agalwood/Motrix
61.9
Adequate · 25 September 2026
206.3k
lines of production code
TypeScript
with JavaScript, Rust
4
measurements over time
What this system is
Motrix Turbo v2 is a cross-platform download manager built on Electron and the aria2 engine, supporting HTTP, BitTorrent, and SFTP protocols. It features a plugin system with a visualization interface, a browser extension bridge for native messaging, and robust file finalization via a Rust sidecar. The application provides comprehensive packaging for Windows, macOS, Linux (AppImage, Flatpak, Snap, Arch), and web environments, ensuring secure and stable download management across diverse operating systems.
Features
Add Flatpak packaging support for Motrix
Introduces the complete Flatpak manifest and metadata for the Motrix download manager, enabling distribution via Flathub. The package bundles the application with Electron 44 and a custom-built aria2 engine (v1.37.0-motrix.16) compiled with support for BitTorrent, SFTP, and WebSocket RPC. It includes necessary build dependencies like c-ares and libssh2, and configures sandbox permissions for Wayland, X11, and DRI access.
flatpak · high confidence
Add Snap packaging configuration for Motrix
Introduced the Snap build infrastructure for Motrix, including a \snapcraft.yaml.in\ template and a desktop entry file. This enables the application to be packaged and distributed as a Snap, with support for strict confinement, GNOME extensions, and native messaging host integration for browser bridges.
build/snap · high confidence
Added aria2 configuration template and tray icon asset
The application now includes a base configuration template for aria2 (extra/aria2.conf) which is copied to the user's config directory on first launch, setting defaults for file allocation, HTTP reliability, BitTorrent peer behavior (including seeding detachment and Transmission-like identity), and logging. Additionally, a new SVG tray icon (extra/tray/tray.svg) has been added to the project assets.
extra · high confidence
AppImage browser integration now supports cold launch
The AppImage distribution now supports cold launching the browser bridge. A new \AppImageNativeHost\ component manages the installation and lifecycle of the native messaging host, ensuring stable copies are preserved across refreshes and that consent is explicitly required. The bridge manager has been updated to handle startup failures gracefully, preserving the installation state even if the listener is unavailable, and the bootstrap process now correctly resolves the native host binary path for the AppImage environment.
src/main · high confidence
Engine diagnostics dialog with safe report export
Users can now open an Engine Diagnostics dialog that displays the engine's state, binary version, RPC status, and recovery recommendations, with options to force-terminate or retry the engine. The dialog includes a diagnostic report feature that exports a JSON snapshot of the engine's health; this export automatically redacts sensitive information such as passwords, tokens, and home directory paths to prevent accidental data leakage when sharing reports.
src/renderer/features/engine-diagnostics · high confidence
Initial project scaffolding and documentation for Motrix Turbo v2
The repository has been initialized with the foundational structure for the new Motrix Turbo v2 release, including a Dockerfile for the headless server, standard project governance files (LICENSE, Code of Conduct, Security Policy, Contributing Guide), and comprehensive bilingual (English and Simplified Chinese) documentation. This change establishes the baseline architecture, development workflows, and legal notices required for the v2 codebase, which is now the primary development branch.
(repo-wide) · high confidence
Introduce finalize-fs sidecar for safe, cross-platform file publication
A new Rust-based sidecar service (\packages/finalize-fs\) is added to handle the finalization of downloaded artifacts. It provides identity-checked file publication and removal, ensuring that renames never overwrite existing destinations and that reparse points or unsafe path components are rejected on Windows. The service implements robust filename sanitization (following Chromium's rules) to ensure compatibility across NTFS, exFAT, and macOS volumes. It includes specific hardening for Linux NFS and NTFS-3G mounts, using hard-link publication intents when native renames fail, and supports SMB shares on Windows with retry logic for transient sharing conflicts. The sidecar also features a durable journal for recovery from crashes or failed operations, ensuring data integrity during cleanup and publication.
packages/finalize-fs · high confidence
Introduce structured task error resolution and parameter parsing
This change introduces a new error handling module in src/shared/task-error that standardizes how download task failures are diagnosed and presented. The new \resolveFailureDescriptor\ function creates a prioritized list of user-facing error reasons, preferring specific detail keys over generic error codes, while also extracting hint keys and technical details for debugging. Additionally, a new \parseDetailParams\ utility safely parses JSON error parameters, degrading to null on malformed input to prevent crashes, and a \taskErrorFieldsEqual\ function ensures consistent comparison of error state for storage operations.
