@@ -4,168 +4,119 @@ Netatalk Changelog
44Announcing Netatalk 4.6.0, Netatalk Client 1.0, and the new netatalk.io
55-----------------------------------------------------------------------
66
7- Today the Netatalk Project announces its largest coordinated release ever:
8- ** Netatalk 4.6.0** , the fastest, safest, and most capable AFP file server we
9- have ever shipped; ** Netatalk Client 1.0** , the first production release of
10- the new official Netatalk client; and the all-new ** netatalk.io** website,
11- rebuilt as the home for the whole Netatalk family.
12-
13- When Apple announced the withdrawal of AFP support in macOS Golden Gate, it
14- marked the end of an era — but not of the protocol, and certainly not of the
15- community around it. Millions of Macs, decades of archives, studios, labs,
16- and retro-computing setups still speak AFP every day. The Netatalk Project's
17- answer to Apple's retreat is to advance: over the past release cycle the
18- entire stack has been modernised, hardened, and dramatically accelerated, and
19- for the first time Netatalk provides both sides of the connection — server
20- and client — so AFP remains a first-class citizen on every platform, whatever
21- Apple ships next.
22-
23- ### One suite, three releases
24-
25- - ** Netatalk 4.6.0** — the AFP file server, with a rebuilt caching core,
26- an overhauled locking subsystem, true multi-protocol coexistence, feature
27- complete Spotlight search, modern SQL database backends, and deep
28- correctness and security hardening throughout.
29- - ** Netatalk Client 1.0** — the official AFP client: a FUSE filesystem
30- driver, an interactive command-line client, and reusable client libraries,
31- graduating from a year of alpha and beta releases to full production status.
32- - ** netatalk.io** — a brand-new statically generated website carrying the
33- manual, wiki, release notes, security advisories, and developer
34- documentation for the entire suite in one place.
7+ Today we're releasing ** Netatalk 4.6.0** , the fastest and most capable AFP
8+ server we've ever shipped; ** Netatalk Client 1.0** , our client's first
9+ production release; and a rebuilt ** netatalk.io** , the new home for both.
10+
11+ Apple is withdrawing AFP support in macOS Golden Gate. That ends an era,
12+ but not the protocol: millions of Macs, decades of archives, studios,
13+ labs, and retro-computing setups speak AFP every day. Our answer is to
14+ advance. This cycle modernised, hardened, and accelerated the whole stack,
15+ and for the first time Netatalk provides both sides of the connection —
16+ server and client — so AFP keeps working on every platform, whatever Apple
17+ ships next.
3518
3619### A file server rebuilt for speed
3720
38- Performance work touched every layer of the server, and the gains compound:
39-
40- - The network transport now negotiates transfer sizes exactly as the AFP
41- specification intends and aligns every frame to the network path and disk, so bulk
42- reads and writes stream at full quantum with no wasted partial packets, buffers or operations anywhere in the stack.
43- - The directory cache — the heart of a file server's responsiveness — now uses an adaptive replacement policy
44- (ARC) by default for 10–50% better hit ratios, and caches state, metadata and resource-fork
45- data so Finder browsing of classic Mac content no longer touches the disk when cached.
46- - Hot paths were profiled syscall-by-syscall: redundant lookups, duplicate
47- metadata probes, and repeated path walks were eliminated across
48- enumeration, file copying, and metadata queries.
49- - Background cache maintenance moved to a non-blocking lock-free handshake, removing
50- latency spikes on busy and single-core systems alike.
51-
52- We benchmarked the last 5 releases using the project's 'lantest' performance measurement tooling —
53- each release in its out-of-the-box configuration — ** Netatalk 4.6.0
54- completes the full test set ~ 55% faster than 4.4.1 and ~ 45% faster than
55- 4.5.1. And is 200–300% faster on the operations used most** : creating,
56- deleting, copying, and browsing folders (2.9× faster bulk
57- deletes, 2.7× faster directory enumeration, 2.3× faster file creation and
58- server-side copies).
59-
60- Netatalk-only deployments get all of this out of the box: a stock
61- configuration is now tuned for the common case, with every knob still
62- available for specialists.
63-
64- ### Strictly coherent caching and a locking overhaul
65-
66- Speed means nothing without correctness, so the caching layers were made
67- strictly coherent: every cache entry is validated, cross-process changes
68- propagate immediately, and long-standing structural defects in the directory
69- cache — some dating back twenty years — were found by a purpose-built attack
70- test suite and fixed. The lock handling subsystem was completely overhauled
71- in the same spirit, normalising Netatalk's file locking and delete semantics
72- to match what POSIX, macOS, and Samba users expect. Files viewed over AFP no
73- longer wedge as "in use"; open forks behave like opens everywhere else; and
74- byte-range locks are taken exactly where other filesystems take them.
