NEWS 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716
  1. aria2 1.18.9
  2. ============
  3. Release Note
  4. ------------
  5. This releases fixes memory leak with OpenSSL and crash on OSX when
  6. proxy is used. We added several new features. Adler32 checksum is
  7. now available in --checksum option and hash element in Metalink files.
  8. We added --bt-detach-seed-only option, which excludes seed-only
  9. downloads when counting concurrent active downloads (-j option). We
  10. disabled SSLv3 by default. If you ever want to enable it or further
  11. tune the TLS protocols to enable, use new --min-tls-version option.
  12. --bt-force-encryption option was added to make requiring BitTorrent
  13. full encryption easier. From this release, we build Android binary
  14. using API level 16.
  15. Changes
  16. -------
  17. * Support HTTP date ending "+0000" as well as "GMT".
  18. Closes GH-330
  19. * Revise getRandom facilities
  20. Use one of the following to provide random bytes:
  21. - Windows CryptGenRandom
  22. - Linux getrandom (syscall interface to urandom, without nasty
  23. corner cases such as file descriptor exhaustion or re-linked
  24. /dev/urandom)
  25. - std::device_random (C++ random device, which usually will be
  26. urandom)
  27. This also equalizes util::getRandom and SimpleRandomizer (the former
  28. will now use the latter) instead of having essentially two different
  29. PRNG interfaces with potentially different quality.
  30. Closes GH-320
  31. * Added debug log of all Metalink URLs with final priorities
  32. Patch from Dan Fandrich
  33. * Use gcc-4.9 and android-16 API level for android build
  34. * Add --bt-force-encryption option
  35. This option requires BitTorrent message payload encryption with
  36. arc4. This is a shorthand of --bt-requre-crypto
  37. --bt-min-crypto-level=arc4. If true is given, deny legacy
  38. BitTorrent handshake and only use Obfuscation handshake and always
  39. encrypt message payload. This option defaults to false.
  40. * TLS: Fix memory leak with OpenSSL
  41. Based on the patch submitted by midnight2k
  42. * Warn about insecure SSL connections.
  43. Fixed GH-313
  44. * Add --min-tls-version option
  45. The --min-tls-version option specifies minimum SSL/TLS version to
  46. enable. Possible Values: SSLv3, TLSv1, TLSv1.1, TLSv1.2 Default:
  47. TLSv1
  48. * LibsslTLSContext: Disable SSLv3 and enable ECDHE cipher suites
  49. * Add Dockerfile.mingw
  50. Dockerfile.mingw builds aria2 Windows binary. It is probably the
  51. easiest way to build the Windows binary.
  52. * Fix crash when JSON batch response vector is empty
  53. * Fix doc: Wrong rpc secret token prefix
  54. * Add --bt-detach-seed-only option
  55. This option excludes seed only downloads when counting concurrent
  56. active downloads (-j option). This means that if -j3 is given and
  57. this option is turned on and 3 downloads are active and one of those
  58. enters seed mode, then it is excluded from active download count
  59. (thus it becomes 2), and the next download waiting in queue gets
  60. started. But be aware that seeding item is still recognized as
  61. active download in RPC method.
  62. * mingw: Use MoveFileExW for better atomic move
  63. * Work around libintl's vprintf macro messing with OutputFile::vprintf
  64. Patch from David Macek
  65. * Fix crash on OSX when proxy is used
  66. See GH-275
  67. * Support Adler32 checksum
  68. Adler32 checksum is available for --checksum option and hash element
  69. in Metalink files. Currently, we use Adler32 implementation in
  70. Zlib.
  71. aria2 1.18.8
  72. ============
  73. Release Note
  74. ------------
  75. This releases fixes the bug that aria2 cannot read piped stdin on
  76. mingw32. It also fixes busy loop on mingw32 when SSL/TLS is used. We
  77. also fixed 2 crashes which can occur on all platforms.
  78. Changes
  79. -------
  80. * WinTLS: Fix abrupt connection closing and closing in general.