src/shared/task-error · high confidence
Introduces Flatpak Native Messaging companion and plugin system visualization libraries
This change adds the \packages/native-host\ directory, which contains the build and packaging scripts for the \motrix-flatpak-native-host\ companion binary used to bridge browser extensions with the Motrix Flatpak sandbox, along with its installation documentation. It also introduces new utility libraries in \src/renderer/routes/plugins/lib\ to support the plugin system: \audience.ts\ provides logic for mapping plugin permissions to user-facing security tones and summaries, while \call-graph-model.ts\ and \call-graph-layout.ts\ implement the data processing and ELK-based graph layout algorithms required to visualize plugin dependency and call graphs.
packages/native-host, src, src/renderer/routes/plugins/lib · high confidence
Introduces a new application menu with task management and confirmation flows
Adds a new application menu feature for the renderer, including a responsive CSS layout, a web-specific menu button component, and a desktop action handler. The menu allows users to execute task commands (pause, resume, delete, move) and global actions (pause/resume all, clear stopped tasks) with proper intent validation and selection tracking. It includes a confirmation dialog for destructive actions like clearing stopped tasks and handles navigation focus restoration. The implementation supports both desktop (IPC-based) and web (HTTP-based) platforms, with specific handling for mobile viewports and operator authentication states.
src/renderer/features/application-menu · high confidence
Introduces a new shared protocol layer for IPC and RPC communication
This change establishes a new, structured protocol layer in src/shared/protocol to standardize communication between the renderer, main process, and server shells. It introduces a typed RPC envelope system (motrix-rpc-v1) with robust error handling, sanitization, and versioning to ensure safe and consistent data exchange. The layer defines a comprehensive set of commands (e.g., task management, plugin controls, settings updates), queries (e.g., task details, plugin manifests, system status), and events (e.g., engine state changes, UI updates, bridge pairing events) that replace ad-hoc IPC calls. It also includes a bridge protocol for browser extension pairing and a forwardable event list to ensure consistent state synchronization across different host environments (Electron, web, server).
src/shared/protocol · high confidence
Introduces a new web-based directory picker with sorting and preference persistence
The web directory picker now supports sorting entries by name or modification time, with the chosen sort order persisted across sessions via local storage. The picker also manages directory preferences, including favorites and recent locations, and handles server directory navigation with robust error states and timeout handling.
src/renderer/features/web-directory-picker · high confidence
Introduces comprehensive type definitions for the application's shared domain models
This change establishes a robust, shared TypeScript type system for the application's core features, replacing ad-hoc or missing definitions with explicit interfaces and enums. It introduces types for the engine lifecycle and diagnostics (including failure reasons and recovery actions), download task states and action guards (defining when tasks can be paused, resumed, or retried), and plugin management (covering installation, consent, and runtime status). Additionally, it adds models for system integration (AppImage, Linux default apps), network configuration (GeoIP, DNS resolution, proxies), and UI state (dashboard layout, menu context, notifications). These definitions provide a stable contract between the main process and renderer, ensuring consistent data shapes across IPC boundaries and enabling better type safety for features like engine recovery, plugin security, and download history.
src/shared/types · high confidence
Introduces native-host support for Flatpak and AppImage sandboxed environments
The native-host component now includes dedicated support for running the browser bridge inside Linux sandboxed environments. A new Flatpak companion binary and broker protocol enable the host to install, manage, and communicate with the bridge within the Flatpak sandbox, while a new AppImage configuration module provides secure, owner-only launch validation for AppImage distributions. These additions allow the Motrix browser extension to function correctly when the desktop application is installed via Flatpak or AppImage, ensuring secure native messaging integration in these specific deployment models.
packages/native-host/src · high confidence
Introduces platform abstraction for host-specific services and aria2 binary detection
The platform module now provides a structured way to isolate host-specific logic. It defines a \PlatformServices\ interface and a \RunHost\ enum (supporting Electron and Node) to standardize access to environment details like user data directories and development flags. Additionally, it includes a utility to determine the correct aria2 binary name (\aria2c\ or \aria2c.exe\) based on the operating system, ensuring cross-platform compatibility for download operations.
src/shared/platform · high confidence
Introduces shared application infrastructure for menus, commands, and error handling
This change adds the foundational shared modules for the native application, including a centralized catalog of application commands (e.g., task creation, pausing, quitting) and a structured menu system that maps these commands to UI sections. It also introduces a comprehensive error code enumeration covering engine, task, plugin, and NAT issues, alongside a strict semantic versioning comparison utility for plugin updates. Additionally, it establishes a central registry for external URLs (supporting locale-specific manual links) and defines default keyboard shortcuts, providing the core wiring for the application's interface and stability.
