfer.
Some paths are not yet exercised end to end — Notably publishing while firewalled through a buddy relay, and a cold join from an empty contact file with no KAD.
EPX — Ember Peer Exchange
EPX is an Ember-exclusive extension to the eMule protocol that accelerates source discovery between Ember peers. It makes downloads faster whenever multiple Ember clients are present on the network.
EPX and the Ember Network are separate things that are easy to confuse. EPX is an extra opcode on the eMule wire, exchanged with Ember peers you are already transferring with. The Ember Network is a whole overlay of its own, with its own DHT and its own encrypted transport. Both work independently: EPX still helps with the Ember Network switched off.
How it works
When two Ember clients connect (during a download or upload), they exchange compact lists of the files they are currently downloading along with the sources they know about for each file. If the receiving peer is downloading one of those files, it immediately gains new sources it may not have found through KAD or ED2K peer exchange alone.
Key point: EPX only activates between confirmed Ember peers. Detection uses the private OP_EMBER_HELLO / OP_EMBER_HELLOANSWER handshake. TCP EPX also requires the peer's advertised Ed25519 public key to BLAKE3-bind to its Ember hash — an offline check that a replayed key pair can pass, and so a deliberately lower bar than the proof of possession behind chat, browse and other friend privileges. UDP EPX requires an authenticated Noise_IK session. Legacy ET_MOD_VERSION / CT_EMULE_MISCOPTIONS2 Ember bits are not used.
Wire Protocol
EPX uses opcode 0xF0 on the eMule extended protocol (OP_EMULEPROT). The current version is v4. The payload format:
version (1 byte, currently 0x04)
file_count (u16 LE)
for each file:
ed2k_hash (16 bytes)
file_size (u64 LE)
file_flags (u8, bit 0 = has AICH root hash)
aich_root (20 bytes, only present if bit 0 of file_flags is set)
source_count (u16 LE)
for each source:
ipv4 (4 bytes, network order)
tcp_port (u16 LE)
udp_port (u16 LE)
flags (u8, bit 0 = firewalled, bit 1 = obfuscation, bit 2 = relay-capable)
peer_count (u16 LE)
for each peer:
ipv4 (4 bytes, network order)
tcp_port (u16 LE)
[optional ERAT trailer]
v4 is layout-identical to v3 for the main body and adds the relay-capable flag bit plus an optional ERAT relay-attestation trailer. v3 parsers ignore unknown flag bits. v3 additions over v2: per-file AICH root hashes for corruption recovery, UDP port and capability flags per source, and a peer discovery section for Ember mesh building. v2 and v3 payloads are still accepted.
ERAT relay attestations
After the peer list, a v4 packet may append a trailer beginning with magic ERAT: version byte, attestation count (max 16), then fixed-size Ed25519-signed entries binding a relay IP/port to an expiry and capability bits. Only cryptographically valid, non-expired attestations (max TTL 30 minutes) become connection-broker relay candidates. The per-source relay-capable flag alone never admits a relay.
Peer-relay QUIC RELAY_REQUEST messages are version 2 and require proof of possession: the requester includes their Ed25519 public key and Ember hash, a fresh nonce, and a signature over the session id, the relay's ERAT attestation hash, target address, and file hash. Legacy hash-only (bearer) requests are rejected. Relays also reject replayed nonces within a short TTL window.
Safety Limits
These caps prevent abuse from poisoned or malicious payloads. Private/reserved IPs and zero-port entries are silently dropped.
Limit
Value
Max files per packet
200
Max sources per file
100
Max payload size
64 KB
Max packets per TCP connection
3
Max total sources per event
2,000
Backward Compatibility
Non-Ember eMule clients silently ignore the 0xF0 opcode — it causes no errors, disconnects, or side effects. EPX is only sent to confirmed Ember peers, and the extension uses a dedicated capability bit so it can never be accidentally triggered.
Friends — Ember-Exclusive Social
Ember includes a built-in friend system that works exclusively between Ember users. It is powered by a separate cryptographic identity called the Ember Hash (also known as your Friend ID), which is distinct from the standard ed2k user_hash used for protocol operations and credits.
How it works
Each Ember client generates a unique 16-byte Ember Hash on first launch. Share a v2 Friend Code (shown on the Friends page) with someone so they can find you on the network. Friend Codes carry the identity needed for privacy-preserving rendezvous lookup without exposing a long-lived raw hash in casual sharing.
Friend discovery is powered by a lightweight rendezvous server. When you connect, Ember registers presence using hashed capabilities (never your raw Friend ID in the clear). When you search for a friend, Ember queries the server and gets back an IP and port for a direct connection. Adding or accepting a friend forces a presence refresh so discovery does not wait on the normal heartbeat interval.
Once a friend is found, Ember opens a direct TCP connection and establishes a Noise IK secure stream with Ed25519 proof-of-possession. After both sides accept the friend request, chat, file browsing, file offers, friends-only shares, and priority uploads unlock on that secured session. When both friends are behind difficult NAT, Ember can still move friend file traffic over the secure session (and optional peer relay) without waiting for HighID.
Ember-only: The friend system is completely invisible to non-Ember clients. It uses a separate identity hash, a dedicated rendezvous server, and dedicated protocol tags that other eMule clients silently ignore.
Features
v2 Friend Codes — Share a Friend Code from the Friends page instead of only a raw Friend ID. Codes support privacy-preserving pairwise presence so mutual chat and browse can unlock once both sides have added each other.
Mutual Friend Requests — The recipient sees an incoming request on the Friends page and can accept or reject it. Chat, file browsing, offers, and priority upload features only activate once both sides have accepted and a secure friend session is established.
Real-Time Online Status — Ember detects when a friend comes online and shows a live online/offline indicator on their card. The Friends page also surfaces when you are not currently discoverable on the rendezvous network.
End-to-End Encrypted Chat — Send and receive messages with mutual friends through a slide-out sidebar. After session setup, messages are encrypted end-to-end; the UI shows an Encrypted badge. Outbound messages queue locally and retry when the friend reconnects. See E2E Encryption.
Remote File Browsing — Browse a mutual friend’s shared file library while they are online and start downloads directly from the browse results.
Friends-Only Shares — Mark Library files as friends-only so they stay out of public search and only mutual friends can request them.
Friend File Offers — Push a specific shared file to a mutual friend from the Friends page. Offers appear as actionable notifications the recipient can accept or decline.
Friend Transfers Without HighID — Mutual-friend downloads can use the Noise-secured friend session (and optional Ember peer relay) when ordinary HighID or callback paths are unavailable—useful when both sides are behind difficult NAT.
Priority Upload Slots — Mutual friends automatically receive priority in your upload queue, giving them faster access to your shared files.
Friend Block List — Block a Friend ID so future requests, chat, browse, and offers from that identity are rejected. Existing mutual friendships with that identity are removed when you block.
Optional Peer Relaying — Relay for other peers (Settings > Network) lets peers who cannot reach each other directly route through you, which is what makes LowID↔LowID transfers work behind strict NATs when attestations allow. It spends your upload bandwidth on people you are not trading with, so you can turn it off.
Discoverable Banner — The Friends page shows a confirmation banner when your identity is registered and discoverable, and warns when presence registration failed so friends may not find you.
E2E Encryption
Friend chat is designed so the rendezvous server and any on-path observer never see message plaintext after a secure session is up.
Noise IK sessions — Friend connections negotiate a Noise_IK secure stream authenticated with Ed25519 proof-of-possession before chat, browse, offer, and friends-only privileges unlock.
End-to-end chat crypto — Message bodies are sealed with XChaCha20-Poly1305 under a key derived from a static X25519 exchange between the two friends’ identity keys. After session setup, plaintext chat fallbacks are rejected. Outbound messages that cannot be delivered stay queued and are retried on reconnect.
Encrypted local history — Conversation history is encrypted at rest in the local database, under a key kept beside it. If that key cannot be recovered, history stays sealed and says so rather than failing quietly.
Clear UI signals — The chat UI shows an Encrypted badge when the secure channel is active, and reconnect-oriented errors when encryption or the friend session fails.