  81. Fixes GH-277
  82. * LibsslTLSSession: Treat 0 from readData as EOF
  83. * Enable dynamicbase and nxcompat in Windows binaries
  84. * Fix crash in OpenedFileCounter::ensureMaxOpenFileLimit()
  85. The crash happens if PieceStorage and/or DiskAdaptor are not
  86. initialized in one of active RequestGroups.
  87. * mingw32: Fix bug that aria2 does not read piped stdin
  88. * Fix std::length_error when no_proxy is used
  89. This is regression introduced in 8cada497.
  90. * Try to set sane limits for RLIMIT_NO_FILE
  91. E.g. on OSX the default is 256, which isn't exactly compatible with
  92. torrent downloads.
  93. Closes GH-257
  94. * Delay auth failures instead of PBKDF2
  95. Closes GH-256
  96. aria2 1.18.7
  97. ============
  98. Release Note
  99. ------------
  100. This release fixes regression which makes 100% CPU utilization in
  101. multi-file torrent download with -V option. It also fixes build error
  102. on big endian platforms.
  103. Changes
  104. -------
  105. * Fixed segfault unsupported encodings
  106. Patch from diadistis
  107. * Fix regression 100% CPU utility when -V is used and download is
  108. multi-file bittorrent downloads.
  109. This is regression of a3426821c8a7f9cf8d80a81726157d4eb844f661
  110. * Fix compile error on big endian platform
  111. aria2 1.18.6
  112. ============
  113. Release Note
  114. ------------
  115. This release fixes several bugs reported in github issues and adds a
  116. feature to make RPC authentication more resilient to certain attacks.
  117. New option --pause-metadata is added. The explanation is a bit log,
  118. so check the changelog and manual. The session is now only saved if
  119. there are changes from the last saved state.
  120. From this release, MinGW32 build uses Windows native TLS
  121. implementation and no longer use OpenSSL library.
  122. Changes
  123. -------
  124. * Disard cache when checking checksum
  125. This will slow down checksum checking but does not thrash cache.
  126. * Compat with libuv 0.11 (Unstable)
  127. Fixes #241
  128. * Drop WinMessageDigestImpl.
  129. The algorithms the `CryptProv` on Windows supports does not
  130. currently include SHA-224, so there is a "dark spot" in this
  131. implementation. Also on Win XP < SP3, most of the SHA-2 family is
  132. not actually supported. All other implementation provide support
  133. for MD5, SHA-1 and all of the SHA-2 family, hence drop the
  134. incomplete WinMessageDigest implementation in favor of any other
  135. supported implementation (at least the internal implementation is
  136. always available at compile-time).
  137. * Add --pause-metadata option
  138. This option pauses downloads created as a result of metadata
  139. download. There are 3 types of metadata downloads in aria2: (1)
  140. downloading .torrent file. (2) downloading torrent metadata using
  141. magnet link. (3) downloading metalink file. These metadata
  142. downloads will generate downloads using their metadata. This option
  143. pauses these subsequent downloads.
  144. * Improve compiler/platform/libs information in logs
  145. Add and use usedCompilerAndPlatform(). This adds compiler
  146. information to INFO logs and the --version output, and may be
  147. helpful when trying to diagnose/reproduce user-reported problems.
  148. Also make INFO logs include usedLibs() output.
  149. Closes #235
  150. * Fix use-after-free on exit with multi-file torrent download + DHT
  151. DefaultPieceStorage may be referenced by one of DHT task (e.g.,
  152. DHTPeerLookupTask), after RequestGroup was deleted, and even after
  153. RequestGroupMan was deleted. DefaultPieceStorage has a reference to
  154. MultiDiskAdaptor which calls RequestGroupMan object on destruction.
  155. So when DHT task is destroyed, DefaultPieceStorage is destroyed,
  156. which in turn destroys MultiDiskAdaptor. DHT task is destroyed
  157. after RequestGroupMan was destroyed, MultiDiskAdaptor will use now
  158. freed RequestGroupMan object, this is use-after-free.
