Changes since 0.4.3.
-
Security: the web interface over HTTPS is no longer open to a denial of
service in its HTTP/2 layer. The HTTP/2 library it used (h2 0.3) can be made
to queue empty data frames without limit, by anyone who can reach the port -
before logging in. The fix exists only in a newer h2 that the web framework
does not support yet, so the web interface now speaks HTTP/1.1 only and that
library is no longer part of the program at all. Browsers switch over by
themselves; nothing needs changing on your side. This only ever mattered with
the web interface switched on and reachable from other machines - it is off,
and bound to this computer only, by default. -
A ratio limit now stops a torrent at the ratio you see. The ratio column
counts everything a torrent has ever uploaded, but the check that enforces
the limit was still counting only what it had uploaded since NanoTorrent was
last started - or since any setting was last changed - so a torrent showing
3.9 against a limit of 2.0 could carry on seeding. Both use the same figure
now. If share limits are switched on, torrents already past their limit get
the chosen action within seconds of the first start: paused, or removed if
that is what you picked. -
The AppImage starts on systems that do not have libxkbcommon-x11 installed.
The window toolkit loads that library only when it opens a window, so it was
never picked up when the AppImage was packed, and on a minimal system the
program quit at once with "Library libxkbcommon-x11.so could not be loaded".
That is what kept it out of the AppImage catalog. It is bundled now, and the
release build checks for it by starting the AppImage on a virtual display -
with the system's own copy removed - and waiting for its window. -
v1 torrents made with Create Torrent are always valid. When the data added
up to an exact multiple of the piece size, the torrent carried one piece
hash too many, which stricter clients refuse; a folder could also come out
as a different torrent on another computer, because its files were listed
in whatever order the disk gave them. v1 is now built by the same code as
v2 and hybrid: files in name order, an automatic piece size that grows with
the data instead of always 2 MB, a clear error for a file name that is not
valid Unicode instead of a dialog that kept hashing forever, and a folder
that links back into itself is no longer followed round and round. -
Force recheck and Set location on a paused torrent check the data straight
away, and the torrent stays paused - as does moving one from the web
interface or a plugin, and editing its trackers. Before, it dropped to 0%
and was only checked once you started it, so a recheck of a complete,
paused torrent made it look empty. -
A torrent that opens NanoTorrent - a .torrent file or magnet link
double-clicked while the program is closed - now gets its "added" message
and reaches plugins like any other. Anything added in the
first second after startup used to be taken for part of the restored list. -
Plugins: torrent() and torrents() report each torrent's label. They always
gave an empty one. -
A PicoTorrent install is no longer copied into NanoTorrent's profile behind
your back on first start. File > Migrate from > PicoTorrent brings its
torrents, labels and settings across when you ask for it.
Under the hood: two rounds of dependency updates, all within their current
versions - tokio, hyper, mio, zerocopy, actix-server, async-compression,
calloop, libc, quinn, uuid and several smaller ones. cargo audit now has a
single ignored advisory left, and that one cannot be reached (see
.cargo/audit.toml). Eight web-server settings that nothing has read since
0.4.0 are removed from the settings database. And a set of tests now drives a
real torrent session - create, seed, pause, recheck, move, relocate, restart -
so a change that breaks any of those fails before it ships.