What the encryption does not cover. The key comes from a static Diffie-Hellman between long-lived identity keys, not a ratchet, so there is no forward secrecy: someone who captures your traffic today and later obtains an identity private key could read those messages. Encryption also protects message bodies only — IP addresses, relationship capabilities, message size and timing stay observable to peers and to on-path services. The in-app chat says the same thing rather than implying more.
Note: EPX source exchange and Ember mesh peer discovery can unlock earlier from HELLO hash↔pubkey binding between Ember peers. Friend privileges (chat, browse, offers, friends-only shares, verified requests) still require a secure friend session / proof-of-possession.
Privacy
The rendezvous server stores presence as hashed capabilities derived from your Friend identity (never the raw Friend ID in the clear), paired with IP and port. Registration is pubkey-bound and signature-checked so entries cannot be spoofed with a stolen hash alone. Entries expire automatically after 5 minutes without a heartbeat. Between Ember peers, the Ember Hash is exchanged via the private OP_EMBER_HELLO / OP_EMBER_HELLOANSWER handshake (with Ed25519 proof-of-possession on TCP) — not via the legacy EmuleInfo path used for ordinary eMule metadata.
Network Compatibility
Ember is a first-class citizen of the eMule network. It implements the full protocol suite required to participate alongside every other eMule-family client.
Protocol
Details
KAD (Kademlia DHT)
KAD v8/v9 for decentralized peer and file discovery, firewall checks, buddy relay for firewalled peers, keyword publishing, and note publishing.
ED2K Servers & Peer Exchange
Connect from the ED2K Servers page or optional Auto-Connect Server (last server, else eMule Sunrise). Community server.met lists can be downloaded from emule-security.org. Once connected, servers provide High/Low ID and peer/source exchange.
Credits & SecIdent
eMule credit system with RSA-based Secure Identification to prevent credit theft. Upload priority determined by the standard credit ratio formula.
Obfuscation
RC4-based TCP and UDP header encryption matching eMule’s implementation, helping with ISP throttling.
AICH
Advanced Intelligent Corruption Handling for part-level hash verification and recovery.
Beyond eMule: Ember additionally runs its own Ember Network overlay and the EPX source-exchange extension between Ember peers. Neither is visible to other eMule-family clients, and neither affects the compatibility above.
Port Forwarding
Ember uses two ports for peer communication. Both are configurable in Settings > Network.
Port
Protocol
Purpose
4662
TCP
Peer-to-peer file transfers
4672
UDP
KAD DHT and Ember Network communication (both share this socket)
For best performance (High ID), forward both ports on your router, enable UPnP for automatic mapping, or use STUN port keep-alive when you are behind CGNAT or full-cone NAT without UPnP.
UPnP: When enabled, Ember uses the IGD protocol to automatically request port mappings from your router. This works with most consumer routers and is the easiest path to High ID.
STUN port keep-alive: On by default in Settings > Network. Ember periodically refreshes your NAT mappings with STUN (and a TCP hold from the listen port) and advertises the public ports peers should connect to. It auto-suspends on Open / Symmetric NAT or unstable remapping and falls back to your Settings ports.
High ID vs Low ID
An ID is a value calculated from the client's IP address and assigned by the ED2K server when Ember connects for peer exchange. It indicates whether proper bidirectional communication is possible.
High ID
A High ID means your connection port is open and freely accessible from the internet. Your client is fully reachable by others. This is the optimal state.
Low ID
A Low ID means your connection port is blocked or cannot be reached, typically caused by firewalls, routers, or NAT. Any ID value less than 16,777,216 is considered a Low ID.
Disadvantages of a Low ID
Peer Routing — Since your IP is not directly reachable, all requests must be routed through the server, increasing overhead.
Reduced Sources — Two Low ID clients cannot connect to each other, leading to fewer available sources.
Lost Messages — On busy servers, messages can get lost, causing missed queue progression and slower downloads.
Note: The ID only affects control message exchange. Actual data transfer is still handled client-to-client. If your ID is High, there are no extra advantages to a higher numeric value.
Troubleshooting Low ID
If you're stuck with a Low ID despite correct settings:
Verify that ports 4662 (TCP) and 4672 (UDP) are forwarded on your router.
Check that your OS firewall allows Ember through on both protocols.
Restart Ember to reconnect to the ED2K server.
Enable UPnP in Settings > Network for automatic port mapping.
Leave STUN port keep-alive enabled (Settings > Network) if you are behind CGNAT or full-cone NAT without UPnP — Ember will try to hold and advertise remapped public ports.
If behind symmetric NAT or a VPN that remaps ports unstably, STUN keep-alive suspends automatically; High ID may still require a VPN with a fixed forwarded port or another tunneling solution.
Tech Stack
Layer
Technology
Frontend
Svelte 5 + TypeScript + Vite
App Shell
Tauri v2
Backend
Rust (2021 edition)
Database
SQLite via rusqlite
Networking
Tokio async runtime
Ember Overlay Transport
Noise IK / XX over UDP (ChaCha20-Poly1305 + BLAKE2s)
Ember is licensed under the GPLv3 and welcomes contributions. Visit the GitHub repository to open issues, submit pull requests, or review the codebase.
FAQ
Yes. Ember speaks the same KAD wire protocol as eMule 0.50a and compatible clients (aMule, eMule Xtreme, etc.). It participates in the same network, finds the same sources, and respects the same credit system. Connect to KAD and/or an ED2K server from the app (or enable optional auto-connect in Settings). Ember’s own additions — the Ember Network overlay and the EPX extension — only involve other Ember clients and are silently ignored by everything else.
Use Settings > Backup. Choose a passphrase, create the backup, copy the single .emberbackup file across, then restore it on the new machine from the same screen and restart when prompted. Your user hash, SecIdent keys, upload credits, friends, known files and settings all come across, which is what keeps your standing on the network. The files you share are not in the backup, so copy those separately and re-add the folders in Settings > Library — folders always need re-approving on a new machine. Keep the backup somewhere safe: it contains your private keys, and a lost passphrase cannot be recovered.
It is Ember’s own encrypted peer-to-peer overlay, with its own DHT and no directory server. Ember nodes find each other directly, publish the files they share, and look up download sources over it. You do not set anything up: it is on by default and joins on its own, with no Connect button. It runs alongside KAD and eD2K, so you keep access to the whole eMule network as well. See the Ember Network section.
Because there is no bootstrap server to ask. Ember deliberately ships no seed list and hosts no bootstrap pool — one would hand its operator a list of every participant’s identity and IP. Instead a new node finds its first Ember peers through KAD (via a fixed rendezvous key and Ember peers spotted in ordinary KAD traffic) or through an eD2K transfer with an Ember-capable client. Once it has been online, it remembers up to 200 contacts and can rejoin on its own. So on a fresh install, keep KAD and/or a server available; after that the overlay stands on its own feet.
Probably not. There is no central pool to fetch peers from, so a fresh node fills its routing table on a maintenance cycle and the first connection can take a minute or two. If it stays empty, check that KAD is connected or that you have an ED2K server available — those are how Ember finds its first peers. Ember keeps looking for as long as it is switched on.
EPX (Ember Peer Exchange) is an Ember-exclusive extension that lets Ember peers share source lists with each other, speeding up source discovery. It activates automatically when two Ember clients connect — no configuration needed. It has zero impact on non-Ember clients. It is not the same thing as the Ember Network: EPX is an extra opcode on the eMule wire, while the Ember Network is a separate overlay with its own DHT. Both work independently of each other.
No. ED2K High/Low ID is assigned when Ember connects to an ED2K server and reflects TCP reachability. KAD Open/Firewalled is KAD's independent assessment of UDP reachability. You can have a High ID on ED2K while being Firewalled on KAD if only your TCP port is open but UDP is blocked.
Forward ports 4662 (TCP) and 4672 (UDP) on your router, enable UPnP, or leave STUN port keep-alive on in Settings > Network. Make sure your OS firewall also allows Ember through. On CGNAT or full-cone NAT without UPnP, STUN keep-alive can hold remapped public ports and advertise them for High ID. Symmetric or unstable VPN remapping still often needs a VPN with a fixed forwarded port.