src/shared · high confidence
Introduces task activity tracking for download lifecycle events
Adds a new \src/core/activity\ module that records task lifecycle events (such as submission and download completion) into a local SQLite database. This system aggregates activity into daily snapshots, handles coverage gaps when recording fails, and exposes the data via a service layer that emits updates to the event bus, enabling the UI to display historical download activity.
src/core · high confidence
New Add Task dialog with draft preservation and adaptive sizing
The Add Task dialog now preserves unsaved drafts when the user closes it, requiring explicit confirmation to discard changes, and prevents replacement requests from overwriting an in-flight submission. The dialog height adapts dynamically to its content while respecting viewport and maximum size limits, and it automatically recovers pending magnet file selections after connection drops or refreshes.
src/renderer · high confidence
New directory preferences dialog for managing favorites and recent folders
Users can now manage their favorite and recent folder lists through a new Directory Preferences dialog. This feature allows adding, removing, and promoting folders between favorites and recent lists, with changes staged as drafts and persisted only when explicitly saved. The implementation includes a custom hook for handling draft state, conflict resolution, and retry logic for failed saves, along with comprehensive test coverage for the dialog and draft management logic.
src/renderer/features/directory-preferences · high confidence
New plugin detail and relationship graph components
The plugin detail view now includes an About section that displays the plugin description, author, and homepage link, and an Access section that lists granted and optional permissions with interactive toggles for community plugins (while showing trusted/builtin permissions as read-only) and a warning for broad host access. Additionally, a new plugin call-graph visualization has been added, featuring a React Flow-based graph with custom edges that display call volume and command counts, an inspector panel for selecting and viewing node/edge details, an error boundary with retry and table-switch options, and a legend for call volume.
src/renderer/routes/plugins/components · high confidence
New shared constants for UI dimensions, performance profiles, and localization
This change introduces a new \src/shared/constants\ module that centralizes configuration values previously scattered or hardcoded. It defines UI geometry constants for the Add Task dialog and desktop window chrome, establishes a set of engine performance profiles (auto, balanced, high, maximum, custom) with specific tuning values like connection limits and split sizes, and provides a robust locale catalog with support for English and Traditional Chinese, including utilities for canonicalizing and resolving language codes. Additionally, it adds constants for video file type detection, incomplete download suffixes, user-agent presets, and keys that require application restarts.
src/shared/constants · high confidence
Server bridge extension support and security hardening
The server bridge now supports remote extensions over the MBP1 protocol, including a new bootstrap runtime, pairing prompt adapter, admission policy with rate limiting, and trusted extension registry management. This change also adds security hardening by introducing public URL diagnostics to warn about misconfigurations (loopback, unspecified hosts, invalid URLs) and adding test fixtures for expired and valid certificates to ensure proper TLS handling in the bridge communication layer.
src/server · high confidence
Behavioural changes
Added third-party license texts for Mozilla, aria2, and Rust crates
The repository now includes the full text of several third-party licenses in the THIRD\_PARTY\_LICENSES directory to ensure compliance and transparency. Specifically, the Mozilla Public License 2.0, the GNU General Public License v2 (associated with aria2 and its OpenSSL exception), the Apache License 2.0, and the MIT License (associated with various Rust crates such as base64, bitflags, block-buffer, and cfg-if) have been added as new files.
_THIRD\_PARTY\LICENSES · high confidence
Enhanced download source validation and task navigation fallbacks
The application now enforces stricter validation on download inputs, rejecting oversized text, unsupported protocols (such as sftp or ftps), and ambiguous URL structures like backslashes or embedded credentials, while offering automatic corrections for issues like unescaped characters. It also introduces robust fallbacks for task navigation, ensuring that links and notifications for removed or invalid tasks redirect to the main downloads list rather than breaking. Additionally, path handling for torrent metadata has been improved to correctly relativize file paths across different operating systems and container formats.
src/shared/lib · high confidence
Installer now registers file associations and macOS app entitlements
The Windows installer now explicitly registers Motrix as the default handler for .torrent files and magnet links via system capabilities, ensuring deep links resolve correctly without relying on legacy per-user registry keys. On macOS, the build now includes an entitlements file granting the app necessary permissions for JIT execution, native module loading, network access, and file system read-write access, which are required for stable operation under Apple's hardened runtime.
