changes.rst 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392
  1. .. _important_notes:
  2. Important notes 2.x
  3. ===================
  4. This section provides information about security and corruption issues.
  5. (nothing to see here yet)
  6. .. _changelog:
  7. Change Log 2.x
  8. ==============
  9. Version 2.0.0b5 (not released yet)
  10. ----------------------------------
  11. Please note:
  12. This is a beta release, only for testing - do not use for production repos.
  13. Compatibility notes:
  14. - this is a major "breaking" release that is not compatible with existing repos.
  15. We tried to put all the necessary "breaking" changes into this release, so we
  16. hopefully do not need another breaking release in the near future. The changes
  17. were necessary for improved security, improved speed, unblocking future
  18. improvements, getting rid of legacy crap / design limitations, having less and
  19. simpler code to maintain.
  20. You can use "borg transfer" to transfer archives from borg 1.1/1.2 repos to
  21. a new borg 2.0 repo, but it will need some time and space.
  22. - command line syntax was changed, scripts and wrappers will need changes:
  23. - you will usually either export BORG_REPO=<MYREPO> into your environment or
  24. call borg like: "borg -r <MYREPO> <COMMAND>".
  25. in the docs, we usually omit "-r ..." for brevity.
  26. - the scp-style REPO syntax was removed, please use ssh://..., #6697
  27. - ssh:// URLs: removed support for /~otheruser/, #6855.
  28. If you used this, just replace it by: ssh://user@host:port/home/otheruser/
  29. - -P / --prefix option was removed, please use the similar -a / --glob-archives.
  30. - the archive name is always given separately from the repository
  31. (differently than with borg 1.x you must not give repo::archive).
  32. - the archive name is either given as a positional parameter, like:
  33. - borg create myarchive2 /some/path
  34. - borg diff myarchive1 myarchive2
  35. - or, if the command makes sense for an arbitrary amount of archives, archives
  36. can be selected using a glob pattern, like:
  37. - borg delete -a 'myarchive*'
  38. - borg recreate -a 'myarchive*'
  39. - some borg 1.x commands that supported working on a repo AND on an archive
  40. were split into 2 commands, some others were renamed:
  41. - borg 2 repo commands:
  42. - borg rcreate # "repo create", was: borg init
  43. - borg rlist # "repo list"
  44. - borg rinfo # "repo info"
  45. - borg rdelete # "repo delete"
  46. - borg 2 archive commands:
  47. - borg create ARCHIVE ...
  48. - borg list ARCHIVE
  49. - borg extract ARCHIVE ...
  50. - borg diff ARCH1 ARCH2
  51. - borg rename OLDNAME NEWNAME
  52. - borg info -a ARCH_GLOB
  53. - borg delete -a ARCH_GLOB
  54. - borg recreate -a ARCH_GLOB ...
  55. - borg mount -a ARCH_GLOB mountpoint ...
  56. For more details, please consult the docs or --help option output.
  57. - create/recreate/import-tar --timestamp: defaults to local timezone
  58. now (was: UTC)
  59. - some deprecated options were removed:
  60. - removed --remote-ratelimit (use --upload-ratelimit)
  61. - removed --numeric-owner (use --numeric-ids)
  62. - removed --nobsdflags (use --noflags)
  63. - removed --noatime (default now, see also --atime)
  64. - removed --save-space option (does not change behaviour)
  65. - the --glob-archives option was renamed to --match-archives (the short option
  66. name -a is unchanged) and extended to support different pattern styles:
  67. - id: for identical string match (this is the new default!)