Friends are an Ember-exclusive feature. Share a v2 Friend Code from the Friends page with another Ember user. Ember finds them through its rendezvous server and sends a friend request. Once both sides accept and a secure Noise session is established, mutual friends unlock online status, end-to-end encrypted chat, remote file browsing, friends-only shares, file offers, priority uploads, and transfers that can work without HighID. You can also block a Friend ID to reject future contact. Non-Ember clients do not have a Friend ID / Friend Code and cannot participate.
Yes. Mutual-friend sessions use Noise IK secure streams with Ed25519 proof-of-possession. Chat messages then use static X25519 ECDH + AEAD end-to-end encryption; plaintext chat fallbacks are rejected after session setup. The chat UI shows an Encrypted badge when the secure channel is active. Outbound messages queue until the friend is reachable again, and conversation history is encrypted in the local database. The rendezvous server only helps with discovery — it never sees message plaintext.
Credits reward users who upload. The transferred amount of data determines the credit you are given with a particular client. They are not global — they only apply on the client who granted them. Credits are a major modifier when calculating how fast you advance through other users' upload queues. Ember uses RSA-based Secure Identification (SecIdent) to prevent credit theft.
Currently, official releases are Windows-only (Windows 10/11). However, the underlying stack (Tauri + Rust) is cross-platform, and community builds for other platforms may become available in the future.
Ember checks for a newer version automatically on launch and shows a non-blocking notification when one is available. You can install it in-app with one click — no need to download installers manually — and Ember restarts into the new version. You can also check anytime under Settings > About. Every release is cryptographically signed, and Ember verifies the signature before installing. Updates are also gated by signed security epochs (anti-rollback), so installs only advance when the signed epoch allows it.
Yes. Ember is released under the GNU General Public License v3 (GPLv3). The full source code is available on GitHub. This means anyone can use, modify, and distribute it, but derivative works must also be released under the same license.
No. Ember is a complete ground-up rewrite of the eMule protocol stack in Rust, not a fork or modification of the original C++ codebase. It implements the same protocols from scratch to ensure compatibility while using modern, memory-safe code.
Release History
Every Ember release for Windows, newest first. These are the same notes we publish on GitHub Releases. Ember can also update itself in-app once a signed release is published.
Drag folders onto Ember to share them. Dropping folders on the window used to name what you dropped and then open the folder picker anyway, so dropping five folders still meant choosing one of them by hand. They are shared as they land now, however many you drop at once, and the folder picker accepts more than one selection too. Dropping a file offers to share the folder holding it, since sharing here works a folder at a time. We still ask first in the two cases worth asking about: when a drop would include your user folder, which would offer your documents, desktop and pictures to other users, and when it carries far more folders than anyone means to share in one go
The downloads list does more without leaving it. Right-clicking an empty part of the list opens the actions that apply to the whole list: pause, resume, stop or cancel everything, copy every download link, paste a link, clear finished rows, select all, and open your Downloads folder. Selecting rows also puts a Copy Link button next to Cancel, which reads Copy All Links once you have selected more than one
Ember search results appear as they are found. We used to hold everything a lookup gathered until the whole search finished, and an Ember lookup deliberately keeps asking further peers rather than stopping early, so on a cold start you watched Kad fill the list while Ember showed nothing until the very end. Results now arrive as they are found, the first one straight away and the rest in batches. A file both networks know about updates the row you already have instead of adding a second one
The Ember Network page shows when answers are being cut short. A peer replies to a keyword query with as many records as fit in one packet, which is about five, so a busy word can hold far more than anyone can see. There was no way to tell that apart from a quiet network. The page now counts the answers we had to trim and the records that did not fit
Four new figures for judging whether your node is healthy. An estimate of how many nodes are out there, how many of your contacts have actually answered you rather than just been mentioned by somebody else, how far behind republishing is, and how long it has been since any Ember packet arrived. Between them they separate still joining from joined and quiet from stuck
What’s Fixed
We compared Ember’s network against our own Kad implementation, constant for constant, and audited every change made since 1.5.2. Most of what follows is the result. The theme is silent failure: several of these switched a feature off completely and reported nothing.
Before you upgrade
Nothing to do. We didn’t touch the library database, so you can move between 1.5.0, 1.5.1, 1.5.2 and 1.5.3 in either direction. 1.5.3 also speaks the same Ember network protocol as 1.5.2, so the two find each other normally while everyone upgrades
Publishing and search
Your files stop quietly leaving search. Keyword publishing could switch itself off entirely, and did so after every restart on a well-connected node. Sources kept publishing the whole time, so your files stayed downloadable by anyone who already had the link while their keyword records expired and they disappeared from search. Nothing reported it, because from the inside it looked like there was nothing due
Searching your own library returns all of it. When Ember read your own node’s index it applied the limit that exists only because a reply has to fit in one packet, so it offered about five of your files. That bit hardest on a small network, where your node holds much of the index and the local read is most of the search
A search result can’t leave a download impossible to finish. In 1.5.2 we made a content hash learned from the network need two publishers to agree before we hold a file to it, and covered the path that finds sources. A hash arriving with a search result took a different route and kept the old rule, so one wrong value still meant a download that failed its final check, reopened every part, and started again forever
A popular word can’t be taken over and locked. When a keyword filled up we displaced whichever publisher held the most entries, which reads as fairness until you notice that a publisher identity is a free keypair: an arrival holding nothing always outranked an established publisher, so a few hundred keys could strip a word bare and then keep it. A full word now turns new records away, and no single publisher may hold more than 45 of its 300 entries
A full word frees up the moment its records expire. Every limit counts records that are still resident and the tidy-up only ran every five minutes, so a word at its limit turned away genuine records for that long after the records blocking it had already died
The Ember Network
What you store for other people survives a restart. We dropped all of it on exit. Replication refills it within the hour and publishers re-announce on their own schedules, so nothing was lost for good, but on a young network, and especially when an update restarts many nodes at once, that leaves a window where content is simply missing. The saved file isn’t trusted: every record goes back in through the ordinary checks
Publishing addresses peers that are still there. We cached whole contacts for four hours and never rechecked them, so a publish kept talking to peers the routing table had already dropped. We now look up who is closest at the time we publish
A contact that never existed can’t end a lookup early. Contacts arrive unverified, so a peer could answer with an invented address one bit away from what we were looking for, pin the front of the queue, and make every later answer look like no progress. A lookup now only counts a peer that has actually replied
Half the background traffic is gone. Records held on other publishers’ behalf were re-sent to twenty peers every hour, which was the single largest thing Ember put on the wire, about double everything else it sends. Re-sending cannot extend a record’s life, because expiry is computed from the publisher’s signed timestamp and every copy is identical. What it genuinely buys is reaching nodes that joined recently, and two hours buys that just as well
Changing address doesn’t leave people dialling your old one. Source records carry the address to connect to and were only refreshed on a two-hour cycle, so a DHCP lease change or an ISP reconnect left every record we had placed pointing downloaders at whoever holds that address now
Source records expire on their own clock. They borrowed the keyword record’s twenty-four hours. A source names a peer to download from, so it stops being true the moment that peer leaves, while a keyword record stays true whoever is online. Six hours survives two missed refreshes and clears a departed peer four times sooner
A node with Kad switched off can tell whether its port is open. Only Kad’s probe could establish it, so an Ember-only node marked every source record it published as firewalled for as long as it ran. That is the safe direction, but it relays connections that never needed relaying and hides exactly the open nodes that make the best relays for everyone else
A spoofed address can’t get a real peer’s session dropped. When we had to shed a session both rules picked the wrong one: a peer pushed aside while it was busy looks idle, so it always seemed the right one to drop. Refreshing a peer’s liveness also outlived its session by half, so every scheduled check found a dead session and paid for a fresh handshake