build · high confidence
Introduces strict validation schemas for application settings and task creation
This change adds a comprehensive set of Zod-based validation schemas in src/shared/schemas to enforce data integrity for core application features. For task creation, it defines schemas for both HTTP and BitTorrent inputs, enforcing constraints such as maximum base64 payload sizes, required file selections for torrents, and valid magnet URIs. Application settings are now validated with specific defaults and recovery logic for preferences like file deletion mode, tray icon colors, and byte unit systems. Additionally, schemas are introduced for the cross-platform application menu structure, dashboard layout tiles, directory preferences, and the browser bridge configuration, ensuring that UI states and user inputs are consistent and safe before reaching the engine.
src/shared/schemas · high confidence
Modernized Linux AppImage distribution and hardened release packaging
The Linux AppImage distribution has been modernized to support native Arch Linux packages and improved update mechanisms. The release pipeline now includes a new \appimage-artifact.mjs\ script that validates AppImage runtimes against strict ELF standards, ensuring static linking and removing legacy FUSE dependencies. Additionally, the \assemble-release-artifacts.mjs\ script now handles a broader set of Linux artifacts, including \.pacman\ packages for Arch Linux, alongside existing \.deb\, \.rpm\, and \.flatpak\ formats. The \before-pack-verify.mjs\ hook enforces stricter checks on bundled native binaries (aria2, native-host, finalize-fs) to prevent shipping incomplete or mismatched builds.
scripts · high confidence
Test coverage
Added e2e test coverage for core application features; Added integration tests for native host, Flatpak broker, and companion; Added plugin fixtures for integration testing; Added test fixtures for plugin hook delivery, SDK 2.0 compatibility, and timer activity; Expanded automated testing for release, compliance, and infrastructure scripts; New Bridge E2E test suite for MDXP integration and AppImage cold launch; New Playwright e2e test fixtures for Motrix; New browser-based e2e test suite for the web directory picker; New test utilities for aria2 integration and task fixtures.
Dependencies
Initial dependency manifests for Motrix v2.0.0-beta.40
This change introduces the foundational dependency manifests for the Motrix v2.0.0-beta.40 release. The root \package.json\ establishes the project as an ES module using pnpm 12.5.1, upgrading the runtime to Electron 44.4.3 and React 19.3.0, while adding modern tooling like Vite 8.3.0, Biome, and TypeScript 7.0.2. It also introduces new internal packages: \@motrix/native-host\ and \@motrix/finalize-fs\, which are Rust-based components (defined in their respective \Cargo.toml\ and \Cargo.lock\ files) for native host operations and filesystem finalization. Additionally, a dedicated \scripts/release-signing-tool\ package is added to isolate the \electron-builder\ dependency for release signing.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 33 → 62 (+29.2)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 72 → 69 (-3.1)
- Architecture 94 (new)
- Maturity 55 → 70 (+14.7)
- Readiness 12 → 54 (+41.1)
- Security 45 → 79 (+33.9)
- Accessibility 65 (new)
Resolved (79)
- Boundary-crossing change coupling: ConfigManager.js ↔ configKeys.js (src/main/core/ConfigManager.js)
- Boundary-crossing change coupling: DynamicTray.vue ↔ index.js (src/renderer/components/Native/DynamicTray.vue)
- Boundary-crossing change coupling: task.js ↔ preferences.js (src/renderer/utils/task.js)
- Change coupling: all.js ↔ app.js (src/shared/locales/all.js)
- Change coupling: all.js ↔ index.js (src/shared/locales/all.js)
- Change coupling: app.js ↔ index.js (src/shared/locales/app.js)
- Change coupling: preferences.js ↔ preferences.js (src/shared/locales/de/preferences.js)
- Change coupling: preferences.js ↔ preferences.js (src/shared/locales/fa/preferences.js)
- Change coupling: preferences.js ↔ preferences.js (src/shared/locales/fr/preferences.js)
- Change coupling: preferences.js ↔ preferences.js (src/shared/locales/pt-BR/preferences.js)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Dimension evaluation failed
