 |
What's new: v0.1.7 - Chat history
|
 |
 |
Released 2026-04-17
|
 |
 |
 |
Lemoniscate v0.1.7 Release Notes
Persistent chat history. Your server now remembers what was said while clients were offline, and modern clients can page back through it. Storage is JSONL-based with no database dependency -- it works on Tiger PPC the same as modern macOS and Linux.
As writing this the only server that has chat history is Apple Media Archive as it's the only hotline server I run but hopefully you'll be the next!
This pairs well with the HOPE AEAD encryption from 0.1.6: if you have an encryption key configured, message bodies are encrypted at rest using ChaCha20-Poly1305 while metadata stays plaintext so the index and startup scan still work.
Chat History
- Server-side chat persistence using append-only JSONL files under
<FileRoot>/ChatHistory/. One file per channel (channel-0.jsonl for public chat, channel-N.jsonl for private chat rooms). No database, no external dependencies.
- Cursor-based pagination via
TranGetChatHistory (transaction 700). Clients query with before/after cursors and a limit parameter. The server returns matching entries plus a has_more flag for paging. Queries are O(log n) via an in-memory binary-search index built at startup.
- Capability negotiation at login. The server advertises
HL_CAPABILITY_CHAT_HISTORY (bit 4) so clients know history is available. Navigator v0.2.5+ renders the backlog automatically.
- Legacy client replay. When
ChatHistoryLegacyBroadcast is enabled, the server replays the last N messages (default 30) as regular chat broadcasts on login. Clients without history support still see what they missed -- it just shows up as normal chat lines when they connect.
- Optional at-rest encryption. Point
ChatHistory.EncryptionKey at a 32-byte key file and message bodies are sealed with ChaCha20-Poly1305 before being written to disk. The nonce, ciphertext, and tag are base64-encoded inline. Metadata (timestamp, nick, flags, icon) stays plaintext so startup scanning, pruning, and grep still work.
- Crash-safe storage. On startup, each channel file is scanned line-by-line. If the last line is truncated (power loss, SIGKILL mid-write), the trailing garbage is removed with
ftruncate() and the index is rebuilt cleanly.
- Configurable retention. Set
ChatHistoryMaxMessages (default 10,000) and/or ChatHistoryMaxDays (0 = unlimited) to control how much history is kept. Pruning runs at startup and periodically.
- Per-connection rate limiting on history queries using a token-bucket algorithm. Default: 20-token capacity refilling at 10/sec. Prevents a client from hammering the history endpoint.
- Sign-on / sign-off logging. When
ChatHistoryLogJoins is enabled (default off), user connections and disconnections are recorded as system messages in the history stream. Renderers display these as system events, not chat lines.
- Per-channel support. Public chat and private chat rooms each get their own history file and index. Private chats (those with a
FieldChatID) are persisted separately.
- Permission gating.
ACCESS_READ_CHAT_HISTORY (bit 56) controls who can query history, falling back to ACCESS_READ_CHAT (bit 9) when unset.
- Periodic fsync. The server flushes chat history to disk every 60 seconds via the existing idle-check timer, balancing durability against write overhead.
GUI
- New Chat History disclosure section in Settings with controls for:
- Enable/disable
- Max messages and max days retention
- Legacy broadcast replay (on/off + message count)
- Log joins/parts
- All settings persist to both plist (GUI) and YAML (CLI) config formats.
Config
New YAML keys under the ChatHistory mapping:
ChatHistory:
Enabled: true
MaxMessages: 10000
MaxDays: 0
LegacyBroadcast: false
LegacyCount: 30
EncryptionKey: ""
RateCapacity: 20
RateRefillPerSec: 10
LogJoins: false
Equivalent plist keys: ChatHistoryEnabled, ChatHistoryMaxMessages, ChatHistoryMaxDays, ChatHistoryLegacyBroadcast, ChatHistoryLegacyCount, ChatHistoryRateCapacity, ChatHistoryRateRefillPerSec, ChatHistoryLogJoins.
Build
chat_history.c and chat_history.h added to the source tree.
test/test_chat_history.c with 11 tests covering pagination, crash recovery, tombstone semantics, pruning, encryption round-trip, and rate-limiter math.