Your node paces itself by how big the network is. A node among two hundred peers and a node among two hundred thousand ran identical timers. Ember now estimates the size of the network from how tightly packed its neighbours are and scales what it checks and how often against it
Library
Copy All Links copies in the order you are looking at. The button took files in the order they were scanned rather than the order on screen, so sorting by name, size or folder changed the list in front of you and made no difference at all to what landed on the clipboard
Transfers
Pause All and Resume All follow the filter box. Stop All and Cancel All already applied to the downloads you could actually see, but these two reached every download regardless. With a filter typed in, two commands sitting in the same menu meant different things by All, and the pair that reached rows you could not see was the dangerous half
A long upload stops freezing at 100%. An upload counts the bytes actually sent, and a peer that re-requests data pushes that past the size of the file, routinely and by tens of megabytes over a long session. We trimmed the figure to the file size before it reached the speed calculation, so from that moment every sample looked identical and the row froze: no speed, the counter stuck exactly at the file size, and a status of Complete. One session here carried on serving at over a megabyte a second for another half hour behind a row that said it had finished
Updating
Ember tells you when an update handed off to an installer that never ran. Installing ends by launching the installer and exiting, so nothing of ours is left to see whether it started. Our installer isn’t Authenticode-signed yet, which makes every release an unknown program to SmartScreen, and a refusal there is indistinguishable from success from inside Ember: the app closes and nothing happens. The verified installer is now kept on disk and the attempt recorded, so the next launch can see the update didn’t land, say so, and offer to run it
That offer survives the routine update check. The check a few seconds after startup wiped the notice, then found the staged version again and offered to download the very same bytes and repeat the hand-off that had just failed, so the feature disabled itself in the exact situation it was built for
A staged installer is still held to the rollback floor. Rechecking the signature answers whether these are the bytes we verified, which is a different question from whether that version is still one we will install. A staged build now has to beat the running one, and anything below the floor is deleted rather than offered
The Ember Network has its own light on the status bar. We only showed it once Kad was up, which made the two look like the same thing. They aren’t. You can now see whether the overlay is running and how many peers it is holding
Finished downloads say when their Ember hash was checked. If we verified a completed file against the content hash published on the Ember Network and it matched, the row gets a badge. It only appears when the check actually ran, so a file recovered after a crash, or one with no Ember hash to check against, won’t have it
File properties show the Ember content hash next to the ed2k and AICH hashes, so you can see the digest your downloads are checked against
The Ember Network page shows what you’re holding for other people. Your node stores records on the network’s behalf and there was no way to see how many. We count only records somebody else published, so the number is what you’re actually contributing rather than your own entries coming back to you
What’s Fixed
Our third audit since 1.4.2, this time seven passes reading in parallel over everything we had changed. It turned up 28 findings. 26 held up and are fixed here; two were our own false alarms.
Before you upgrade
Nothing to do. We didn’t touch the library database, so you can move between 1.5.0, 1.5.1 and 1.5.2 in either direction
Friends and the Ember Network
Your friend code can’t be used to take over your presence. An ember2: code is meant to be public, and it’s enough to work out where your presence is registered. Anyone holding yours could claim that spot with their own key, so friends looking you up reached a stranger or found nothing at all. One request was enough, and it worked every time. A presence slot now belongs to the identity it was derived from and to nobody else. This one is server-side and already deployed, so 1.5.0 and 1.5.1 are covered too
Your node can relay for friends again. We tied the relay offer to Kad being connected, and Kad is off in a default install, so a default install advertised nothing and turned away every friend that tried to use it. Relaying is the one discovery path that works for two friends who share no downloads, which is the case we built it for
Relayed transfers survive both ends going quiet. Our 1.5.1 fix kept the second peer’s side of a relay alive and missed the first, so a quiet relayed session was still being closed at thirty seconds. Also server-side, also already deployed
A spoofed packet can’t stop a peer reaching you. Someone forging a peer’s address could displace that peer’s half-finished handshake over and over, so when the real reply turned up there was nothing left to match it against and first contact never completed. Both halves of the handshake now survive a forged packet
One unverified claim can’t fail a download forever. A single node could assert the content hash for a file and we would enforce it at completion. If the claim was wrong the download failed, found nothing to repair, and started again from the top, indefinitely. A hash we learn from the network now needs two publishers to agree before we hold a file to it
Talking to other clients
Obfuscated connections don’t corrupt themselves after a stall. If a peer stopped reading for a minute, the next packet could put part of the previous one back on the wire. It decrypts cleanly at the far end, so nothing looks wrong until the framing has drifted and the connection is finished
One byte can’t hold an incoming connection slot. A connection that sent a single byte and then went silent was waited on with no timeout at all. Around thirty-four of those filled the listener and shut out every real peer, upload and port test
Source swapping runs with Kad off. Moving a peer from a file it can’t help with to one it can was gated on Kad, even though it only ever deals with ordinary ed2k sources. Nobody running server-only ever saw it work
A peer can’t make us hold hundreds of megabytes. We bounded the corruption-recovery buffer by bytes in one download path and by packet count in the other. The one we missed is the path a single-source download takes
Search
The name you see is the name you get. Two different rules picked the filename for the results list and the filename written to disk, so a result could show one name and download another
Peers send a full page of results. Our budget for how many packets one answer may use was smaller than a single page, so the 1.5.1 fix couldn’t take effect and each peer still returned a slice of what it held
Kad
One peer can’t block all publishing on your node. Comments, ratings and source records shared one space with keyword records, and only keyword records could be trimmed to make room. Whichever of the other two filled it first locked the whole store and refused everything else in the meantime: five hours for sources, a full day for comments
A refused publish can’t delete somebody else’s records. Our 1.5.1 fix covered new records and not updates to existing ones, so a peer could still make us drop another publisher’s entries to clear space for a record its own limits were about to turn down
Your data
An interrupted save doesn’t reset your settings. Replacing a file on Windows sometimes needs the old one moved aside first. In 1.5.1 we taught the identity file to recover from that and left every other file as it was. For settings it meant a launch that looked like a fresh install: every preference back to default and every shared folder gone
Approved folders stay approved, and stay yours. The record of which folders Ember may use failed the same way, and it failed open. An empty record looked like a first run, so whatever was sitting at each configured path got approved again without anyone asking you
An interrupted save doesn’t lock you out of chat history. The chat key could be left under the set-aside name, and we would then report the history sealed and tell you to restore a backup, with the key sitting right next to the database
Backups are never shared, whatever you call them. Our rule for keeping a profile backup out of your shared folders matched the extension exactly, so a file saved as .EmberBackup went straight past it and got indexed and offered to peers like anything else
Restoring an old backup can’t stop Ember opening. A chat message that happened to start with the text we use to mark encrypted messages made the upgrade of a pre-1.4 database fail, and then fail again on every launch after that
The last saves on exit aren’t skipped. One save finishing at the wrong moment consumed the signal another was waiting on, and the wait that followed ate the time the reputation, source list and server list saves needed
Two smaller ones: file permissions on Windows are applied through a handle that can’t be redirected between the check and the change, and the peer credit counters saturate instead of wrapping when a stored value is out of range
No new features in this one. It’s our second full audit, read in parallel across the network loop, each eD2K path, Kad, the Ember overlay, storage and security, the command layer, the interface and the rendezvous server. Twenty-two findings held up and all of them are fixed here.
Two of them were costing people something every day. If you run Ember server-only, which is what you have if you’ve never pressed Connect on the Kad page, every reply peers sent you was being thrown away, so queue positions never moved while we kept asking for them. And roughly one in every 250 incoming connections from a stock eMule client was dropped before it started, over a byte we assumed eMule would never send and it turns out picks at random.