  68. - sh: for shell pattern / globbing match (this was used by --glob-archives)
  69. - re: for regular expression match
  70. So you might need to edit your scripts like e.g.::
  71. borg 1.x: --glob-archives 'myserver-*'
  72. borg 2.0: --match-archives 'sh:myserver-*'
  73. New features:
  74. - adding used storage quota to borg info, #7121
  75. Fixes:
  76. - disallow --list with --progress, #7219
  77. - create: fix --list --dry-run output for directories, #7209
  78. - do no assume hardlink_master=True if not present, #7175
  79. Other changes:
  80. - switch archive and file timestamps to UTC, also output tzoffset
  81. - update development.lock.txt, including a setuptools security fix, #7227
  82. - remove --save-space option (does not change behaviour)
  83. - validation / placeholders / JSON:
  84. - text attributes (like archive name, comment): validate more strictly, #2290
  85. - transfer: validate archive names and comment before transfer
  86. - remove bpath, barchive, bcomment placeholders / JSON keys
  87. - docs:
  88. - docs and comments consistency and readability improvement
  89. - fix --progress display description, #7180
  90. - tests:
  91. - fix archiver tests on Windows
  92. - fix tox4 passenv issue, #7199
  93. - github actions updates (fix deprecation warnings)
  94. - add tests for borg transfer/upgrade
  95. Version 2.0.0b4 (2022-11-27)
  96. ----------------------------
  97. Fixes:
  98. - transfer/upgrade: fix borg < 1.2 chunker_params, #7079
  99. - transfer/upgrade: do not access Item._dict, #7077
  100. - transfer/upgrade: fix crash in borg transfer, #7156
  101. - archive.save(): always use metadata from stats, #7072
  102. - benchmark: fixed TypeError in compression benchmarks, #7075
  103. - fix repository.scan api minimum requirement
  104. - fix args.paths related argparsing, #6994
  105. Other changes:
  106. - tar_filter: recognize .tar.zst as zstd, #7093
  107. - adding performance statistics to borg create, #6991
  108. - docs: add rcompress to usage index
  109. - tests:
  110. - use github and MSYS2 for Windows CI, #7097
  111. - win32 and cygwin: test fixes / skip hanging test
  112. - vagrant / github CI: use python 3.11.0 / 3.10.8
  113. - vagrant:
  114. - upgrade pyinstaller to 5.6.2 (supports python 3.11)
  115. - use python 3.11 to build the borg binary
  116. Version 2.0.0b3 (2022-10-02)
  117. ----------------------------
  118. Fixes:
  119. - transfer: fix user/group == None crash with borg1 archives
  120. - compressors: avoid memoryview related TypeError
  121. - check: fix uninitialised variable if repo is completely empty, #7034
  122. - do not use version_tuple placeholder in setuptools_scm template, #7024
  123. - get_chunker: fix missing sparse=False argument, #7056
  124. New features:
  125. - rcompress: do a repo-wide (re)compression, #7037
  126. - implement pattern support for --match-archives, #6504
  127. - BORG_LOCK_WAIT=n env var to set default for --lock-wait option, #5279
  128. Other:
  129. - repository.scan: misc. fixes / improvements
  130. - metadata: differentiate between empty/zero and unknown, #6908
  131. - CI: test pyfuse3 with python 3.11
  132. - use more relative imports
  133. - make borg.testsuite.archiver a package, split archiver tests into many modules
  134. - support reading new, improved hashindex header format, #6960.
  135. added version number and num_empty to the HashHeader, fixed alignment.
  136. - vagrant: upgrade pyinstaller 4.10 -> 5.4.1, use python 3.9.14 for binary build
  137. - item.pyx: use more Cython (faster, uses less memory), #5763
  138. Version 2.0.0b2 (2022-09-10)
  139. ----------------------------
  140. Bug fixes:
  141. - xattrs / extended stat: improve exception handling, #6988
  142. - fix and refactor replace_placeholders, #6966
  143. New features:
  144. - support archive timestamps with utc offsets, adapt them when using
  145. borg transfer to transfer from borg 1.x repos (append +00:00 for UTC).
  146. - create/recreate/import-tar --timestamp: accept giving timezone via
  147. its utc offset. defaults to local timezone, if no utc offset is given.
  148. Other changes:
  149. - chunks: have separate encrypted metadata (ctype, clevel, csize, size)
  150. chunk = enc_meta_len16 + encrypted(msgpacked(meta)) + encrypted(compressed(data)).
  151. this breaks repo format compatibility, you need to create fresh repos!
  152. - repository api: flags support, #6982
  153. - OpenBSD only - statically link OpenSSL, #6474.
  154. Avoid conflicting with shared libcrypto from the base OS pulled in via dependencies.
  155. - restructured source code
  156. - update diagrams to odg format, #6928
  157. Version 2.0.0b1 (2022-08-08)
  158. ----------------------------
  159. New features:
  160. - massively increase archive metadata stream size limit, #1473.
