changes.rst 23 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565
  1. .. _important_notes:
  2. Important notes 2.x
  3. ===================
  4. This section provides information about security and corruption issues.
  5. (nothing to see here yet)
  6. .. _changelog:
  7. Change Log 2.x
  8. ==============
  9. Version 2.0.0b6 (2023-06-11)
  10. ----------------------------
  11. Please note:
  12. This is a beta release, only for testing - do not use for production repos.
  13. Compatibility notes:
  14. - this is a major "breaking" release that is not compatible with existing repos.
  15. We tried to put all the necessary "breaking" changes into this release, so we
  16. hopefully do not need another breaking release in the near future. The changes
  17. were necessary for improved security, improved speed, unblocking future
  18. improvements, getting rid of legacy crap / design limitations, having less and
  19. simpler code to maintain.
  20. You can use "borg transfer" to transfer archives from borg 1.1/1.2 repos to
  21. a new borg 2.0 repo, but it will need some time and space.
  22. - command line syntax was changed, scripts and wrappers will need changes:
  23. - you will usually either export BORG_REPO=<MYREPO> into your environment or
  24. call borg like: "borg -r <MYREPO> <COMMAND>".
  25. in the docs, we usually omit "-r ..." for brevity.
  26. - the scp-style REPO syntax was removed, please use ssh://..., #6697
  27. - ssh:// URLs: removed support for /~otheruser/, #6855.
  28. If you used this, just replace it by: ssh://user@host:port/home/otheruser/
  29. - -P / --prefix option was removed, please use the similar -a / --match-archives.
  30. - the archive name is always given separately from the repository
  31. (differently than with borg 1.x you must not give repo::archive).
  32. - the archive name is either given as a positional parameter, like:
  33. - borg create myarchive2 /some/path
  34. - borg diff myarchive1 myarchive2
  35. - or, if the command makes sense for an arbitrary amount of archives, archives
  36. can be selected using a glob pattern, like:
  37. - borg delete -a 'sh:myarchive*'
  38. - borg recreate -a 'sh:myarchive*'
  39. - some borg 1.x commands that supported working on a repo AND on an archive
  40. were split into 2 commands, some others were renamed:
  41. - borg 2 repo commands:
  42. - borg rcreate # "repo create", was: borg init
  43. - borg rlist # "repo list"
  44. - borg rinfo # "repo info"
  45. - borg rdelete # "repo delete"
  46. - borg 2 archive commands:
  47. - borg create ARCHIVE ...
  48. - borg list ARCHIVE
  49. - borg extract ARCHIVE ...
  50. - borg diff ARCH1 ARCH2
  51. - borg rename OLDNAME NEWNAME
  52. - borg info -a ARCH_GLOB
  53. - borg delete -a ARCH_GLOB
  54. - borg recreate -a ARCH_GLOB ...
  55. - borg mount -a ARCH_GLOB mountpoint ...
  56. For more details, please consult the docs or --help option output.
  57. - create/recreate/import-tar --timestamp: defaults to local timezone
  58. now (was: UTC)
  59. - some deprecated options were removed:
  60. - removed --remote-ratelimit (use --upload-ratelimit)
  61. - removed --numeric-owner (use --numeric-ids)
  62. - removed --nobsdflags (use --noflags)
  63. - removed --noatime (default now, see also --atime)
  64. - removed --save-space option (does not change behaviour)
  65. - using --list together with --progress is now disallowed (except with --log-json), #7219
  66. - the --glob-archives option was renamed to --match-archives (the short option
  67. name -a is unchanged) and extended to support different pattern styles:
  68. - id: for identical string match (this is the new default!)
  69. - sh: for shell pattern / globbing match (this was used by --glob-archives)
  70. - re: for regular expression match
  71. So you might need to edit your scripts like e.g.::
  72. borg 1.x: --glob-archives 'myserver-*'
  73. borg 2.0: --match-archives 'sh:myserver-*'
  74. - use platformdirs 3.x.x instead of home-grown code. Due to that:
  75. - XDG_*_HOME is not honoured on macOS and on Windows.
  76. - BORG_BASE_DIR can still be used to enforce some base dir + .config/ or .cache/.
  77. - the default macOS config and cache dir will now be in ~/Library/Application Support/borg/.
  78. - create: different included/excluded status chars, #7321
  79. - dry-run: now uses "+" (was: "-") and "-" (was: "x") for included/excluded status
  80. - non-dry-run: now uses "-" (was: "x") for excluded files
  81. Option --filter=... might need an update, if you filter for the status chars
  82. that were changed.