Before you upgrade
Nothing to do this time. Unlike 1.5.0, we didn’t change your library database, so you can move between 1.5.0 and 1.5.1 freely
Talking to other clients
Queue positions update again with Kad off. Replies from peers all arrive on the socket Kad uses: your place in their queue, whether a source is still alive, the answer to the UDP port test, reask relaying for firewalled peers. We discarded the lot whenever Kad wasn’t connected, and we kept sending the questions, so the traffic went out and nothing ever came back. Peers waiting in your queue got no acknowledgement either, and had to fall back or give up
eMule clients connect reliably. Our private friend handshake opens with a byte we believed eMule’s obfuscation could never begin with. It can: eMule picks that first byte at random and rules out only three values. Every collision sent an ordinary eMule client into the wrong handshake and dropped the connection, usually after making it wait ten seconds first
One peer’s “I don’t have that” doesn’t count against your other downloads. A peer declining one file was marked failed on every file you were getting from it, and any queue position you had just learned went out with it. Peers commonly serve several of your downloads at once, so this cost people working sources
Server names show up instead of an address. A server that sent its name in the compact form the eMule protocol also allows wasn’t parsed, so the list kept showing a bare IP for it
Uploads
A single peer can’t pin your disk and a CPU core. One small request asked us to hash an entire shared file start to finish, and nothing remembered the answer, so repeating the request cost the same work every time. It needed no upload slot, no queue position and no identity. On a large share a handful of packets could make the app unresponsive for minutes and stall your downloads with it
More upload slots on a slow connection. We guaranteed two upload slots where eMule guarantees four, and since the number comes from how fast you’re actually uploading, two slow peers kept it at two. You now serve as many peers as eMule would, and two trickling peers can’t hold your whole upload
Downloads
Peers that compress aren’t dropped mid-transfer. When another source finished the part you were working on first, a compressed block already in flight arrived with nothing to match it against, and we treated that as the peer misbehaving, closed the connection, then sat out a cooldown of nearly half an hour before trying again. Nothing is wrong at either end when this happens
Invented identities can’t push out real sources. When a file’s source list is full we drop the least valuable entry rather than the oldest. Which entries counted as least valuable depended on a name the sending peer chose, so a peer that made one up for each source it offered could push out sources you had already used, and its replacements were what we wrote to disk for next time
Repeated junk sources don’t displace working ones. A firewalled source offered with an id of zero can never be contacted, and zero was the one value our duplicate check couldn’t recognise, so the same packet sent again added another dead entry every time
A peer can’t make us hold hundreds of megabytes. While waiting for a corruption-recovery answer we set aside a fixed number of packets regardless of how large they were, and a peer could inflate them on purpose
Search
Each peer contributes everything it holds. Asking a peer for another page of results was meant to happen once it had sent a full page, but we compared a single network packet against the size of a whole page, and a page always arrives split across many packets. No peer was ever asked for a second page, so popular keywords returned only the first slice of what each one actually had
Friends and the Ember Network
Relayed transfers survive a quiet moment. When both sides are firewalled, traffic can go through the rendezvous server. A relayed connection that went quiet for thirty seconds was closed by the layer underneath even though the relay itself allows three minutes, and quiet is normal here: a peer parked in an upload queue says nothing for close to half an hour. This is a server-side fix and is already deployed, so it applies to 1.5.0 too
Kad storage can’t be filled by one peer. Comments and ratings published to your node had no per-publisher limit at all, so one peer could fill the space shared with keyword and source records. After that no new source could be stored, and honest keyword records were discarded to make room. Separately, a peer whose own record was about to be refused could still make us delete somebody else’s to clear space for it
Your data
An unexpected exit doesn’t discard the session. Our save-on-exit sequence ran against a deadline set forty-five seconds after launch. If the app closed any way other than being asked to, that deadline was long gone and every step was skipped: peer list, library checkpoint, credits, reputation, server list. The log blamed a slow disk. The library checkpoint on its own is what saves you re-hashing your whole share on the next start
Your identity survives an interrupted save. Replacing a file on Windows sometimes needs the old one moved aside first, and if the app died in that instant the only copy was left under a name nothing ever looked for again. For the identity file that meant the next launch generated a brand new one, silently resetting your Kad id, your friendships and your credit with every peer
A locked settings file doesn’t unapprove your folders. If we couldn’t read the record of which folders Ember may use at startup, and a backup tool or antivirus holding it open is enough for that, we treated it as damaged and replaced it with an empty one. Every shared folder and your download folder then had to be re-approved by hand
Backups are never shared to the network. Saving a profile backup into one of your shared folders got it indexed, hashed and offered to other peers like any other file. It holds your keys, so it should never have been publishable, however strong the passphrase
Two exports at once can’t destroy a backup. Starting a second export to the same file before the first finished interleaved the two and reported success, leaving a backup no passphrase could ever open where a good one used to be
The brief hitch every few minutes while we wrote the Ember peer list to disk is gone, and a slow save no longer eats into the time the other saves have
Our first full read-only audit of the app, plus the work that was prepared for 1.4.1. There is no 1.4.1 release; all of it ships here instead.
The headline is a bug that had been in 1.4.0 from the start: no file larger than 4 GiB could be downloaded at all. Most of the rest you had no way of seeing from outside the app. Uploads capped at a tenth of their limit, friends unable to find you, a source exchange that never answered, and several paths that failed without leaving a trace.
Before you upgrade
This release upgrades your library database, and 1.4.0 can’t open it afterwards. The upgrade is automatic and keeps your data, but it only goes one way. If you want the option of going back to 1.4.0, copy your Ember data folder somewhere safe before you install
What’s New
Diagnostics on the Ember Network page. Counters for source exchanges, how many offered sources we use versus filter out, replies too large for UDP, and storage rejections. Every one of them covers a path that used to fail without saying anything
What’s Fixed
Downloads
Files larger than 4 GiB download again. We rejected the very first block of data every source sent for a large file, because we believed the packet couldn’t describe a position that far in. Every source disconnected immediately and the download never started. Nothing above 4 GiB could be fetched from anyone, eMule or Ember
Less re-downloading after corruption. When a peer asked us to help pinpoint which small piece of a part was damaged, we built the answer wrong for most file sizes and it was rejected. That peer then had to fetch the whole 9 MB part again instead of the 180 KB block that was actually bad
Damaged archives salvage what they can. A single unreadable entry threw away the entire recovery, including everything already checked and rescued
Finished parts are on disk before we trust them. A part could be recorded as verified while its data was still only in memory. A power cut at that moment left us convinced the data was good, and we would then serve it to other peers
Progress doesn’t jump backwards. The bar could drop by a whole part near the end while the last piece waited to be checked
Uploads and sharing
Uploads aren’t stuck at a tenth of your limit. Upload Speed Sense briefly lowers your upload to measure a quiet connection before it starts managing speed. If it couldn’t find a peer to measure against, which is the normal case with Kad disabled, a failed bootstrap, or a restrictive router, it never finished measuring and stayed there for the whole session. Nothing in the interface said so
Your credit with other peers survives a restart. Credit earned by uploading was reset the first time each peer verified itself after we restarted, costing you the queue position you had built up
Credit is harder to steal. Our protection against a stranger claiming another peer’s identity to inherit their credit could never actually fire. Separately, anyone who knew a peer’s identifier could strip that peer’s standing by failing a single check on their behalf
Large libraries scan without stalling the app. We matched each finished file by scanning every file already indexed, which on a big share held up uploads and the interface for the length of the scan. Watching offline network shares doesn’t block the window any more either
Search
Nobody else can rename your download. When several peers answered for the same file we kept the longest name offered. Anyone can pad a name, so a single peer could rename a file in the results, and since that name is what we save the download as, on your disk too. The name most peers agree on now wins
Inflated results sink. A peer claiming an impossible number of sources sorted above every honest result
Turning Ember on takes effect immediately. Enabling the Ember Network from its own page left Search still convinced it was off, refusing Ember searches until you restarted the app
Searches find more. A popular file is held by many peers, and every copy it returned used one of the 300 result slots. Copies are counted once now, so a common file doesn’t crowd out everything else
Friends and the Ember Network
Friends can find you again. Registration with the rendezvous server restarted every ten seconds and threw away its own result each time, so it never completed. For most setups that meant you were never discoverable, friend transfers couldn’t start, and we re-registered forever
UDP source exchanges get answered. We built the reply for a connection where size isn’t limited, so on any client with a real download list it was too big to send and got dropped. It’s built to fit now, and sends fewer files rather than nothing
Your own address isn’t accepted back. Sources travel peer to peer, so one eventually came back pointing at you and left a download trying to connect to itself
Relay offers are charged to whoever sent them. A single peer could fill the relay list with entries it made up and push out relays learned elsewhere
A missed reply isn’t the end. A peer that failed to answer once was dropped from that search for good, and one lost packet is enough to cause it
Known-good peers stay known-good. Peers that had answered were pushed aside by ones we had merely heard about, so the connections actually in use went stale and were dropped
Downloads can’t be misdirected. Any peer could publish a false fingerprint for a file. We would finish the download, find it didn’t match, find nothing actually wrong with it, and start over from scratch, forever. Fingerprints now need agreement from several peers, and they never override one we worked out ourselves
Network protection
Ember isn’t usable as a reflector. Two of our handshakes replied to whoever a packet claimed to come from, with a response larger than the request. Both prove an address is real now before spending anything substantial on it, which also stops one peer being locked out of another’s connection list
Flood defences cost less than the flood. The tables protecting against packet floods searched tens of thousands of entries per packet, and chose the busiest peer to forget, which let an attacker reset the very limit meant to catch it. One tracker grew without limit
Shared storage can’t be monopolised. A single peer could fill the space we offer the network and lock out every honest publisher for a day, and could sidestep its own quota by changing port
A stalled server can’t wedge reconnection. A server that answered slowly but never finished logging in could hold us on “Connecting” for close to an hour with no fallback
Files, folders and updates
Changing a folder’s properties doesn’t break downloads. Compressing your download folder, turning off search indexing on it, or a cloud client marking it, all looked identical to the folder being swapped out. We revoked our own access, every download failed, and there was no way to restore it from inside the app. Saving Settings restores it now, and ordinary property changes are ignored
Installing an update doesn’t lose progress. The installer shut us down in a way that skipped saving, so every update discarded the resume data for downloads in progress, the library checkpoint that exists to avoid a full re-scan, and the peer and server lists
“Up to date” instead of a security warning. If the published release was older than the version installed, every check failed with a warning rather than telling you there was nothing to install
Chat day separators stay correct across daylight saving changes, and remote text can’t use invisible characters to disguise how a name reads
The Ember Network beta. 1.4.0 turns on our own encrypted overlay by default, so peers can find each other, publish what they share, and discover download sources without a central directory. File bytes still move over the familiar eD2K path.