- Handler table size bumped to 1024 to accommodate transaction code 700.
- Makefile dependency tracking improved with
-MMD -MP on the modern branch (PPC branch uses manual rebuilds).
Known Issues
- Chat history is not replicated or synced between servers. It's local to the machine running Lemoniscate.
- The at-rest encryption key must be managed manually (generated, backed up, and referenced in config). There is no key rotation mechanism.
- Legacy broadcast replay sends messages as regular chat, so there's no visual distinction between replayed history and live chat on older clients.
Downloads
|
 |
 |
 |
( Release page )
|
 |
 |
 |
News about Lemoniscate
|
 |
 |
1 post
|
 |
 |
 |
|
 |
 |
 |
( All news )
|
 |
 |
 |
v0.1.3 - Bugfixes
|
 |
 |
Released 2026-03-22
|
 |
 |
 |
A new PowerPC app arrives!
Lemoniscate is based off of MorbiusAdmin (A GUI wrapper for Morbius) but isn't a port or fork as it's entirely a rewrite top-to-bottom in C and Obj-C for the GUI. This means it's tiny, right now only about 560 kB decompressed. It uses generally under 25 MB of ram in limited testing. Roughly 100k is the icon.
It's a (almost) fully functioning Hotline Server for OS X 10.4 and OS X 10.5 and I'm sure the C source code will be useful for anyone looking for C ports of Hotline.
Sans TLS, this has full 1.9 protocol coverage!
A New x86 app arrives!
Also I'm now including an experimental 10.11-Current macOS build.... Ironically the icon file is about 5x larger than the app itself.
v0.1.3 changes
- Fix path traversal in folder uploads, register missing handlers
Current features
Chat & Messaging
- Public chat room with all connected users
- Private chat rooms — create, invite users, set topics
- Instant messages (private messages between users)
- Auto-reply when a user is away or idle
- /me action messages
- Admin broadcast messages to all users
User Management
- User accounts with login and password (salted SHA-1 hashed)
- Guest access (no login required)
- 41 individual permission bits per account
- Admin account editor — create, modify, rename, and delete accounts
- Batch account editing (v1.5+ multi-user editor)
- Kick/disconnect users (with optional message)
- Protected accounts that can't be disconnected
File Sharing
- Browse server files and folders
- Download files with progress tracking
- Upload files to the server
- Download entire folders (recursive)
- Upload entire folders (recursive)
- Resume interrupted downloads
- File info — type, creator, size, dates, comments
- Rename, move, and delete files and folders
- Create new folders
- Create file aliases (symlinks)
- 70+ file type mappings for correct Mac type/creator codes
News & Message Board
- Flat message board (classic Hotline "News")
- Threaded news with categories and articles
- Create and delete news categories
- Post, read, and delete articles with threading
- News data persists across server restarts
Server Administration
- GUI admin application (Cocoa, native Tiger look)
- Setup wizard for first-time configuration
- macOS plist configuration (native format)
- YAML fallback for compatibility
- Server agreement displayed on login
- Server banner image
- Default banner bundled with the app
- Start, stop, and restart from the GUI
- Live server logs in the admin interface
- Log file saved to Application Support
Networking
- Hotline protocol on port 5500 (configurable)
- File transfers on port 5501
- Bonjour/mDNS for local network discovery
- Tracker registration (UDP, periodic with live user count)
- Idle/away detection (5 minutes, auto-broadcasts status)
- Per-IP rate limiting
- Ban list (IP addresses and usernames)
Access Control
Granular per-account permissions including:
- Download, upload, delete, rename, and move files
- Create folders and file aliases
- Read and send chat
- Create and manage private chat rooms
- Read, post, and delete news articles
- Create and delete news categories
- View and modify user accounts
- Disconnect other users
- Send broadcast messages
- Upload location restrictions (Uploads/Drop Box only)
- Drop box folder visibility control
Compatibility
- Runs on Mac OS X 10.4 Tiger (PowerPC)
- Works with Hotline Navigator, the mierau Swift client, and classic Hotline clients
- FILP file transfer format with INFO and DATA forks
- Hotline 1.8+ protocol (version 190)
- CLI server binary for headless operation
- Mobius-compatible account and news file formats
The more interesting stuff
Planned features
- Right clicking of connected users to ban/kick
- Live reloading of Board / Threaded News on post
Possible Features
- End-to-end encryption
- TLS?