  159. * Fix bug that zero length file is not opened when flushing cache
  160. This bug was only seen when MultiDiskAdaptor was used.
  161. * Support PREF_DIR change for Metalink files
  162. Reworked previous commit adeead6f0396e2f8551d1182972e277728fd6c8b,
  163. and now support changing PREF_DIR for Metalink downloads.
  164. * Fix assertion failure when dir option of paused HTTP/FTP download is
  165. changed
  166. When the directory is changed via aria2.changeOption RPC method, we
  167. directly change first FileEntry's path using FileEntry::setPath().
  168. If there is no PREF_OUT option is given, basically file name is
  169. unknown, so we just set empty string and let the next run determine
  170. the correct file name and new directory is applied there. But
  171. previous code does not reset length property of FileEntry, so the
  172. unexpected code path is taken when unpaused and its path expects
  173. path is not empty string. This commit fixes this issue by setting
  174. length to 0 using FileEntry::setLength().
  175. * Save session only when there is change since the last serialization
  176. This is a slight optimization not to cause useless disk access.
  177. This only applies to saving session automatically (see
  178. --save-session-interval). aria2.saveSession and serialization at
  179. the end of the session are always performed as before.
  180. When serialization, we first check that whether there is any change
  181. since the last serialization. To do this, we first calculate hash
  182. value of serialized content without writing into file. Then compare
  183. this value to the value of last serialization. If they do not
  184. match, perform serialization.
  185. * Fix (unknown length) downloads larger than 2GiB
  186. Closes #215
  187. * Fix F_PREALLOC based allocation on some OSX versions
  188. * Use index.html as filename for conditional-get when file is missing
  189. in URI
  190. Previously we disabled conditional-get if file part is missing in
  191. URI. But we use constant string "index.html" in this case, so we
  192. can do the same to determine the modification time. In this patch,
  193. if we have file part in URI, we are not going to set absolute file
  194. path in FileEntry, since it prevents content-disposition from
  195. working.
  196. * Always add README.html to dist_doc_DATA
  197. rst2html is required to produce README.html from README.rst. We
  198. include generated README.html to distribution. And rst2html is not
  199. required when compiling sources in distribution and always
  200. README.html is available.
  201. * Validate token using PBKDF2-HMAC-SHA1.
  202. This change should make token validation more resilient to:
  203. - timing attacks (constant time array compare)
  204. - brute-force/dictionary attacks (PBKDF2)
  205. Closes #220
  206. * Add --disable-websocket configure option
  207. * mingw32: Enable wintls and compile with GMP
  208. By enabling wintls, we can use Windows certificate store to validate
  209. server's certificate. Previously, we built windows build using
  210. openssl and since we don't bundle CA certificates, aria2 fails to
  211. validate server's certificate unless user setups their CA
  212. certificates. GMP provides fast big integer calculations, whic is
  213. used in BitTorrent encryption.
  214. * AppleTLS: Enable BEAST mitigations in ST
  215. Only available in 10.9+, but since we might be building on a
  216. previous version but running on 10.9+, always try to set the option.
  217. * WinTLS: Accept chains with no revocation information.
  218. This is kind what browser do anyway (IE, Firefox, Chrome tested),
  219. what AppleTLS does, what GnuTLS does and what OpenSSL
  220. does. Actually, most browsers will also be OK with the CRL/OCSP
  221. provider being offline. WinTLS will still fail in that case.
  222. Should revocation information be available in the trust chain (CRL
  223. or OCSP) the certificate still will be checked!
  224. "Real" CAs, aka. those provided by the OS or system CA bundle,
  225. usually provide revocation information and are thus still checked.