What’s New
Ember Network (beta)
On by default. The overlay joins on its own. Profiles that still had it switched off from an older default are migrated on, and we tell you if anything was flipped
Finding other Ember users. Nodes meet through a well-known KAD rendezvous key, through Ember peers we notice in ordinary KAD traffic, and through eD2K transfers with Ember-capable clients. There is no central bootstrap pool and no seed list shipped in the build
Publish and search. Shared files are published so other Ember users can find them, and keyword search and source lookup run on the Ember DHT alongside KAD and servers
Downloads still use eD2K. Ember finds the source; the file transfers client to client over eD2K. Keep KAD or servers available so a fresh install can join
Ember Network page. Redesigned to show whether you’re connected, whether people can reach you, and whether your shared files are published, with the technical diagnostics kept collapsed
A versioned wire format. Incompatible peers refuse each other cleanly instead of looking like packet loss
Library
Ember share badges. The Library’s Shared column shows when a file has a live Ember source record
What’s Fixed
No full re-hash on every launch. An idle startup doesn’t re-hash the whole library when nothing has changed
An audit pass over everything added since 1.3.5: publish, search, store replay limits, table admission, and the edges around them
Disabling Ember stops advertising under the rendezvous key, so other nodes don’t spend bridge pings on a peer that won’t answer
The developer-only Ember console is out of the shipping build
A reliability release, and the result of a full audit. Most of what it fixes was quiet by nature: settings that didn’t apply, messages that were never shown, and a library that could stop indexing without telling you.
Library and sharing
One slow file doesn’t empty your library. A file that took more than five minutes to hash cancelled the whole scan and discarded everything not yet indexed, and it happened again on every launch, so files went missing from your share with no explanation. Large files on a network share, an external drive or OneDrive are left for a later attempt now, while the rest of the scan carries on
Adding a folder can’t wedge. A file whose read never returned could hold the scan lock for the rest of the session, blocking every later folder add or reload and delaying shutdown. That wait doesn’t hold the lock any more
Copy All Links on large libraries. Copying every link failed outright above 50,000 files. It’s sent in batches now
Accurate scan warnings. The “only the first 100,000 files were indexed” notice appeared on ordinary reloads of any large folder. It only shows up when the limit was actually hit
Excluded files stay excluded. Part-finished downloads, our own temporary and backup files, and anything inside the Ember data folder could come back into your share through the known-files list
Failures are visible. When the library failed to load, we rendered an empty library with an invitation to add a folder. It reports the error now
Friends and chat
Privacy toggles take effect. Turning off incoming chat or browsing did nothing at all if the save failed: the switch stayed on and the setting never reached the network. The switch reverts now, and you get told
No more missing messages. Sending the same text twice in quick succession delivered both and showed one, and the second stayed invisible until you reopened the conversation
Queued messages reach their friend. A message typed while a friend was offline could stay marked queued indefinitely after they came back, if the reconnect reused a connection that was already open
Abandoned messages say so. A queued message we’ve given up on shows as failed instead of reading “queued” for the rest of the session
Unread badges while minimised. Messages that arrived with the window minimised were marked read and raised no badge, so they were easy to miss entirely
Browsing a friend. A friend sharing two copies of one file could blank the browse window
Transfers
Archive recovery works again on large files. Recovery of a part-finished archive ran out of time before it began on anything multi-gigabyte. Those are the files people actually want it for
Lighter Known Clients tab. Trust badges issued one lookup per credit record every few seconds, which on a mature client list meant thousands at once and could crowd out other work
Search
Preferences are saved. Search method, filters, sort order and column choices were never written to disk and reset on every launch
Stop actually stops. Results kept arriving in a search that had been stopped, and a stop that failed to reach the network said nothing
Held Enter. Holding or repeatedly pressing Enter opened an unbounded number of searches and tabs
A failed notes lookup was indistinguishable from a file that genuinely has none
Settings
Unsaved changes are protected. Clicking away to another page discarded pending edits without asking
Empty number fields. Clearing a box and saving stored that field’s factory default, including the listening ports, and could prompt a restart for a change you never made
Choosing a language. Arrow keys committed a language and restarted the app mid-selection, so you couldn’t browse the list from the keyboard
Bandwidth fields. After typing in a speed box, Apply Recommended and Discard didn’t update what was shown, so the value saved wasn’t the value on screen
Security
Fail closed on durable state. Closes silent data loss from unsaved transfers, mixed backup restores and chat that vanished after a reload, and bounds resource exhaustion in rendezvous admission, relays and oversized friend requests
Stricter URL checks. Our rejection of credentials embedded in a URL could be sidestepped by leaving out the slashes after https:, which would let a download link display a trusted host while fetching from somewhere else. IPv6 addresses are handled properly again too
Deep links. An ed2k:// link that failed once stopped every later link from being handled for the rest of the session. The confirmation prompt also shows the file name, size and hash on separate lines rather than running them together
Archive recovery limits. A deliberately crafted archive could keep recovery scanning past its own time limit and ignore a cancel
Relay stability. Live relay sessions were torn down by ordinary congestion instead of waiting for it to clear
Smaller things
Two crashes that blanked a page outright: repeated lines in the server log, and duplicate entries in a friend’s file list
Error notifications appeared behind the dialog whose failure they were reporting, so the message was invisible at the moment it mattered
The “TCP port already in use” warning disappeared a few seconds after appearing, while uploads stayed broken
The update notice did nothing once an update had downloaded or failed, leaving the banner on screen until restart
A security notice was unreadable in the light theme, and several error messages ended in the word “undefined”
Re-selecting a played audio or video file restarted it from the beginning without being asked
A folder priority we had rejected stayed on screen as though it had been applied
Move Ember to a new PC. Settings > Backup writes your whole profile to one passphrase-encrypted .emberbackup file and restores it on another machine or after a reinstall. Your identity, secure-identification keys and upload credits come across, so your standing on the network survives the move
What it covers. Identity and SecIdent keys, credits, settings, the shared-folder list, known files, friends, chat history, the transfer list, server and KAD contacts, the IP filter, and learned spam data. The files you share and part-finished downloads stay out, so the backup stays small
Always encrypted. The archive holds your private keys, so a passphrase is required rather than optional, and Windows-bound key material is re-wrapped for whichever account restores it. A lost passphrase can’t be recovered
Safe restores. A restore is prepared immediately and applied while Ember next starts, because the files it replaces are in use while Ember runs. We keep the replaced originals in a pre-restore folder, and you can discard a pending restore before it’s applied
Transfers
Stop All and Cancel All. Both sit beside Pause All and Resume All in the toolbar’s More menu. With the Filter box narrowed they act only on the downloads you can see, and the confirmation says which filter it matched
Bulk actions on finished downloads. Completed and failed rows can be selected like active ones and removed together, instead of one right-click at a time. Your files are kept; only the list entries go