Known Bugs
- Status of downloads doesn't show live updates
Downloads
|
 |
 |
 |
( Release page )
|
 |
 |
 |
v0.1.2 - Actually getting good
|
 |
 |
Released 2026-03-21
|
 |
 |
 |
A new PowerPC app arrives!
Lemoniscate is based off of MorbiusAdmin (A GUI wrapper for Morbius) but isn't a port or fork as it's entirely a rewrite top-to-bottom in C and Obj-C for the GUI. This means it's tiny, right now only about 560 kB decompressed. It uses generally under 25 MB of ram in limited testing. Roughly 100k is the icon.
It's a (almost) fully functioning Hotline Server for OS X 10.4 and OS X 10.5 and I'm sure the C source code will be useful for anyone looking for C ports of Hotline.
A New x86 app arrives!
Also I'm now including an experimental 10.11-Current macOS build.... Ironically the icon file is larger than the app itself. See v0.1.1 for the that
v0.1.2 changes
- Fixed Double menus in drop for Lemoniscate
- Fixed Scroll bars appear even when one item or zero items on several panes
- Fixed Icon is blank when tabbing
- Made the about much less horrible
- old.hotlinenavigator.com now is the homepage as it is compatible
Current features
Chat & Messaging
- Public chat room with all connected users
- Private chat rooms — create, invite users, set topics
- Instant messages (private messages between users)
- Auto-reply when a user is away or idle
- /me action messages
- Admin broadcast messages to all users
User Management
- User accounts with login and password (salted SHA-1 hashed)
- Guest access (no login required)
- 41 individual permission bits per account
- Admin account editor — create, modify, rename, and delete accounts
- Batch account editing (v1.5+ multi-user editor)
- Kick/disconnect users (with optional message)
- Protected accounts that can't be disconnected
File Sharing
- Browse server files and folders
- Download files with progress tracking
- Upload files to the server
- Download entire folders (recursive)
- Upload entire folders (recursive)
- Resume interrupted downloads
- File info — type, creator, size, dates, comments
- Rename, move, and delete files and folders
- Create new folders
- Create file aliases (symlinks)
- 70+ file type mappings for correct Mac type/creator codes
News & Message Board
- Flat message board (classic Hotline "News")
- Threaded news with categories and articles
- Create and delete news categories
- Post, read, and delete articles with threading
- News data persists across server restarts
Server Administration
- GUI admin application (Cocoa, native Tiger look)
- Setup wizard for first-time configuration
- macOS plist configuration (native format)
- YAML fallback for compatibility
- Server agreement displayed on login
- Server banner image
- Default banner bundled with the app
- Start, stop, and restart from the GUI
- Live server logs in the admin interface
- Log file saved to Application Support
Networking
- Hotline protocol on port 5500 (configurable)
- File transfers on port 5501
- Bonjour/mDNS for local network discovery
- Tracker registration (UDP, periodic with live user count)
- Idle/away detection (5 minutes, auto-broadcasts status)
- Per-IP rate limiting
- Ban list (IP addresses and usernames)
Access Control
Granular per-account permissions including:
- Download, upload, delete, rename, and move files
- Create folders and file aliases
- Read and send chat
- Create and manage private chat rooms
- Read, post, and delete news articles
- Create and delete news categories
- View and modify user accounts
- Disconnect other users
- Send broadcast messages
- Upload location restrictions (Uploads/Drop Box only)
- Drop box folder visibility control
Compatibility
- Runs on Mac OS X 10.4 Tiger (PowerPC)
- Works with Hotline Navigator, the mierau Swift client, and classic Hotline clients
- FILP file transfer format with INFO and DATA forks
- Hotline 1.8+ protocol (version 190)
- CLI server binary for headless operation
- Mobius-compatible account and news file formats
The more interesting stuff
Planned features
- Right clicking of connected users to ban/kick
- Live reloading of Board / Threaded News on post
- Checking the size of banners to make sure they are compatible
Possible Features
- End-to-end encryption
- TLS?