  226. It should be mostly (only?) custom (organization) CAs that lack
  227. revocation information, but those users might want to use aria2 in
  228. their intranets and VPNs anyway ;)
  229. See #217
  230. * Fix GnuTLS 2.x compatiblity
  231. Closes GH-216
  232. * AppleTLS: Use newer, non-deprecated API in 10.8+
  233. aria2 1.18.5
  234. ============
  235. Release Note
  236. ------------
  237. This release fixes BitTorrent download failure on Mingw build.
  238. Changes
  239. -------
  240. * Ignore error when setting DSCP value
  241. Setting DSCP is additional feature and failure to enable it should
  242. not abort download entirely. This change fixes the bug that windows
  243. build does not perform bittorrent downloads.
  244. aria2 1.18.4
  245. ============
  246. Release Note
  247. ------------
  248. This release adds new RPC authorization mechanism using --rpc-secret
  249. option. The existing --rpc-user and --rpc-passwd options are now
  250. deprecated, and all applications using RPC API is strongly encouraged
  251. to migrate to the new mechanism. See RPC INTERFACE section in aria2
  252. manual page for the details. The new RPC method, aria2.saveSession,
  253. was added, which tells aria2 server to save session file immediately.
  254. There are several enhancements and bug fixes. See the changes for the
  255. details.
  256. Changes
  257. -------
  258. * Added support for RPC channel encryption in aria2rpc
  259. Patch from David Macek
  260. * Add aria2.saveSession RPC method
  261. This method saves the current session to a file specified by
  262. --save-session option. This method returns "OK" if it succeeds.
  263. * Add numStoppedTotal key to aria2.getGlobalStat() RPC method response
  264. It shows the number of stopped downloads in the current session and
  265. not capped by --max-download-result option. On the other hand, the
  266. existing numStopped key also shows the number of stopped downloads,
  267. but it is capped by --max-download-result option.
  268. * Better handling of 30x HTTP status codes
  269. Reference: http://greenbytes.de/tech/tc/httpredirects/
  270. * Implement new RPC authorization using --rpc-secret option
  271. Add future deprecation warning to --rpc-user and --rpc-passwd. Warn
  272. if neither --rpc-secret nor a combination of --rpc-user/rpc-passwd
  273. is set.
  274. * Add --enable-color option to enable/disable terminal color output
  275. * Add DSCP support
  276. * gnutls: Don't fail handshake if returned error is not fatal
  277. * Add workaround GnuTLS bug with OCSP status extension and
  278. non-blocking socket
  279. GnuTLS version 3.1.3 - 3.1.18 and 3.2.0 - 3.2.8, inclusive, has this
  280. bug. For these versions, we disable OCSP status extension.
  281. * Make GnuTLS log level dependent on the aria2 ones
  282. aria2 1.18.3
  283. ============
  284. Release Note
  285. ------------
  286. This release fixes the bug which may cause assertion failure after
  287. multi-file downloads (e.g., multi-file metalink or torrent) are
  288. performed several times due to the bad handling of --bt-max-open-files
  289. option.
  290. Changes
  291. -------
  292. * Fix crash if unpause failed before assigning BtProgressInfoFile
  293. object
  294. * Enable and check PIE in makerelease-osx
  295. * Fix bug that numOpenFile_ is not reduced when MultiDiskAdaptor is
  296. deleted
  297. This bug caused assertion error in
  298. RequestGroupMan::ensureMaxOpenFileLimit
  299. aria2 1.18.2
  300. ============
  301. Release Note
  302. ------------
  303. This release fixes the wrong handling of return value of fork(), which
  304. leads to high CPU usage. The progress readout has some color output.
  305. Mingw32 build now receives colorized output. Mingw32 build now can
  306. read unicode command-line arguments. The build script of OSX was
  307. rewritten. The --bt-max-open-files now limits the number of opened
  308. file globally for multi-file downloads instead of per download basis.
  309. Changes
  310. -------
  311. * Remove the outdated, broken build_osx_release.sh
  312. * Initial revision of the a new OSX release Makefile
  313. * Allow using libgmp with AppleTLS/WinTLS
  314. * Fix crash when metaurl contains unsupported URI or text
  315. * Fix bad fork() return value handling
  316. * Use some colors in progress reports (where available)
  317. * Implement basic color support for the Windows console
  318. Only \033[*m (SGR) is supported, with a 16+16 color terminal.
  319. * AppleTLS: Implement PKCS12 loading.