Clearer selection. Each bulk button reports how many rows it would affect and greys out when none apply, so a mixed selection can’t silently do nothing
Search
Copy eD2K links for one result, for every ticked result, or for the whole list at once, from the right-click menu, the selection bar, or Ctrl+C. No need to start a download just to get its link
What’s Fixed
We stopped looking like an eMule that misreports its version. Our MuleInfo packet carried a real version byte where eMule expects a sentinel, which is what anti-leecher mods treat as a spoofed client, and it could cost you upload slots or credit score
Friends-only shares. Mark Library files as friends-only so they stay out of public search and only mutual friends can request them. Non-friends are refused at the protocol layer
Friend file offers. Push a specific shared file to a mutual friend from the Friends page. Offers arrive as notifications the recipient can accept or decline, with rate limits and expiry
Friend transfers without HighID. Mutual-friend downloads can use the Noise-secured friend session when ordinary HighID or callback paths aren’t available. We can also discover optional peer relays through friend gossip for harder NAT cases
Friend block list. Block a Friend ID and future requests, chat, browse and offers from that identity are rejected. Blocking also removes any existing mutual friendship with it
Durable offline chat queue. Outbound friend messages stay queued across reconnects and app restarts, then retry when the friend session is back. Undeliverable messages surface as failed instead of hanging forever
Knowing when you’re reachable. The Friends page warns when you aren’t currently discoverable on the rendezvous network, and a friend card can show when a peer is online but not reachable for a direct connection
Optional friend relaying. Help friends connect (Settings) controls whether you advertise willingness to assist LowID↔LowID paths. Turn it off if you’d rather not relay for other people
Friend chat polish. Clearer conversation grouping, day separators, and tab scrolling in the chat dock
What’s Fixed
Friends-only share flags survive Library rescans and resume paths, and are enforced for downloads already in progress rather than only fresh requests
Friend relay discovery works in both directions on secure friend sessions, with safer candidate caps and clearer failure attribution, so we don’t drop a good relay because the far side refused
Friend file offers are harder to spam, and friend-connect hints don’t mis-attribute progress to the wrong peer
Friend cards redesigned. One compact row per friend, presence shown once, and the secondary actions (Browse, Reconnect, Copy Friend ID, Remove) collected in an overflow menu with the Friend ID and last address
Friend browse redesigned. Download controls are clearly visible, and a filter box narrows a large shared library
Fewer interruptions. No toast when a friend comes online or goes offline, since the card already shows it. Actionable notices, like a friend being behind a firewall or needing a newer Ember, still appear
Diagnostics
Panics are written to ember.log, so a crash during startup records its cause instead of closing silently
Transfers and statistics
Known Clients shows a friend’s nickname, last address, country and last-seen, instead of just a name
Interface
Fits laptop screens. The sidebar auto-collapses on narrower windows, the status bar and Transfers columns compact, and the Library folder drawer overlays instead of squeezing the file table. 4K layouts are unchanged
The default window is 1400×900, so the app fits without scrolling on a 16″ laptop
Unread chats show a blue dot rather than an orange count
KAD page: we removed the redundant Ember peers and EPX sources tiles. Both are still in the status bar
What’s Fixed
Ember starts when a shared or download folder’s filesystem identity has changed, for example a folder that was deleted and recreated, or a re-imaged drive. We revoke the affected folder instead, and you can re-approve it from Settings, so a stale record can’t keep the app from launching
Unreadable folder-approval state is quarantined instead of being treated as fatal
Friend downloads reconnect after both clients restart. A rediscovered friend’s address is reseeded into your existing download sources
Statistics: File Requests protocol overhead is measured now. It used to always read zero
One-sided Add Friend when both peers are online. Friend-code intro presence lets you find someone before mutual pairwise capabilities exist
Adding or accepting a friend forces a rendezvous presence refresh, so discovery doesn’t wait about two minutes
Clearer “not found” messaging when the peer is offline or still needs to add you back
Ember and EPX
EPX and Ember mesh peer discovery unlock on the HELLO hash↔pubkey binding. Legacy proof-of-possession is disabled and was blocking the status bar EPX count and the KAD Ember peer count
Friend privileges (chat, browse, verified requests) still need a secure friend session or PoP
A security and Friends release: end-to-end friend chat, hardened sessions and updater, safer file opens, and a batch of Library, EPX and connectivity fixes since 1.2.3. Please tell us if anything here misbehaves.
Friend chat is end-to-end encrypted (static X25519 ECDH plus AEAD), and plaintext chat fallbacks are rejected once a session is set up
Chat shows an Encrypted badge, and errors point you at reconnecting when encryption fails
Friend sessions use Noise IK secure streams, with chat history encrypted in the local database
v2 Friend Codes and privacy-preserving rendezvous capabilities (pairwise presence). The Friends page explains how mutual chat and browse unlock
A signed anti-rollback updater with security epochs. An install only advances when the signed epoch allows it
Deep links need confirming before they open, and you can review a pending link later
Dragging a folder into Library asks you to confirm in a system folder picker before sharing it
Queued downloads over the safety budget are quarantined rather than deleted, with a notice in the app
A corrupted or unreadable ban–reputation policy prompts an explicit acknowledge and reset before networking continues
The default window is 1920×1200 on first launch
The updater treats a missing manifest or signature (HTTP 404) as “no update”, so a check doesn’t fail while release assets are still uploading
The first-run and Settings IP filter download uses the live ipfilter.zip mirror, the same one Security uses, and remembers the enable preference
What’s Fixed
Library and media
Library activity, collections, media playback and bulk actions persist and clear busy state correctly
Media serve doesn’t reopen files by path after approval, which was a TOCTOU. Reads stay on the approved handle
Friends, EPX and transfers
EmuleInfo no longer clears Ember identity during EPX auth
AICH trust is scoped to the local file hash, and AICH upload requests use the pinned open handle
Oversized UDP exchanges are refused, ERAT trailer space is reserved, and UDP ingest is rate-limited
Attestation expiry is honored, reserved EPX versions are rejected, and mesh discovery requires PoP
Friend and Ember upload-queue priority flags reset correctly across sessions, so there’s no sticky queue boost
Archive recovery hashing opens the recovery file handle-safe instead of reopening by path
Upload and completion paths pin approved handles so a path-swap race can’t slip through
Connectivity and rendezvous
NAT TCP mappings are discovered over TCP instead of inferred from UDP STUN readings
Friend punch doesn’t fail open on legacy proof v3 during v4 sessions, and rendezvous filters legacy entries on v4 polls
Mailbox delivery is page-cached with idempotent replay, so a crash mid-page can’t permanently skip messages
Rendezvous and friend flows stay compatible across protocol v3 and v4 without breaking stock eMule traffic
Updater, deep links and setup
Install stays offered when a verified pending update is retained after the native updater clears pending state
Deferred deep links survive handler remounts without reopening twice
Windows shared-folder prepare doesn’t delete an opened directory entry on a path or type mismatch
Added the missing translation for invalid terminal deep links (deeplink_terminal_invalid)
A connectivity fix for STUN and NATMAP keep-alive: we advertise the remapped public TCP port again, and a LowID session reconnects so the eD2k server learns it. Please tell us if anything here misbehaves.