  83. - borg is now more strict and disallows giving some options multiple times -
  84. if that makes no sense. Highlander options, see #6269. That might make scripts
  85. fail now that somehow "worked" before (but maybe didn't work as intended due to
  86. the contradicting options).
  87. New features:
  88. - diff: include changes in ctime and mtime, #7248
  89. - diff: sort JSON output alphabetically
  90. - diff --content-only: option added to ignore metadata changes
  91. - diff: add --format option, #4634
  92. - import-tar --ignore-zeros: new option to support importing concatenated tars, #7432
  93. - debug id-hash / parse-obj / format-obj: new debug commands, #7406
  94. - transfer --compression=C --recompress=M: recompress while transferring, #7529
  95. - extract --continue: continue a previously interrupted extraction, #1356
  96. - prune --list-kept/--list-pruned: only list the kept (or pruned) archives, #7511
  97. - prune --short/--format: enable users to format the list output, #3238
  98. - implement BORG_<CMD>_FORMAT env vars for prune, list, rlist, #5166
  99. - rlist: size and nfiles format keys
  100. - implement unix domain (ipc) socket support, #6183::
  101. borg serve --socket # server side (not started automatically!)
  102. borg -r socket:///path/to/repo ... # client side
  103. - add get_runtime_dir / BORG_RUNTIME_DIR (contains e.g. .sock and .pid file)
  104. - support shell-style alternatives, like: sh:image.{png,jpg}, #7602
  105. Fixes:
  106. - do not retry on permission errors (pointless)
  107. - transfer: verify chunks we get using assert_id, #7383
  108. - fix config/cache dir compatibility issues, #7445
  109. - xattrs: fix namespace processing on FreeBSD, #6997
  110. - ProgressIndicatorPercent: fix space computation for wide chars, #3027
  111. - delete: remove --cache-only option, #7440.
  112. for deleting the cache only, use: borg rdelete --cache-only
  113. - borg debug get-obj/put-obj: fixed chunk id
  114. - create: ignore empty paths, print warning, #5637
  115. - extract: support extraction of atime/mtime on win32
  116. - benchmark crud: use TemporaryDirectory below given path, #4706
  117. - Ensure that cli options specified with action=Highlander can only be set once, even
  118. if the set value is a default value. Add tests for action=Highlander, #7500, #6269.
  119. - Fix argparse error messages from misc. validators (being more specific).
  120. - put security infos into data dir, add BORG_DATA_DIR env var, #5760
  121. - setup.cfg: remove setup_requires (we have a pyproject.toml for that), #7574
  122. - do not crash for empty archives list in borg rlist date based matching, #7522
  123. - sanitize paths during archive creation and extraction, #7108 #7099
  124. - make sure we do not get backslashes into item paths
  125. Other changes:
  126. - allow msgpack 1.0.5 also
  127. - development.lock.txt: upgrade cython to 0.29.35, misc. other upgrades
  128. - clarify platformdirs requirements, #7393.
  129. 3.0.0 is only required for macOS due to breaking changes.
  130. 2.6.0 was the last breaking change for Linux/UNIX.
  131. - mount: improve mountpoint error msgs, see #7496
  132. - more Highlander options, #6269
  133. - Windows: simplify building (just use pip)
  134. - refactor toplevel exception handling, #6018
  135. - remove nonce management, related repo methods (not needed for borg2)
  136. - borg.remote: remove support for borg < 1.1.0
  137. ($LOG, logging setup, exceptions, rpc tuple data format, version)
  138. - new remote and progress logging, #7604
  139. - borg.logger: add logging debugging functionality
  140. - add function to clear empty directories at end of compact process
  141. - unify scanning and listing of segment dirs / segment files, #7597
  142. - replace `LRUCache` internals with `OrderedDict`
  143. - docs:
  144. - add installation instructions for Windows
  145. - improve --one-file-system help and docs (macOS APFS), #5618 #4876
  146. - BORG_KEY_FILE: clarify docs, #7444
  147. - installation: add link to OS dependencies, #7356
  148. - update FAQ about locale/unicode issues, #6999
  149. - improve mount options rendering, #7359
  150. - make timestamps in manual pages reproducible.