  161. currently rather testing the code, scalability will improve later, see #6945.
  162. - rcreate --copy-crypt-key: copy crypt_key from key of other repo, #6710.
  163. default: create new, random authenticated encryption key.
  164. - prune/delete --checkpoint-interval=1800 and ctrl-c/SIGINT support, #6284
  165. Fixes:
  166. - ctrl-c must not kill important subprocesses, #6912
  167. - transfer: check whether ID hash method and chunker secret are same.
  168. add PlaintextKey and AuthenticatedKey support to uses_same_id_hash function.
  169. - check: try harder to create the key, #5719
  170. - SaveFile: use a custom mkstemp with mode support, #6933, #6400
  171. - make setuptools happy, #6874
  172. - fix misc. compiler warnings
  173. - list: fix {flags:<WIDTH>} formatting, #6081
  174. Other changes:
  175. - new crypto does not need to call ._assert_id(), update code and docs.
  176. https://github.com/borgbackup/borg/pull/6463#discussion_r925436156
  177. - check: --verify-data does not need to decompress with new crypto modes
  178. - Key: crypt_key instead of enc_key + enc_hmac_key, #6611
  179. - misc. docs updates and improvements
  180. - CI: test on macOS 12 without fuse / fuse tests
  181. - repository: add debug logging for issue #6687
  182. - _version.py: remove trailing blank, add LF at EOF (make pep8 checker happy)
  183. Version 2.0.0a4 (2022-07-17)
  184. ----------------------------
  185. New features:
  186. - recreate: consider level for recompression, #6698, #3622
  187. Other changes:
  188. - stop using libdeflate
  189. - CI: add mypy (if we add type hints, it can do type checking)
  190. - big changes to the source code:
  191. - split up archiver module, transform it into a package
  192. - use Black for automated code formatting
  193. - remove some legacy code
  194. - adapt/fix code for mypy
  195. - use language_level = 3str for cython (this will be the default in cython 3)
  196. - docs: document HardLinkManager and hlid, #2388
  197. Version 2.0.0a3 (2022-07-04)
  198. ----------------------------
  199. Fixes:
  200. - check repo version, accept old repos only for --other-repo (e.g. rcreate/transfer).
  201. v2 is the default repo version for borg 2.0. v1 repos must only be used in a
  202. read-only way, e.g. for --other-repo=V1_REPO with borg init and borg transfer!
  203. New features:
  204. - transfer: --upgrader=NoOp is the default.
  205. This is to support general-purpose transfer of archives between related borg2
  206. repos.
  207. - transfer: --upgrader=From12To20 must be used to transfer (and convert) archives
  208. from borg 1.2 repos to borg 2.0 repos.
  209. Other changes:
  210. - removed some deprecated options
  211. - removed -P (aka --prefix) option, #6806. The option -a (aka --glob-archives)
  212. can be used for same purpose and is more powerful, e.g.: -a 'PREFIX*'
  213. - rcreate: always use argon2 kdf for new repos, #6820
  214. - rcreate: remove legacy encryption modes for new repos, #6490
  215. Version 2.0.0a2 (2022-06-26)
  216. ----------------------------
  217. Changes:
  218. - split repo and archive name into separate args, #948
  219. - use -r or --repo or BORG_REPO env var to give the repository
  220. - use --other-repo or BORG_OTHER_REPO to give another repo (e.g. borg transfer)
  221. - use positional argument for archive name or `-a ARCH_GLOB`
  222. - remove support for scp-style repo specification, use ssh://...
  223. - simplify stats output: repo ops -> repo stats, archive ops -> archive stats
  224. - repository index: add payload size (==csize) and flags to NSIndex entries
  225. - repository index: set/query flags, iteration over flagged items (NSIndex)
  226. - repository: sync write file in get_fd
  227. - stats: deduplicated size now, was deduplicated compressed size in borg 1.x
  228. - remove csize support at most places in the code (chunks index, stats, get_size,
  229. Item.chunks)
  230. - replace problematic/ugly hardlink_master approach of borg 1.x by:
  231. - symmetric hlid (all hardlinks pointing to same inode have same hlid)
  232. - all archived hardlinked regular files have a chunks list
  233. - borg rcreate --other-repo=OTHER_REPO: reuse key material from OTHER_REPO, #6554.