75-
76- ### True multi-protocol: Netatalk alongside Samba
77-
78- The coherency and locking work unblocked the headline feature: ** Netatalk
79- now works correctly alongside other protocols on the same shared volumes.**
80- Where sharing a volume between AFP and SMB previously required several
81- coordinated — and easily mis-set — options, there is now a single switch:
82- declare a volume multi-protocol and every coherency and locking default
83- snaps to the safe value; leave it off and a Netatalk-only server keeps the
84- fast path. Option names were aligned with Samba's for the same behaviours,
85- configuration parsing became strict and fail-closed, and an end-to-end
86- Samba interoperability test — a kernel CIFS mount and a Netatalk Client
87- mount exercising one shared volume in both directions — guards it all in
88- continuous integration.
89-
90- ### Spotlight search: feature complete
91-
92- Finder search over AFP is now feature complete, intuitive, and enabled by
93- default. Multi-word searches match every word, quoted phrases match exactly,
94- searching within a folder searches only that folder, and result limits are
95- honoured consistently — all served at high performance directly from the
96- CNID database with no external indexer required, on every platform Netatalk
97- supports. Pluggable backends remain available for full-text indexing where
98- deeper search is wanted.
21+ The network transport now negotiates transfer sizes as the AFP
22+ specification intends and aligns every frame to the network path and disk,
23+ so bulk transfers stream at full quantum with no wasted packets or
24+ buffers. The directory cache defaults to adaptive replacement (ARC) for
25+ 10–50% better hit ratios and now caches state, metadata, and resource-fork
26+ data, so browsing classic Mac content doesn't touch the disk once cached.
27+ Hot paths were profiled syscall by syscall to strip redundant lookups and
28+ path walks, and background cache maintenance is now lock-free, ending
29+ latency spikes on busy and single-core systems.
30+
31+ The numbers: benchmarked with the project's lantest tooling, each release
32+ in its stock configuration, ** 4.6.0 completes the full test set ~ 55%
33+ faster than 4.4.1 and ~ 45% faster than 4.5.1, and is 200–300% faster on
34+ the operations used most** — 2.9× on bulk deletes, 2.7× on directory
35+ enumeration, 2.3× on file creation and server-side copies. All of it is on
36+ by default; every knob remains for specialists.
37+
38+ ### Strictly coherent caching, correct locking
39+
40+ The caching layers are now strictly coherent: every entry is validated,
41+ cross-process changes propagate immediately, and structural defects in the
42+ directory cache — some twenty years old — were found by a purpose-built
43+ attack test suite and fixed. Locking and delete semantics now match POSIX,
44+ macOS, and Samba: files viewed over AFP no longer wedge as "in use", open
45+ forks behave like opens everywhere else, and byte-range locks land where
46+ other filesystems put them.
47+
48+ ### Netatalk alongside Samba
49+
50+ That work unblocked the headline feature: ** Netatalk now shares volumes
51+ correctly with other protocols.** What used to take several coordinated,
52+ easily mis-set options is now one switch — declare a volume multi-protocol
53+ and every coherency and locking default snaps to the safe value; leave it
54+ off and a Netatalk-only server keeps the fast path. Option names match
55+ Samba's, configuration parsing fails closed, and an end-to-end
56+ interoperability test — a kernel CIFS mount and a Netatalk Client mount on
57+ one shared volume — guards it in CI.
58+
59+ ### Spotlight search, feature complete
60+
61+ Finder search over AFP now just works: multi-word searches match every
62+ word, quoted phrases match exactly, folder-scoped searches stay in the
63+ folder, and result limits are honoured — served straight from the CNID
64+ database with no external indexer, on every supported platform. Pluggable
65+ backends remain for full-text indexing.
9966
10067### Modern database backends
10168
102- Netatalk's catalog database has completed its move to modern SQL engines.
103- ** SQLite is now the default backend** — zero-configuration, in-process, and
104- robust — with ** MySQL/MariaDB as the first-class choice for large or
105- multi-server deployments** . Both backends gained a real error contract:
106- contention, disk-full, and corruption are now distinguished and handled
107- gracefully instead of ending user sessions, and even 32-bit ID exhaustion
108- recovers cleanly. The legacy Berkeley DB (* dbd* ) scheme is deprecated and
109- will be removed in a future release.
69+ ** SQLite is now the default catalog backend** — zero-configuration and
70+ in-process — with ** MySQL/MariaDB for large or multi-server deployments** .
71+ Both now distinguish contention, disk-full, and corruption instead of
72+ ending user sessions, and even 32-bit ID exhaustion recovers cleanly. The
73+ legacy Berkeley DB (* dbd* ) scheme is deprecated and will be removed.
11074
11175### Security and resilience
11276
113- The release cycle closed out more than twenty CVEs, hardened every
114- authentication method (DHX, DHX2, SRP), tightened wire-format parsing
115- throughout, introduced a new unprivileged single-user operating mode, and
116- adopted stronger vulnerability reporting and analysis practices. Even the
117- classic AppleTalk transport received its modernisation — and its first-ever
118- unit tests. Behind the scenes, a continuous performance dashboard, a
119- shaped-network test harness, thread-sanitised protocol test suites, and
120- JUnit-reported specification tests now gate every change, so the gains in
121- this release are locked in for the next one.