  151. - describe performing pull-backups via ssh remote forwarding
  152. - suggest to use forced command when using remote-fowarding via ssh
  153. - fix some -a / --match-archives docs issues
  154. - incl./excl. options header, clarify --path-from-stdin exclusive control
  155. - add note about MAX_DATA_SIZE
  156. - update security support docs
  157. - improve patterns help
  158. - CI / tests / vagrant:
  159. - added pre-commit for linting purposes, #7476
  160. - resolved mode bug and added sleep clause for darwin systems, #7470
  161. - "auto" compressor tests: do not assume zlib is better than lz4, #7363
  162. - add stretch64 VM with deps built from source
  163. - misc. other CI / test fixes and updates
  164. - vagrant: add lunar64 VM, fix packages_netbsd
  165. - avoid long ids in pytest output
  166. - tox: package = editable-legacy, #7580
  167. - tox under fakeroot: fix finding setup_docs, #7391
  168. - check buzhash chunksize distribution, #7586
  169. - use debian/bookworm64 box
  170. Version 2.0.0b5 (2023-02-27)
  171. ----------------------------
  172. New features:
  173. - create: implement retries for individual fs files
  174. (e.g. if a file changed while we read it, if a file had an OSError)
  175. - info: add used storage quota, #7121
  176. - transfer: support --progress
  177. - create/recreate/import-tar: add --checkpoint-volume option
  178. - support date-based matching for archive selection,
  179. add --newer/--older/--newest/--oldest options, #7062 #7296
  180. Fixes:
  181. - disallow --list with --progress, #7219
  182. - create: fix --list --dry-run output for directories, #7209
  183. - do no assume hardlink_master=True if not present, #7175
  184. - fix item_ptrs orphaned chunks of checkpoint archives
  185. - avoid orphan content chunks on BackupOSError, #6709
  186. - transfer: fix bug in obfuscated data upgrade code
  187. - fs.py: fix bug in f-string (thanks mypy!)
  188. - recreate: when --target is given, do not detect "nothing to do", #7254
  189. - locking (win32): deal with os.rmdir/listdir PermissionErrors
  190. - locking: thread id must be parsed as hex from lock file name
  191. - extract: fix mtime when ResourceFork xattr is set (macOS specific), #7234
  192. - recreate: without --chunker-params borg shall not rechunk, #7336
  193. - allow mixing --progress and --list in log-json mode
  194. - add "files changed while reading" to Statistics class, #7354
  195. - fixed keys determination in Statistics.__add__(), #7355
  196. Other changes:
  197. - use local time / local timezone to output timestamps, #7283
  198. - update development.lock.txt, including a setuptools security fix, #7227
  199. - remove --save-space option (does not change behaviour)
  200. - remove part files from final archive
  201. - remove --consider-part-files, related stats code, update docs
  202. - transfer: drop part files
  203. - check: show id of orphaned chunks
  204. - ArchiveItem.cmdline list-of-str -> .command_line str, #7246
  205. - Item: symlinks: rename .source to .target, #7245
  206. - Item: make user/group/uid/gid optional
  207. - create: do not store user/group for stdin data by default, #7249
  208. - extract: chown only if we have u/g info in archived item, #7249
  209. - export-tar: for items w/o uid/gid, default to 0/0, #7249
  210. - fix some uid/gid lookup code / tests for win32
  211. - cache.py: be less verbose during cache sync
  212. - update bash completion script commands and options, #7273
  213. - require and use platformdirs 3.x.x package, tests
  214. - better included/excluded status chars, docs, #7321
  215. - undef NDEBUG for chunker and hashindex (make assert() work)
  216. - assert_id: better be paranoid (add back same crypto code as in old borg), #7362
  217. - check --verify_data: always decompress and call assert_id(), #7362
  218. - make hashindex_compact simpler and probably faster, minor fixes, cleanups, more tests
  219. - hashindex minor fixes, refactor, tweaks, tests
  220. - pyinstaller: remove icon
  221. - validation / placeholders / JSON:
  222. - implement (text|binary)_to_json: key (text), key_b64 (base64(binary))
  223. - remove bpath, barchive, bcomment placeholders / JSON keys
  224. - archive metadata: make sure hostname and username have no surrogate escapes
  225. - text attributes (like archive name, comment): validate more strictly, #2290
  226. - transfer: validate archive names and comment before transfer
  227. - json output: use text_to_json (path, target), #6151
  228. - docs:
  229. - docs and comments consistency, readability and spelling fixes
  230. - fix --progress display description, #7180
  231. - document how borg deals with non-unicode bytes in JSON output
  232. - document another way to get UTF-8 encoding on stdin/stdout/stderr, #2273
  233. - pruning interprets timestamps in the local timezone where borg prune runs
  234. - shellpattern: add license, use copyright/license markup
  235. - key change-passphrase: fix --encryption value in examples
  236. - remove BORG_LIBB2_PREFIX (not used any more)
  237. - Installation: Update Fedora in distribution list, #7357
  238. - add .readthedocs.yaml (use py311, use non-shallow clone)
  239. - tests:
  240. - fix archiver tests on Windows, add running the tests to Windows CI
  241. - fix tox4 passenv issue, #7199
  242. - github actions updates (fix deprecation warnings)
  243. - add tests for borg transfer/upgrade
  244. - fix test hanging reading FIFO when `borg create` failed
  245. - mypy inspired fixes / updates
  246. - fix prune tests, prune in localtime
  247. - do not look up uid 0 / gid 0, but current process uid/gid
  248. - safe_unlink tests: use os.link to support win32 also
  249. - fix test_size_on_disk_accurate for large st_blksize, #7250
  250. - relaxed timestamp comparisons, use same_ts_ns
  251. - add test for extracted directory mtime
  252. - use "fail" chunker to test erroneous input file skipping
  253. Version 2.0.0b4 (2022-11-27)
  254. ----------------------------
  255. Fixes:
  256. - transfer/upgrade: fix borg < 1.2 chunker_params, #7079
  257. - transfer/upgrade: do not access Item._dict, #7077
  258. - transfer/upgrade: fix crash in borg transfer, #7156
  259. - archive.save(): always use metadata from stats, #7072
  260. - benchmark: fixed TypeError in compression benchmarks, #7075
  261. - fix repository.scan api minimum requirement
  262. - fix args.paths related argparsing, #6994
  263. Other changes:
  264. - tar_filter: recognize .tar.zst as zstd, #7093
  265. - adding performance statistics to borg create, #6991
  266. - docs: add rcompress to usage index
  267. - tests:
  268. - use github and MSYS2 for Windows CI, #7097
  269. - win32 and cygwin: test fixes / skip hanging test
  270. - vagrant / github CI: use python 3.11.0 / 3.10.8
  271. - vagrant:
  272. - upgrade pyinstaller to 5.6.2 (supports python 3.11)
  273. - use python 3.11 to build the borg binary
  274. Version 2.0.0b3 (2022-10-02)
  275. ----------------------------
  276. Fixes:
  277. - transfer: fix user/group == None crash with borg1 archives
  278. - compressors: avoid memoryview related TypeError
  279. - check: fix uninitialised variable if repo is completely empty, #7034
  280. - do not use version_tuple placeholder in setuptools_scm template, #7024
  281. - get_chunker: fix missing sparse=False argument, #7056
  282. New features:
  283. - rcompress: do a repo-wide (re)compression, #7037
  284. - implement pattern support for --match-archives, #6504
  285. - BORG_LOCK_WAIT=n env var to set default for --lock-wait option, #5279
  286. Other:
  287. - repository.scan: misc. fixes / improvements
  288. - metadata: differentiate between empty/zero and unknown, #6908
  289. - CI: test pyfuse3 with python 3.11
  290. - use more relative imports
  291. - make borg.testsuite.archiver a package, split archiver tests into many modules
  292. - support reading new, improved hashindex header format, #6960.
  293. added version number and num_empty to the HashHeader, fixed alignment.
  294. - vagrant: upgrade pyinstaller 4.10 -> 5.4.1, use python 3.9.14 for binary build
  295. - item.pyx: use more Cython (faster, uses less memory), #5763
  296. Version 2.0.0b2 (2022-09-10)
  297. ----------------------------
  298. Bug fixes:
  299. - xattrs / extended stat: improve exception handling, #6988
  300. - fix and refactor replace_placeholders, #6966
  301. New features:
  302. - support archive timestamps with utc offsets, adapt them when using
  303. borg transfer to transfer from borg 1.x repos (append +00:00 for UTC).
  304. - create/recreate/import-tar --timestamp: accept giving timezone via
  305. its utc offset. defaults to local timezone, if no utc offset is given.
  306. Other changes:
  307. - chunks: have separate encrypted metadata (ctype, clevel, csize, size)
  308. chunk = enc_meta_len16 + encrypted(msgpacked(meta)) + encrypted(compressed(data)).
  309. this breaks repo format compatibility, you need to create fresh repos!
  310. - repository api: flags support, #6982
  311. - OpenBSD only - statically link OpenSSL, #6474.