  320. * Limit number of opened file globally with --bt-max-open-files option
  321. This change changes the behavior of --bt-max-open-files. Previously,
  322. it specifies the maximum number of opened files for each multi-file
  323. download. Since it is more useful to limit the number globally, the
  324. option now specifies the global limit. This change suggests that
  325. aria2.changeOption() method now ignores --bt-max-open-files and
  326. aria2.changeGlobalOption now reads it and dynamically change the
  327. limit.
  328. * Don't fail multiple concurrent dl same file if auto-file-renaming is
  329. enabled
  330. * mingw32: Use CommandLineToArgvW() and GetCommandLineW() to read
  331. cmd-line args
  332. This change enables aria2 to read unicode characters in
  333. command-line.
  334. aria2 1.18.1
  335. ============
  336. Release Note
  337. ------------
  338. This release fixes the percent-encoding bug which affects file name
  339. encodings. It adds PKCS12 support in certificate import. It also adds
  340. experimental internal implementation of message digest functions, ARC4
  341. cipher and bignum. It means that no external libraries are required to
  342. build BitTorrent support, but this feature is still marked as
  343. experimental. This release also fixes the android build with NDK r9.
  344. Changes
  345. -------
  346. * LibsslTLSContext: Remove weak cipher suite
  347. * AppleTLS: Enable --certificate
  348. * util::percentEncodeMini: Fix regression bug removed unsignedness
  349. srange-based for around std::string is convenient but several
  350. functions depend unsigned char for correctness and readability.
  351. * Log exception; throw error if loading private key and/or certificate
  352. failed
  353. * Provide internal ARC4 implementation
  354. Now you can build bittorrent support without without external
  355. libraries, meaning you can skip libnettle, libgmp, libgcrypt, GnuTLS
  356. and OpenSSL on OSX (for now).
  357. * Internal implementation of DHKeyExchange
  358. Reusing a bignum (well, unsigned very-long) implementation I had
  359. lying around for years and just cleaned up a bit and brought to
  360. C++11 land.
  361. It might not be the most performant implementation, but it shoud be
  362. fast enough for our purposes and will go a long way of removing
  363. gcrypt, nettle, gmp, openssl dependencies when using AppleTLS and
  364. WinTLS (upcoming).
  365. * PKCS12 support in --certificate and --rpc-certificate options.
  366. * Add --disable-ssl configure option
  367. * Add internal md5 and sha1 message digests
  368. * Fix AppleMessageDigestImpl use with large data
  369. * Set old cookie's creation-time to new cookie on replacement
  370. As described in http://tools.ietf.org/html/rfc6265#section-5.3
  371. * Fix link error with Android NDK r9
  372. Since Android ndk r9, __set_errno is deprecated. It is now defined
  373. as inline function in errno.h. The syscall assembly calls
  374. __set_errno, but since libc.so does not export it, the link
  375. fails. To workaround this, replace all occurrences of __set_errno
  376. with a2_set_errno and define it as normal C function.
  377. aria2 1.18.0
  378. ============
  379. Release Note
  380. ------------
  381. This release changes the default disk cache size to 16 MiB. To change
  382. the default size, --with-disk-cache configure option was added. Now
  383. used URIs are also saved by --save-session option. The control file is
  384. now always saved if --force-save is given. The ctrl-c handling on
  385. Mingw build was improved. The internal intl library is no longer
  386. supplied. From this release, C++11 compiler is required to build aria2
  387. executable. For gcc, at least 4.6.3 is required.
  388. Changes
  389. -------
  390. * Use AM subdir-objects
  391. Doing so in AM_INIT_AUTOMAKE seems to be the most compatible way of
  392. doing so.
