« Back to Applications

AquaLink

For PowerPC Macs (Tiger)

A personal project that lets 20-year-old PowerPC Macs (iBook, Power Mac; Mac OS X Tiger/Leopard) keep working on today's networks.

  • Connect to modern NAS devices, Windows PCs, and Macs, and drag & drop files between them — something PPC Macs have never been able to do before.
  • You can also expose the PPC Mac itself as a simple NAS, so current Macs and Windows PCs can connect to it as a shared folder.
Download AquaLink.zip
Last updated: 2026-09-23 (v0.5.23)
Downloads so far: 152
Only needed if you'll use the Mac's NAS feature from Windows. Keep both zip files together in the same folder.
Note: Tiger's stock Safari/curl can't verify today's HTTPS certificates, so downloading here directly can fail. We recommend Aquafox — the PowerPC-era browser we make a Japanese language pack for — which handles modern HTTPS fine. Failing that, fetch the file on a modern machine and copy it over, or use a modern curl via Tigerbrew/MacPorts.

Changelog

  • 2026-09-23 — Extended the HTTPS support in "share this Mac" to work from Windows too (previously Mac/Finder only). The Windows connection guide now fetches and trusts AquaLink's self-signed certificate automatically, and connects using an "@SSL@port" path. Building this surfaced two real certificate bugs: the certificate had no SAN (Subject Alternative Name) for hostname matching, so Windows rejected it outright (fixed by adding the server's LAN IP as a SAN); and adding that SAN without also bumping the certificate to X.509v3 left it in a state .NET's stricter certificate parser rejected as "corrupted" (fixed by explicitly setting the version). Also fixed a separate, very confusing failure: running the connection script as administrator hid the mounted drive from the normal desktop's File Explorer even though it reported success, so the script now detects and refuses to run elevated. Tested on real hardware: Windows 11, Ventura, High Sierra, and an M2 MacBook Air on Tahoe.
  • 2026-09-22 — Fixed the hosts-file update step in the Windows connection guide (AquaLink-windows-setup.zip). The name check was a substring match, so registering a server named "aqualink" could be wrongly treated as "already present" just because an unrelated entry like "aqualink-nas" contained it as a substring — the real entry never got added and name resolution failed. It also never checked whether a matching name's IP was still correct, so a stale entry from an earlier run (the Mac's IP can change) could silently stick around. Now checks both the exact name and the current IP before rewriting.
  • 2026-09-22 — Fixed the Windows connection guide (AquaLink-windows-setup.zip). AquaLink's default port (8091) wasn't on Windows's WebClient allow-list, so credentials never got sent and Windows just showed a generic "not authenticated" error (code 1244) with no clue the port was the cause. WebClient's allow-list (AuthForwardServerList) actually needs an entry shaped like "http://servername" (no port number) — a bare "*" isn't the documented syntax and didn't actually work — so this was corrected, and the fix now appends to whatever's already registered instead of overwriting it (in case more than one AquaLink share is set up under different names). Also fixed a related issue found right after: a plain UNC path naming just the server is always read as port 80 by WebClient, so reaching AquaLink's non-standard port 8091 needs a "servername@port" suffix (this was showing up as "network path not found," error 67). Confirmed on a real Windows 11 machine.
  • 2026-09-22 — Added optional HTTPS support to the "share this Mac" feature (a new "HTTPS (encrypted, experimental)" checkbox in Share Settings, off by default). OpenSSL is built on-device and statically linked; a self-signed certificate is generated once on first use and reused after that, so Finder's trust decision doesn't reset on every launch. This addresses the previously-flagged plaintext-on-LAN limitation when turned on. Windows-side certificate trust is out of scope for now, so Windows connections stay on plain HTTP.
  • 2026-09-22 — Added an opt-in crash report feature. If the previous session left a new crash log, it's shown in full on launch and you're asked once whether to send it to this site (never sent without consent, and never rewritten). Building it surfaced two real bugs that only showed up on actual Tiger hardware: a call to -[NSAlert setAccessoryView:], which doesn't exist on this AppKit, and a crash that raced with AppKit's drag-type registration right after the confirmation dialog closed.
  • 2026-09-21 — If the "Share" or "Username" field contains something that looks like an IP address (possibly swapped with the Address field), AquaLink now asks for confirmation before connecting, without rewriting what you typed.
