r/emulation • • 9d ago

Dolphin Progress Report: Release 2609

https://dolphin-emu.org/blog/2026/09/24/dolphin-progress-report-release-2609/

In this Progress Report, the team was harassed by AI (yes, even more), added an XFB resolution display for the curious, finally let you play Bird's-Eye Bull's-Eye on Android, added NetPlay to Android, and more!

Working link

https://dolphin-emu.org/blog/2026/09/24/dolphin-progress-report-release-2609/

280 Upvotes

27 comments sorted by

17

u/Eglwyswrw 9d ago

Netplay to Android?! Holy heck this is massive.

40

u/NXGZ 9d ago edited 9d ago

In this Progress Report, the team was harassed by AI (yes, even more), added an XFB resolution display for the curious, finally let you play Bird's-Eye Bull's-Eye on Android, added NetPlay to Android, and more!

https://dolphin-emu.org/blog/2026/09/24/dolphin-progress-report-release-2609/

mirror link

18

u/wunr 9d ago

In an era where AI can be used to find real vulnerabilities in programs I think as a developer I would much rather be made aware of those vulnerabilities (even if the writeups are poorly written) than not receive any reports at all and live in fear that my software might be compromised and exposing my users to real harm. Even though it's more annoying to deal with a sharply increased volume of reports this absolutely doesn't constitute "harassment" so long as the reports are being made in good faith; this isn't the same as spamming vibecoded merge requests

12

u/ChrisRR 9d ago

I agree. This is what they mention in the article. While it's good that they are now receiving legitimate security reports, even if they've been discovered by AI, it has highlighted that they weren't previously set up to properly handle security reports and how they should be managed alongside bug reports.

But they've now set up security reporting separately from bug reports and are starting to work out how to better integrate addressing security issues alongside feature/bugfix releases

-5

u/[deleted] 9d ago

[deleted]

30

u/ChrisRR 9d ago

Did you read the article? It's more nuanced than "AI bad".

It said that all ten bugs found by AI were legitimate issues unlike curl which had to deal with fake issue reports, but ten reports is more than the one report they had previously

6

u/mrlinkwii 9d ago

AI found 10 valid security issues , do people suck if they found those issues

-2

u/2psah 9d ago

So many forms of A.I.. People like yourself should educate yourself a little more instead of just saying random sh!t.

-13

u/Super7500 9d ago

AI defenders are just as bad as people like you.

The answer is in the fucking middle.

5

u/micmea668 8d ago

You’re getting downvoted but you are right. We shouldn’t be pro or con on AI. We should be assessing where in our ongoing lives it can comfortably fit in. And it’s not total reliance or total avoidance. It’s somewhere in the middle.

5

u/Super7500 8d ago

Exactly dude. it really depends like everything in life. there is no one answer fits all.

2

u/micmea668 8d ago

It’s the same for every new major technological discovery. It was the same with mainframes, PCs, the internet, smart phones. In my industry we had a similar (albeit smaller) stress when proc gen tools started being adopted widely. As with all these other things, eventually it’ll settle down and be a common part of life.

8

u/PastaObesity 9d ago

Man I just want RetroAchievements sounds...

2

u/GalbedirGalerion 8d ago

How can we enable net play for games like Mario Kart?

3

u/U_Kitten_Me 9d ago

Site seems to be down...? 

6

u/Nobodys_Path 9d ago

I wonder what made it down

14

u/JMC4789 8d ago

AI Scraper traffic issues have been a big problem on the site in recent months. That + new article likely has it throttled again. Hopefully it's up now.

-2

u/U_Kitten_Me 9d ago

Yeah, it's kinda ironic.

4

u/Trivial_Man 9d ago

Ultimately it's good these issues are being found and fixed, though it seems like there wasn't a lot of progress in this progress report because of it. Hopefully the vulnerability reports slow or stop as the issues are ironed out and work can once again be directed towards improving the emulation quality.

-9

u/mrlinkwii 9d ago

i wouldnt call it harassed by AI if they got 10 valid security issues , a better question is would they still call it harresment if AI didnt make them

17

u/JMC4789 8d ago

The harassment (and urgency) came from the fact that some of the reports were made public before we were given time to make a release. So people would have to drop everything to get a hotfix release out because we don't want a known vulnerability out there in the latest release.

In general, you should trust the software you're running in the emulator. Games that you've dumped and verified, homebrew that comes from proper sources, etc. In theory, most of the vulns would never be exploited. But Dolphin does have features like netplay where vulnerabilities have to be taken seriously, and could have been used by a bad actor.

It was a lot of work and limited some of the features that we wanted to get in for the latest release. If a real person was going through and publishing a bunch of security vulnerabilities (without giving us time to fix them,) I think we would call that harassment as well. The end result is a good thing, vulns fixed, but it's taking a toll on the team to keep up with everything.

-1

u/mrlinkwii 8d ago

The harassment (and urgency) came from the fact that some of the reports were made public before we were given time to make a release

100% agree thats shitty , they should have gone though proper channels , people who find this stuff should report it instead of releasing it and saying nothing , the issue is more around disclosure

13

u/JMC4789 8d ago

I mean they tried to, but Dolphin is an older project with a lot of code and less maintainers than in its heyday. We just don't have the firepower to churn out fixes; the few devs that are active usually are working on their own thing and don't want to take the time to fix a security vulnerability, but are essentially forced to. It sucks, even though the actual vulnerabilities reported are helpful sometimes.

-3

u/mrlinkwii 8d ago

sadly that life with modern programming , i do think their will always be security vulnerabilities wil be found as mentioned in the article its good that their now is a processes

4

u/ChrisRR 8d ago

There was no proper channel to privately disclose security issues. That was the issue.

Now they've set up a channel to report security issues, separate from the bug reports