github Power2All/nanotorrent v0.4.4
NanoTorrent 0.4.4

6 hours ago

Changes since 0.4.3.

  • Security: the web interface over HTTPS is no longer open to a denial of
    service in its HTTP/2 layer. The HTTP/2 library it used (h2 0.3) can be made
    to queue empty data frames without limit, by anyone who can reach the port -
    before logging in. The fix exists only in a newer h2 that the web framework
    does not support yet, so the web interface now speaks HTTP/1.1 only and that
    library is no longer part of the program at all. Browsers switch over by
    themselves; nothing needs changing on your side. This only ever mattered with
    the web interface switched on and reachable from other machines - it is off,
    and bound to this computer only, by default.

  • A ratio limit now stops a torrent at the ratio you see. The ratio column
    counts everything a torrent has ever uploaded, but the check that enforces
    the limit was still counting only what it had uploaded since NanoTorrent was
    last started - or since any setting was last changed - so a torrent showing
    3.9 against a limit of 2.0 could carry on seeding. Both use the same figure
    now. If share limits are switched on, torrents already past their limit get
    the chosen action within seconds of the first start: paused, or removed if
    that is what you picked.

  • The AppImage starts on systems that do not have libxkbcommon-x11 installed.
    The window toolkit loads that library only when it opens a window, so it was
    never picked up when the AppImage was packed, and on a minimal system the
    program quit at once with "Library libxkbcommon-x11.so could not be loaded".
    That is what kept it out of the AppImage catalog. It is bundled now, and the
    release build checks for it by starting the AppImage on a virtual display -
    with the system's own copy removed - and waiting for its window.

  • v1 torrents made with Create Torrent are always valid. When the data added
    up to an exact multiple of the piece size, the torrent carried one piece
    hash too many, which stricter clients refuse; a folder could also come out
    as a different torrent on another computer, because its files were listed
    in whatever order the disk gave them. v1 is now built by the same code as
    v2 and hybrid: files in name order, an automatic piece size that grows with
    the data instead of always 2 MB, a clear error for a file name that is not
    valid Unicode instead of a dialog that kept hashing forever, and a folder
    that links back into itself is no longer followed round and round.

  • Force recheck and Set location on a paused torrent check the data straight
    away, and the torrent stays paused - as does moving one from the web
    interface or a plugin, and editing its trackers. Before, it dropped to 0%
    and was only checked once you started it, so a recheck of a complete,
    paused torrent made it look empty.

  • A torrent that opens NanoTorrent - a .torrent file or magnet link
    double-clicked while the program is closed - now gets its "added" message
    and reaches plugins like any other. Anything added in the
    first second after startup used to be taken for part of the restored list.

  • Plugins: torrent() and torrents() report each torrent's label. They always
    gave an empty one.

  • A PicoTorrent install is no longer copied into NanoTorrent's profile behind
    your back on first start. File > Migrate from > PicoTorrent brings its
    torrents, labels and settings across when you ask for it.

Under the hood: two rounds of dependency updates, all within their current
versions - tokio, hyper, mio, zerocopy, actix-server, async-compression,
calloop, libc, quinn, uuid and several smaller ones. cargo audit now has a
single ignored advisory left, and that one cannot be reached (see
.cargo/audit.toml). Eight web-server settings that nothing has read since
0.4.0 are removed from the settings database. And a set of tests now drives a
real torrent session - create, seed, pause, recheck, move, relocate, restart -
so a change that breaks any of those fails before it ships.

Don't miss a new nanotorrent release

NewReleases is sending notifications on new releases.