  • 2026-09-18 — Ran a security review. The "share this Mac" feature now rate-limits and temporarily blocks clients that repeatedly fail authentication in a short time (normal use is unaffected). Also, if you use this feature, it's recommended to disable UPnP on your router (confirmed as a real exposure risk when left enabled). Attempted to switch the password scheme to Digest authentication for better security, but found no way to satisfy both Windows's and macOS's native WebDAV clients, so this was not shipped.
  • 2026-09-12 — Fixed a crash in the file list found on a real PowerMac G4, most reliably triggered by clicking a row and then scrolling. The icon-display mechanism for filenames was rebuilt on Apple's own standard NSCell facility, removing the underlying cause of a hardware-dependent crash.
  • 2026-09-11 — The discovered-server dropdown now shows just the name instead of "name — IP address" (too long to read in the popup); picking one still fills in the IP automatically. Also, a successful connection now shows the target (address/share) in the window's title bar, since the small path label alone was easy to miss.
  • 2026-09-11 — Fixed "Unmount" repeatedly failing with "Operation not permitted" on some setups, even after entering an admin password. It now unmounts the same way /sbin/mount_webdav itself does — a small setuid-root helper bundled with the app — so it works reliably without a password dialog or Terminal (a one-time admin password is still needed to set the helper up). Also fixed the "Unmount" button sometimes getting stuck after the volume was ejected directly from Finder, and a leftover desktop icon that could linger after unmounting.
  • 2026-09-10 — Added a standard Edit menu (Copy/Paste/Select All, etc.) to the menu bar — the hand-built menu had none, so ⌘C / ⌘V did nothing in any text field. Also, a successful "Connect in Finder" mount now opens that folder in Finder, since it wasn't obvious what got mounted where (it mounts on the machine running AquaLink).
  • 2026-09-10 — "Connect in Finder" (WebDAV mount) failures were only shown as a small line at the bottom of the window; they now also raise a dialog. AquaLink also checks whether mount_webdav still has its setuid (admin) bit — OS updates can strip it, which makes every mount fail — and points you at the one-line fix if it's gone.
  • 2026-09-10 — The address drop-down now discovers SMB servers on your LAN (NAS boxes, Macs with sharing on) via Bonjour, so you can connect without knowing the IP — just pick it from the list and the IP is filled in. Enter the share name and password as before.
  • 2026-09-06 — The file browser's column headers (Name, Size, Modified) are now clickable to sort. Click again to flip ascending/descending, with a ▲▼ indicator for the current order. Folders always stay on top.
  • 2026-09-06 — Reworked the file list toward a Transmit/Cyberduck style (mostly cosmetic). The Name column now leads with a folder/file icon, so the text "Kind" column is gone. Added a "Modified" column showing each file's own timestamp as "2026-09-06 | 14:32". Size and Modified are right-aligned and fixed width; only the Name column grows when the window widens. All columns use the standard system font.
  • 2026-09-06 — A batch of file-browser UI tweaks (mostly cosmetic). The "Up" button now reads "▲ Up" (it was easily mistaken for browser back/forward) and takes Finder's ⌘↑ shortcut. Fixed the top edge of the rounded buttons being clipped. Dotfiles other than .DS_Store (.lesshst and the like) were showing in the list; now all dotfiles are hidden — a display filter only, nothing is deleted.
  • 2026-09-01 — Fixed connection error messages not showing their second (detail) line — the status field was single-line only. Now also shown in a dialog.
  • 2026-08-31 — Fixed a build failure (SMB2_SEC_NTLMSSP undeclared) against tagged libsmb2 releases such as PPCPorts' — added a compat definition since upstream hasn't moved it to a public header in any release yet.
  • 2026-08-29 — Fixed a regression from the previous fix: a Makefile change was breaking builds on Leopard/Snow Leopard. Now only falls back to the SDK when the system's own headers are actually missing.
  • 2026-08-29 — Fixed a connection failure on libsmb2 built via PPCPorts (with Kerberos support): authentication was attempting Kerberos first and failing, so NTLM is now explicitly requested instead.
  • 2026-08-28 — Added an option to require SMB3 encryption. While implementing it, found and fixed a big-endian bug in libsmb2 itself (the encrypted header's SessionId wasn't byte-swapped for the wire) and reported it upstream.
  • 2026-08-23 — Fixed umount failing under administrator privileges by calling it via its full path (/sbin/umount)
  • 2026-08-20 — Added English UI support (switchable between Japanese and English)
  • 2026-08-20 — Fixed an issue where the menu bar would fail to open