  234. This is useful if you want to use borg transfer to transfer archives from an
  235. existing borg 1.1/1.2 repo. If the chunker secret and the id key and algorithm
  236. stay the same, the deduplication will also work between past and future backups.
  237. - borg transfer:
  238. - efficiently copy archives from a borg 1.1/1.2 repo to a new repo.
  239. uses deduplication and does not decompress/recompress file content data.
  240. - does some cleanups / fixes / conversions:
  241. - disallow None value for .user/group/chunks/chunks_healthy
  242. - cleanup msgpack related str/bytes mess, use new msgpack spec, #968
  243. - obfuscation: fix byte order for size, #6701
  244. - compression: use the 2 bytes for type and level, #6698
  245. - use version 2 for new archives
  246. - convert timestamps int/bigint -> msgpack.Timestamp, see #2323
  247. - all hardlinks have chunks, maybe chunks_healty, hlid
  248. - remove the zlib type bytes hack
  249. - make sure items with chunks have precomputed size
  250. - removes the csize element from the tuples in the Item.chunks list
  251. - clean item of attic 0.13 'acl' bug remnants
  252. - crypto: see 1.3.0a1 log entry
  253. - removed "borg upgrade" command (not needed any more)
  254. - compact: removed --cleanup-commits option
  255. - docs: fixed quickstart and usage docs with new cli command syntax
  256. - docs: removed the parts talking about potential AES-CTR mode issues
  257. (we will not use that any more).
  258. Version 1.3.0a1 (2022-04-15)
  259. ----------------------------
  260. Although this was released as 1.3.0a1, it can be also seen as 2.0.0a1 as it was
  261. later decided to do breaking changes and thus the major release number had to
  262. be increased (thus, there will not be a 1.3.0 release, but 2.0.0).
  263. New features:
  264. - init: new --encryption=(repokey|keyfile)-[blake2-](aes-ocb|chacha20-poly1305)
  265. - New, better, faster crypto (see encryption-aead diagram in the docs), #6463.
  266. - New AEAD cipher suites: AES-OCB and CHACHA20-POLY1305.
  267. - Session keys are derived via HKDF from random session id and master key.
  268. - Nonces/MessageIVs are counters starting from 0 for each session.
  269. - AAD: chunk id, key type, messageIV, sessionID are now authenticated also.
  270. - Solves the potential AES-CTR mode counter management issues of the legacy crypto.
  271. - init: --key-algorithm=argon2 (new default KDF, older pbkdf2 also still available)
  272. borg key change-passphrase / change-location keeps the key algorithm unchanged.
  273. - key change-algorithm: to upgrade existing keys to argon2 or downgrade to pbkdf2.
  274. We recommend you to upgrade unless you have to keep the key compatible with older versions of borg.
  275. - key change-location: usable for repokey <-> keyfile location change
  276. - benchmark cpu: display benchmarks of cpu bound stuff
  277. - export-tar: new --tar-format=PAX (default: GNU)
  278. - import-tar/export-tar: can use PAX format for ctime and atime support
  279. - import-tar/export-tar: --tar-format=BORG: roundtrip ALL item metadata, #5830
  280. - repository: create and use version 2 repos only for now
  281. - repository: implement PUT2: header crc32, overall xxh64, #1704
  282. Other changes:
  283. - require python >= 3.9, #6315
  284. - simplify libs setup, #6482
  285. - unbundle most bundled 3rd party code, use libs, #6316
  286. - use libdeflate.crc32 (Linux and all others) or zlib.crc32 (macOS)
  287. - repository: code cleanups / simplifications
  288. - internal crypto api: speedups / cleanups / refactorings / modernisation
  289. - remove "borg upgrade" support for "attic backup" repos
  290. - remove PassphraseKey code and borg key migrate-to-repokey command
  291. - OpenBSD: build borg with OpenSSL (not: LibreSSL), #6474
  292. - remove support for LibreSSL, #6474
  293. - remove support for OpenSSL < 1.1.1