77+ This cycle closed more than twenty CVEs, hardened every authentication
78+ method (DHX, DHX2, SRP), tightened wire-format parsing throughout, and
79+ added an unprivileged single-user mode. Even the classic AppleTalk
80+ transport was modernised — and gained its first unit tests. Every change
81+ is now gated by a continuous performance dashboard, a shaped-network test
82+ harness, thread-sanitised protocol suites, and JUnit-reported
83+ specification tests.
12284
12385### Netatalk Client 1.0: the other half of the connection
12486
125- With Apple's client going away, the community needed more than a server —
126- and after a year of intensive development spanning hundreds of merged
127- changes, the ** Netatalk Client** makes its first production release as the
128- official client of the Netatalk Project. What began as an experimental
129- codebase has been transformed:
87+ After a year and hundreds of merged changes, the ** Netatalk Client**
88+ graduates from beta to the project's official client:
13089
131- - ** Mount AFP volumes as a native filesystem** via a multi-threaded FUSE
132- driver, with multiple simultaneous mounts, suspend/resume and idle
90+ - ** Mount AFP volumes as a native filesystem** : a multi-threaded FUSE
91+ driver with multiple simultaneous mounts, suspend/resume and idle
13392 reconnection, and full extended-attribute and resource-fork fidelity.
134- - ** A complete interactive command-line client** (` afpcmd ` ) with recursive
135- transfers, tab completion, pagination, and session recovery, plus
136- discovery and status tools under one unified ` afpc ` command namespace.
137- - ** The full modern authentication suite** — DHX, DHX2, and SRP with
138- password changing throughout — hardened with server signature
139- verification and authenticated session binding.
140- - ** Compatibility across the entire AFP timeline** , from AFP 2.x era
141- servers, through Mac OS X personal file sharing and Time Capsules, to
142- Netatalk 4 and AFP 3.4, with Zeroconf discovery, full UTF-8 and classic
143- Mac code page handling.
144- - ** Reusable client libraries** (` libafpclient ` and the stateless
145- ` libafpsl ` ) with a defined public API and stable soversion, ready for
146- third-party integrations.
147- - ** Production engineering** to match the server: continuous integration on
148- Linux, FreeBSD, NetBSD, OpenBSD, macOS, and illumos/Solaris, containerised
149- integration tests, static analysis, and a warnings-as-errors build.
150-
151- Together, server and client mean AFP no longer depends on any vendor: a
152- Linux box can serve, a BSD box can mount, and a fleet of Macs old and new
153- sits happily in between.
93+ - ** A complete command-line client** (` afpcmd ` ) with recursive transfers,
94+ pagination, and session recovery, plus discovery and status tools under
95+ one ` afpc ` namespace.
96+ - ** The full authentication suite** — DHX, DHX2, SRP, password changing —
97+ with server signature verification and authenticated session binding.
98+ - ** Compatibility across the whole AFP timeline** : AFP 2.x servers, Mac
99+ OS X file sharing, Time Capsules, Netatalk 4, AFP 3.4 — with Zeroconf
100+ discovery, full UTF-8, and classic Mac code pages.
101+ - ** Reusable libraries** (` libafpclient ` , the stateless ` libafpsl ` ) with a
102+ stable public API and soversion.
103+ - ** CI on six platforms** — Linux, FreeBSD, NetBSD, OpenBSD, macOS,
104+ illumos/Solaris — with containerised integration tests and a
105+ warnings-as-errors build.
106+
107+ A Linux box can serve, a BSD box can mount, and Macs old and new sit in
108+ between. AFP no longer depends on any vendor.
154109
155110### The new netatalk.io
156111
157- The suite launches alongside a completely new project website. Rebuilt as a
158- fast, statically generated site, netatalk.io brings the manual, the wiki,
159- historical and current release notes, security advisories, and generated
160- source documentation together — always in sync with the code, because it is
161- built from the same repositories it documents.
112+ The manual, wiki, release notes, security advisories, and source
113+ documentation now live on one fast, statically generated site — built from
114+ the same repositories it documents, so it can't drift out of sync.
162115
163116### Thank you
164117
165- This release is the work of a worldwide community of contributors, testers,
166- packagers, and users who refused to let a great protocol fade away. AFP's
167- future is now firmly in the community's hands — and it has never looked
168- better. Get Netatalk 4.6.0 and Netatalk Client 1.0 at
118+ This release is the work of a worldwide community that refused to let a
119+ great protocol fade away. Get Netatalk 4.6.0 and Netatalk Client 1.0 at
169120[ netatalk.io] ( https://netatalk.io ) .
170121
171122Changes in 4.6.0
0 commit comments