- FileTooLong: utils/index.js (src/shared/utils/index.js)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- …and 59 more
New (1081)
- AppImageNativeHost.disable (cognitive 17) (src/main/bridge/appimage-native-host.ts)
- AppImageNativeHost.install (cognitive 27) (src/main/bridge/appimage-native-host.ts)
- AppImageNativeHost.install (cyclomatic 18) (src/main/bridge/appimage-native-host.ts)
- Aria2Adapter.addTorrent (cognitive 27) (src/core/engine/aria2/aria2-adapter.ts)
- Aria2Adapter.addTorrent (cyclomatic 34) (src/core/engine/aria2/aria2-adapter.ts)
- Aria2Adapter.createDownload (cognitive 56) (src/core/engine/aria2/aria2-adapter.ts)
- Aria2Adapter.createDownload (cyclomatic 49) (src/core/engine/aria2/aria2-adapter.ts)
- Aria2Adapter.removeDownloadResults (cognitive 21) (src/core/engine/aria2/aria2-adapter.ts)
- Aria2ConfigBuilder.buildArgs (cognitive 17) (src/core/engine/aria2/aria2-config-builder.ts)
- Aria2ConfigBuilder.buildArgs (cyclomatic 18) (src/core/engine/aria2/aria2-config-builder.ts)
- Aria2PauseState.reconcile (cyclomatic 17) (src/core/engine/aria2/aria2-pause-state.ts)
- BridgeManager.stopCurrent (cognitive 20) (src/main/bridge/bridge-manager.ts)
- BridgeManager.stopCurrent (cyclomatic 17) (src/main/bridge/bridge-manager.ts)
- BridgeReceiver.dispatchSubmit (cognitive 31) (src/core/bridge-receiver/bridge-receiver.ts)
- BridgeReceiver.dispatchSubmit (cyclomatic 18) (src/core/bridge-receiver/bridge-receiver.ts)
- CapabilityBridge.applyHookEffects (cognitive 20) (src/core/plugin/host/capability-bridge.ts)
- CapabilityBridge.applyHookEffects (cyclomatic 18) (src/core/plugin/host/capability-bridge.ts)
- CapabilityBridge.dispatchCall (cognitive 23) (src/core/plugin/host/capability-bridge.ts)
- CapabilityBridge.dispatchCall (cyclomatic 34) (src/core/plugin/host/capability-bridge.ts)
- CapabilityBridge.dispatchFfmpeg (cognitive 19) (src/core/plugin/host/capability-bridge.ts)
- …and 1061 more
Changes since last survey
- 205 commits — 87 feature/other, 118 fixes
By area
- (root) — 44 commits
- src/core — 40 commits
- src/renderer — 40 commits
- src/main — 29 commits
- docs/release-notes — 14 commits
- tests/scripts — 9 commits
- src/shared — 8 commits
- packages/finalize-fs — 4 commits
- src/server — 4 commits
- (repo) — 2 commits
- .github/ISSUE_TEMPLATE — 2 commits
- .github/workflows — 2 commits
- .claude/rules — 1 commit
- build/snap — 1 commit
- docs/bridge-pairing-protocol.md — 1 commit
- e2e/panel-toolbars.spec.ts — 1 commit
- packages/native-host — 1 commit
- scripts/dev.mjs — 1 commit
- tests/docker — 1 commit
Notable commits
- fix: Merge pull request #1967 from agalwood/fix/1966_windows_user_choice_latest_20260826
- fix: Merge pull request #1972 from agalwood/fix/1969_cross_platform_font_fallbacks_20260826
- fix: chore(l10n): fix some quotes in english and simpchinese (#2052)
- fix: fix(add-task): read clipboard only when window opens
- fix: fix(add-task): refresh default save directory on open (#2030)
- fix: fix(add-task): restore window height after collapsing advanced (#1916)
- fix: fix(add-task): shrink non-resizable window on Windows (#1926)
- fix: fix(aria2): harden WebSocket RPC and upgrade engine (#2032)
- fix: fix(bridge): isolate browser registration failures (#2118)
- fix: fix(bridge): preserve browser download filenames (#2155)
- fix: fix(bridge): refresh the save directory for new submissions (#2113)
- fix: fix(bridge): restore Windows desktop startup (#2066)
- fix: fix(bridge): submit task cookies with aria2 motrix.13 (#2073)
- fix: fix(bt): avoid long paths and retry magnet metadata (#1932)
- fix: fix(bt): isolate web seed failures and extend magnet timeout (#2088)
- fix: fix(bt): keep single-file torrent metadata out of downloads (#2209)
- fix: fix(bt): persist magnet file metadata (#1937)
- fix: fix(bt): prevent duplicate torrent tasks and path conflicts (#1939)
- fix: fix(bt): recover magnet file selection and add timeout fallback (#2089)
- fix: fix(build): include the Motrix license in Server artifacts (#1983)
- …and 185 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
agalwood/Motrix was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a426739e7dad563a14187c2647e1b7881118d559 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.