What to Download

  • AquaLink.zip — the app itself. Copy it onto the PowerPC Mac (Tiger/Leopard) you want to use.
  • AquaLink-windows-setup.zip — helper files for connecting to the Mac's sharing feature from Windows. Keep both zip files together in the same folder; don't separate their contents.

How to Use (Quick Start)

  1. Unzip AquaLink.zip and launch AquaLink.app on the target PPC Mac.
  2. If you're only connecting Mac-to-Mac or to a modern NAS, that's all you need.
  3. To use the Mac itself as a NAS from Windows, follow AquaLink's Share This Mac (NAS Mode) → Windows Connection Guide, and run connect-aqualink.bat from AquaLink-windows-setup.zip.

Supported Environments

EnvironmentPowerPC Mac / Mac OS X 10.4.11 (Tiger)
Verified hardwareiBook G4 (PowerBook6,5)

A personal hobby project provided with no warranty. See GitHub for detailed technical information and source code.

AquaLink is basically a thin shell around libsmb2, a C library that speaks SMB2/3. As far as I could find when I looked into it, this makes AquaLink the first working SMB2/3 client anyone's gotten running on PowerPC Mac OS X — Apple's own smbfs.kext never got past SMB1. Here's roughly how it came together, and a few of the uglier bugs along the way.

People assume AI makes this easy. It does make some things easier — typos and indentation mistakes basically don't happen anymore. But what actually happens is lining up at least 3, sometimes 4, of Windows, a PowerMac G4, an iBook G4, an M2 MacBook Air, and a 2010 MacBook — all real hardware — taking logs off each one by hand, and squashing bugs one at a time in VS Code on the M2 MacBook Air. AquaLink especially went through this.

Why libsmb2

There was just no way for a PPC Mac to talk to a modern SMB3 NAS — the built-in SMB stack doesn't speak the protocol, full stop. libsmb2 turned out to be pretty much the only SMB2/3 client library that still builds on hardware and toolchains this old, so that decided it.

Getting libsmb2 to build on Tiger's gcc 4.0.0

Tiger's SDK doesn't have CommonCrypto, so a stock libsmb2 build mis-detects __APPLE__, picks the CommonCrypto AES path anyway, and fails to compile. Fixed that with a small patch to configure.ac that explicitly checks for CommonCrypto/CommonCrypto.h before going down that path. Needed two more flags on top of that: --disable-werror, because gcc 4.0.0 warns about a much wider range of shadowed declarations than modern gcc does, and with -Werror those all turn into hard failures; and --without-libkrb5, because Tiger has neither GSS.framework nor krb5.h, so turning on Kerberos support just breaks the build over missing headers. Falling back to libsmb2's built-in NTLMSSP auth was plenty for a home NAS anyway.