Known Bugs
- Status of downloads doesn't show live updates
Downloads
|
 |
 |
 |
( Release page )
|
 |
 |
 |
v0.1.1 - Minor improvements
|
 |
 |
Released 2026-03-20
|
 |
 |
 |
A new PowerPC app arrives!
Lemoniscate is based off of MorbiusAdmin (A GUI wrapper for Morbius) but isn't a port or fork as it's entirely a rewrite top-to-bottom in C and Obj-C for the GUI. This means it's tiny, right now only about 440k decompressed. It uses generally under 25 MB of ram in limited testing.
It's a (almost) fully functioning Hotline Server for OS X 10.4 and OS X 10.5 and I'm sure the C source code will be useful for anyone looking for C ports of Hotline.
A New x86 app arrives!
Also I'm now including an experimental 10.11-Current macOS build.... Ironically the icon file is larger than the app itself.
v0.1.1 changes
Tiger compatibility may have not worked since I was building on 10.5. This version has fallbacks for Tiger. Trackers now register and should work!
Current features
Chat & Messaging
- Public chat room with all connected users
- Private chat rooms — create, invite users, set topics
- Instant messages (private messages between users)
- Auto-reply when a user is away or idle
- /me action messages
- Admin broadcast messages to all users
User Management
- User accounts with login and password (salted SHA-1 hashed)
- Guest access (no login required)
- 41 individual permission bits per account
- Admin account editor — create, modify, rename, and delete accounts
- Batch account editing (v1.5+ multi-user editor)
- Kick/disconnect users (with optional message)
- Protected accounts that can't be disconnected
File Sharing
- Browse server files and folders
- Download files with progress tracking
- Upload files to the server
- Download entire folders (recursive)
- Upload entire folders (recursive)
- Resume interrupted downloads
- File info — type, creator, size, dates, comments
- Rename, move, and delete files and folders
- Create new folders
- Create file aliases (symlinks)
- 70+ file type mappings for correct Mac type/creator codes
News & Message Board
- Flat message board (classic Hotline "News")
- Threaded news with categories and articles
- Create and delete news categories
- Post, read, and delete articles with threading
- News data persists across server restarts
Server Administration
- GUI admin application (Cocoa, native Tiger look)
- Setup wizard for first-time configuration
- macOS plist configuration (native format)
- YAML fallback for compatibility
- Server agreement displayed on login
- Server banner image
- Default banner bundled with the app
- Start, stop, and restart from the GUI
- Live server logs in the admin interface
- Log file saved to Application Support
Networking
- Hotline protocol on port 5500 (configurable)
- File transfers on port 5501
- Bonjour/mDNS for local network discovery
- Tracker registration (UDP, periodic with live user count)
- Idle/away detection (5 minutes, auto-broadcasts status)
- Per-IP rate limiting
- Ban list (IP addresses and usernames)
Access Control
Granular per-account permissions including:
- Download, upload, delete, rename, and move files
- Create folders and file aliases
- Read and send chat
- Create and manage private chat rooms
- Read, post, and delete news articles
- Create and delete news categories
- View and modify user accounts
- Disconnect other users
- Send broadcast messages
- Upload location restrictions (Uploads/Drop Box only)
- Drop box folder visibility control
Compatibility
- Runs on Mac OS X 10.4 Tiger (PowerPC)
- Works with Hotline Navigator, the mierau Swift client, and classic Hotline clients
- FILP file transfer format with INFO and DATA forks
- Hotline 1.8+ protocol (version 190)
- CLI server binary for headless operation
- Mobius-compatible account and news file formats
The more interesting stuff
Planned features
- Right clicking of connected users to ban/kick
- Live reloading of Board / Threaded News on post
- Checking the size of banners to make sure they are compatible
Possible Features
- End-to-end encryption
- TLS?
Known Bugs
- Double menus in drop for Lemoniscate
- Scroll bars appear even when one item or zero items on several panes
- Icon is blank when tabbing
- About dialog is pretty bad
- Status of downloads doesn't show live updates
Downloads
|
 |
 |
 |
( Release page )
|
 |
 |
|  |
 |
Links
|
 |
 |
Clients
|
 |
 |
Servers
|
 |
 |
Trackers
|
 |
 |
Bots
|
 |
 |
Misc
|
 |
|