When STUN keep-alive confirms a remapped public TCP port while you’re still LowID, we reconnect to the eD2k server, with a 60-second cooldown, so it can retry HighID connect-back with the corrected port
What’s Fixed
STUN keep-alive advertises the twin-probe’s public TCP port again, gated on stability (corroborated immediately, or after two matching readings), instead of always mirroring the configured listen port. HighID and public port status can improve behind full-cone NAT and CGNAT
A remapped TCP port discovered after login isn’t left unused on an already-connected LowID session
A reliability release: Library sharing and large-collection workflows, download source counting, Settings save hangs, relay and friend connects, and KAD publish validation.
Library warns clearly when a shared folder hits the 100,000-file per-folder indexing cap
Settings and Security report whether saves, nodes.dat and IP filter updates were applied live, deferred, or need a restart
Collection create and load use native OS dialogs, so exports aren’t forced into shared or download folders
ed2k:// links and collection opens are persisted until they’re handled, so they survive relaunches and setup-wizard restarts
What’s Fixed
Library
Stale pending share and priority intents don’t silently re-share or flip priority after a rehash
Share, unshare and priority changes persist more safely, with rollback, and apply hash-wide across identical copies
Bulk share, unshare and priority actions work on large selections (batched IPC)
Remove missing keeps clearing until the scan has actually finished, so no missing rows are left over after the 10k batch limit
Large collections: Download All queues in chunks instead of failing wholesale, with skip, oversize and failure feedback
Top Uploads de-dupes by hash, shows total uploaded, and explains unattributed older history when only aggregate totals exist
Keyboard shortcuts work again with the collections panel open, and are blocked correctly during stop-hash confirmation
In-app media playback uses a scoped ember-media protocol that re-checks shared and download roots per request
Duplicate library copies don’t force unnecessary rehashes of non-canonical paths
Downloads and sources
Ephemeral callback and push-grant ports are session-only, so they don’t inflate per-download source counts across relaunches
Resume and reasks prefer dialable listening ports and skip undialable ephemerals
Max download file size is aligned to the ED2K wire limit (593 GiB), and large-file part-count and hashset handling doesn’t truncate into bogus values
MultiPacket parsing is more tolerant of peer extended-request variants
Sharing and settings
Saving Settings doesn’t hang behind long library hashes and scans when shared folders change; folder reconcile runs in the background
Removing a shared folder cancels in-progress scans under that root sooner
Clearer save and download messaging when a live network apply has to wait for a restart
Relay, rendezvous and friends
Friend relay tickets hardened (v3 candidate polling, quota and reservation cleanup, legacy v2 cursor sweep) for more reliable LowID friend connects
Browse friend cancels and correlates by request ID, so stale or swapped results don’t land in the wrong dialog
Friend sessions close and evict cleanly, and relay tickets are limited to manually known friends
STUN keep-alive doesn’t override your configured TCP listen port in Hello and advertising. The UDP mapping stays UDP-only
KAD and protocol
KAD keyword publishes without a filename, size or tags are rejected, so there’s no more empty junk served back to searchers
Published source entries with UDP port 0 fall back to the packet’s real source port, which is what eMule does
Safer .part.met save-path guard cleanup after a download is removed
Search and UI
Backspace doesn’t delete a hovered saved search. Only Delete removes recent entries
Deep-link handling doesn’t double-apply or drop links across restarts and HMR
The setup wizard reports deferred or failed live apply for nodes.dat and the IP filter more clearly
Library table rows support Enter and Space activation, and we filled assorted i18n gaps
Connectivity and Library quality of life: STUN and NATMAP port keep-alive for CGNAT and cone NATs, a Simplified Chinese interface, and a few Library and chat fixes.
Network and HighID
STUN port keep-alive (Settings, on by default) keeps NAT mappings alive with periodic STUN plus a TCP hold from your listen port, and advertises the discovered public TCP and UDP ports for HighID. Useful behind CGNAT or full-cone NAT without UPnP
It auto-suspends on Open or Symmetric NAT, or on unstable port remapping, then falls back to your Settings ports
Home status shows when keep-alive is active and which public ports are being advertised
Library
Copy all eD2K links for the current Library view in one shot, as a single IPC batch, so it works on large libraries
Localization
Simplified Chinese (zh-CN), including the Settings picker and system-language detection (zh and zh-Hans map to zh-CN)
What’s Fixed
Library Missing stays greyed out until a scan actually finds missing files
Closing an active chat tab doesn’t resurrect its wiped draft when you reopen a chat later
The rendezvous-server Docker image builds again; the Rust toolchain pin is aligned with rust-version
Global, Server and KAD search line up more closely with eMule: UDP eligibility and reply auth, Arc/Iso→Pro wire types, KAD AND stripping, availability merge, and stop-cap accounting
We request more server results (OP_QUERY_MORE) automatically when a page is full, up to the eMule-style limits
Shared and downloading files are skipped when counting toward the ed2k search stop limit. The results still appear
Hide spam moved into Advanced Filters, and the empty-server “retry” banner is gone
Uploads
HighID waiting peers are dialled to grant upload slots (AddUpNextClient / push-grant), with concurrency and backoff limits
Soft-zone admission judges newcomers by credit and file priority instead of a zero-wait score
Downloads and transfers
KAD, TCP and UDP source discovery start for queued and add-paused downloads, so sources are ready when you resume
Resume All includes Stopped downloads
Pause All, Resume All and Clear Completed are collapsed into a More menu, which closes on Escape and on an outside click
Library and status
Redesigned Library detail drawer, with sections, missing and hashing banners, and context Properties
Total shared size sits next to the shared-file count in the status bar
Better missing-file scan feedback and bulk selection toasts
Statistics
Completed Uploads counts only when a peer received the entire file in that session
Cumulative counters don’t roll backward across save races, zero durations show as 0s, and empty overhead bars are hidden
What’s Fixed
Connectivity and firewall
Reconnect backoff and per-server cooldowns are honored, and LowID stays sticky against a false “Open” from UPnP
Mid-session OP_IDCHANGE (LowID to HighID) is handled without a full disconnect where possible
A known Open or Firewalled status is preferred over a stale Unknown in the interface
Transfers
Batch cancel always removes the database rows, so cancelled downloads don’t resurrect after a restart
Spam-filter saves are serialized to avoid lost or out-of-order writes
Installer
The desktop shortcut isn’t recreated during in-app updates (/UPDATE), which was making duplicate desktop icons
An in-app media player for playable audio and video
Playable files open from the detail drawer, with Open Externally still there
Search
Polished the search tab stop and close controls
KAD store, search and verify paths line up more closely with eMule: wire publisher IDs, verified contact seeding after a cold start, legacy Hello challenges, and dropping oversized KadRes
What’s Fixed
Security and trust
Peer-relay (ERAT) requests require Ed25519 proof-of-possession, and legacy hash-only RELAY_REQUEST payloads are rejected
EPX trust hardened: PoP required on TCP source exchange, KAD Noise keys pinned, and ERAT TTL handling aligned
Bare-nonce Ember auth is gone in favor of domain-separated signed auth only
IP filtering hardened: the live filter is kept during an async reload or enable, we fail closed on reload errors, always reject bogus inbound TCP, and honor block_private on source inject paths
Downloads and sources
IP filter, ban and reputation checks are unified across dial and inject paths
Insufficient-space downloads are kept across a restart
Mid-download disk-full is classified as insufficient space instead of a generic failure
Friend-related and settings hot-reload fixes from the audit pass: live friend toggles, browse and chat gates, and nickname, max-sources and filter-server updates without restart noise
If you’re on 1.1.3, this is the one to install. 1.1.3 migrated the database on first launch and then refused to open it again.
What’s New
A link to the Ember website from the About dialog and Settings → About
What’s Fixed
Fixed the schema version gate so Ember can open databases after the v20 migration (credits.ember_hash). 1.1.3 migrated on first launch, then refused to start on every later launch