A self-contained Cocoa app

No .nib file — the whole UI is built in code. libsmb2 is statically linked in too, so there's no make install step, no separate library to ship. Unzip it and it just runs.

Getting the NAS to show up as a real Finder volume

libsmb2 on its own only gets you programmatic access, nothing shows up as an icon. AquaLink works around that by running its own tiny embedded HTTP/WebDAV server (raw BSD sockets, handling OPTIONS/PROPFIND/GET/HEAD/PUT/DELETE/MKCOL/LOCK/UNLOCK) on 127.0.0.1, then calling mount_webdav against that loopback address. End result: it shows up in /Volumes like any other network share, and you can just drag files into it in the Finder. FUSE would've been the more obvious route, but MacFUSE/OSXFUSE never supported Tiger at all (PowerPC support was dropped industry-wide around 2011), so that wasn't really on the table.

Going the other way: turning the Mac itself into a NAS

This wasn't part of the original plan — it got added once the actual need showed up: being able to browse and edit old RAW photos sitting on the iBook, straight from a modern Mac or PC. LocalWebDAVServer reuses the same embedded server, but swaps the libsmb2 calls out for plain POSIX file I/O (open/read/write/opendir), binds to INADDR_ANY instead of loopback-only, and adds HTTP Basic auth plus path-traversal (../) protection.

Bugs and lessons along the way

Garbled Japanese text. gcc 4.0.0's Objective-C compiler sometimes just doesn't parse @"日本語"-style literals correctly. Switching to [NSString stringWithUTF8String:"日本語"] — decoding a raw C byte string as UTF-8 explicitly — fixed it.
Unmount race that hung the whole Mac. The original Disconnect button stopped the embedded WebDAV server without checking whether diskutil unmount had actually worked. If the unmount silently failed or hung, macOS was left thinking the volume was still mounted while the server behind it was gone — and the whole of /Volumes would hang. Getting out of that meant temporarily standing up something to answer on that port again; seems like the kernel was just waiting on a pending response. Lesson: don't tear down state after an OS-level command until you've actually confirmed it worked. Now it uses umount (retrying with -f) instead of diskutil unmount, and only stops the server once the unmount is confirmed.
A self-inflicted bug in the icon format. Modern iconutil only writes PNG-based icon representations, and Tiger's Finder can't read those at all — a Tiger-compatible .icns needs the old raw-bitmap chunks (is32/il32/it32 for 24-bit RGB, s8mk/l8mk/t8mk for the masks), so I had to hand-build those. My first PackBits (RLE) encoder/decoder pair was built on a wrong assumption about what the control byte meant, and round-tripping it against itself never caught it — a self-written encoder and decoder that agree with each other only prove they share the same wrong assumption. It only showed up as visual noise on real Tiger hardware. Reading libicns's implementation (an established open-source library) turned up the actual rule, and I confirmed it by decoding Aquafox's own icon with it before fixing my encoder. Lesson: round-tripping a custom format against itself only proves internal consistency, not correctness — you need a real, independently-verified file to check against.
Unmount failing on one specific patched image. Someone running an unofficially patched 10.6.8 PowerPC build reported that Disconnect always failed. Turned out mount_webdav runs setuid-root, so the mount ends up root-owned, and a normal user's umount gets Operation not permitted. Tried two different privilege-escalation paths — NSAppleScript's admin-privileges route, then the lower-level AuthorizationExecuteWithPrivileges — and both failed the exact same way, while sudo from a terminal (which skips the GUI auth path entirely) worked every time. Two independent GUI-auth APIs failing identically points pretty strongly at that patched image's GUI auth being broken at a level no app-side code can fix. Accepted it as a known limitation for that environment — sudo umount -f from the terminal is the reliable workaround. Unmodified Tiger/Leopard/Snow Leopard installs have never hit this.

What's next

Thinking about browser-based access to the NAS feature, so you wouldn't need the dedicated app at all.

Full source code is on GitHub.

Feedback on this app

Rating (optional)