  393. Closes GH-120
  394. * AM_SILENT_RULES([yes]) with backwards-compatiblity
  395. Supported since automake-1.11. There is no point in having the very
  396. verbose compile stuff running about, which cannot even silenced
  397. properly with `make -s` by default. Otherwise, `make V=1` or
  398. `--disable-silent-rules` are your friends
  399. * Fix automake-1.14 am_aux_dir
  400. AC_USE_SYSTEM_EXTENSIONS will cause AC_PROG_CC, which is overridden
  401. by automake-1.14, which will then init (part) of automake, in
  402. particular am_aux_dir expansion, which in turn relies on ac_aux-dir,
  403. which is not initialized at this point, and thus: certain doom (or
  404. fun, depending on your POV and mood :p)
  405. Hence call AC_USE_SYSTEM_EXTENSIONS only after
  406. AM_INIT_AUTOMAKE. This, of course, caused a lot of related macro
  407. shuffling.
  408. Tested against automake-1.10 (OSX Lion/XCode version) and
  409. automake-1.14 (homebrew version)
  410. * Require external gettext for --enable-nls
  411. And stop using the internal flavor with ./intl
  412. * Make AX_CXX_COMPILE_STDCXX_11 test for -stdlib=libc++ via std::shared_ptr
  413. The clang shipped with OSX XCode and clangs not build enabling
  414. libcpp, will default to the libstdc++ headers and lib installed on
  415. the system. In the OSX case, that libstdc++ is the one bundles with
  416. gcc-4.2, which is far too old to provide all required C++11 types,
  417. such as std::shared_ptr. Hence, the C++11 check should try to
  418. compile a program with a C++11 type and try -stdlib=libc++ if the
  419. default lib fails to compile said program.
  420. * Make the configure check for C++11 compiler mandatory
  421. Remove stray "dnl", so that mandatory actually works with (my)
  422. autoreconf.
  423. * Always build doc/manual-src
  424. Should sphinx-build be not available AND the man file not be prsent,
  425. then just "touch" it into existence (and warn about that)
  426. * Win: Use SetConsoleCtrlHandler for SIGINT/SIGTERM
  427. * Implement a simple resource lock (threading)
  428. In this initial implementation Locks are no-ops on platforms other
  429. than Windows.
  430. * Check for sphinx-build during configure
  431. * Add --with-disk-cache configure option
  432. Enables packagers more fine grained control over the default value
  433. without having to mess with config files.
  434. See GH-115
  435. * Change defaults: Enable 16M disk cache by default.
  436. * Always save control file if --force-save is given
  437. * Set log level DEBUG for unittests
  438. * Check that C++ compiler supports override keyword
  439. If the compiler supports override, define CXX11_OVERRIDE as
  440. override, otherwise define it as empty. Use CXX11_OVERRIDE instead
  441. of override.
  442. * AppleTLS: Fix MessageDigestImpl
  443. * AppleTLS: Fix session CFRelease stuff
  444. * Use AX_CXX_COMPILE_STDCXX_11 macro to detect C++0x/C++11 support in
  445. compiler
  446. * Require -std=c++11 and use std::shared_ptr instead of SharedHandle
  447. * Join URI on redirect
  448. * Send HAVE message to the peer which the piece is downloaded from
  449. Historically, aria2 did not send HAVE message to the peer which the
  450. piece is coming from, thinking it is obvious that the peer knows we
  451. have the piece. But it is not obvious if one piece is download from
  452. more than 1 peers (e.g., end game mode). So it is better to send
  453. HAVE to all peers connected.
  454. * Improvements to --follow-torrent=false documentation.
  455. Patch from gt
  456. * SessionSerializer: Truly unique URIs
  457. Before, only spent uris where sanitized not to be contained within
  458. remaining uris. Change this so that each uri in the
  459. union(remaining,spent) get saved once at most. The order of the
  460. uris will won't be changed, with remaining uris going first followed
  461. by spent uris.
  462. Also avoid copying the uri std::strings around during dupe checking,
  463. usually resulting in better performance regarding CPU and space.
  464. * Make getOption RPC method return option for stopped downloads
  465. * SessionSerializer: Save spent URIs as well as remaining ones