  312. Avoid conflicting with shared libcrypto from the base OS pulled in via dependencies.
  313. - restructured source code
  314. - update diagrams to odg format, #6928
  315. Version 2.0.0b1 (2022-08-08)
  316. ----------------------------
  317. New features:
  318. - massively increase archive metadata stream size limit, #1473.
  319. currently rather testing the code, scalability will improve later, see #6945.
  320. - rcreate --copy-crypt-key: copy crypt_key from key of other repo, #6710.
  321. default: create new, random authenticated encryption key.
  322. - prune/delete --checkpoint-interval=1800 and ctrl-c/SIGINT support, #6284
  323. Fixes:
  324. - ctrl-c must not kill important subprocesses, #6912
  325. - transfer: check whether ID hash method and chunker secret are same.
  326. add PlaintextKey and AuthenticatedKey support to uses_same_id_hash function.
  327. - check: try harder to create the key, #5719
  328. - SaveFile: use a custom mkstemp with mode support, #6933, #6400
  329. - make setuptools happy, #6874
  330. - fix misc. compiler warnings
  331. - list: fix {flags:<WIDTH>} formatting, #6081
  332. Other changes:
  333. - new crypto does not need to call ._assert_id(), update code and docs.
  334. https://github.com/borgbackup/borg/pull/6463#discussion_r925436156
  335. - check: --verify-data does not need to decompress with new crypto modes
  336. - Key: crypt_key instead of enc_key + enc_hmac_key, #6611
  337. - misc. docs updates and improvements
  338. - CI: test on macOS 12 without fuse / fuse tests
  339. - repository: add debug logging for issue #6687
  340. - _version.py: remove trailing blank, add LF at EOF (make pep8 checker happy)
  341. Version 2.0.0a4 (2022-07-17)
  342. ----------------------------
  343. New features:
  344. - recreate: consider level for recompression, #6698, #3622
  345. Other changes:
  346. - stop using libdeflate
  347. - CI: add mypy (if we add type hints, it can do type checking)
  348. - big changes to the source code:
  349. - split up archiver module, transform it into a package
  350. - use Black for automated code formatting
  351. - remove some legacy code
  352. - adapt/fix code for mypy
  353. - use language_level = 3str for cython (this will be the default in cython 3)
  354. - docs: document HardLinkManager and hlid, #2388
  355. Version 2.0.0a3 (2022-07-04)
  356. ----------------------------
  357. Fixes:
  358. - check repo version, accept old repos only for --other-repo (e.g. rcreate/transfer).
  359. v2 is the default repo version for borg 2.0. v1 repos must only be used in a
  360. read-only way, e.g. for --other-repo=V1_REPO with borg init and borg transfer!
  361. New features:
  362. - transfer: --upgrader=NoOp is the default.
  363. This is to support general-purpose transfer of archives between related borg2
  364. repos.
  365. - transfer: --upgrader=From12To20 must be used to transfer (and convert) archives
  366. from borg 1.2 repos to borg 2.0 repos.
  367. Other changes:
  368. - removed some deprecated options
  369. - removed -P (aka --prefix) option, #6806. The option -a (aka --glob-archives)
  370. can be used for same purpose and is more powerful, e.g.: -a 'PREFIX*'
  371. - rcreate: always use argon2 kdf for new repos, #6820
  372. - rcreate: remove legacy encryption modes for new repos, #6490
  373. Version 2.0.0a2 (2022-06-26)
  374. ----------------------------
  375. Changes:
  376. - split repo and archive name into separate args, #948
  377. - use -r or --repo or BORG_REPO env var to give the repository
  378. - use --other-repo or BORG_OTHER_REPO to give another repo (e.g. borg transfer)
  379. - use positional argument for archive name or `-a ARCH_GLOB`
  380. - remove support for scp-style repo specification, use ssh://...
  381. - simplify stats output: repo ops -> repo stats, archive ops -> archive stats
  382. - repository index: add payload size (==csize) and flags to NSIndex entries
  383. - repository index: set/query flags, iteration over flagged items (NSIndex)
  384. - repository: sync write file in get_fd
  385. - stats: deduplicated size now, was deduplicated compressed size in borg 1.x
  386. - remove csize support at most places in the code (chunks index, stats, get_size,
  387. Item.chunks)
  388. - replace problematic/ugly hardlink_master approach of borg 1.x by:
  389. - symmetric hlid (all hardlinks pointing to same inode have same hlid)
  390. - all archived hardlinked regular files have a chunks list
  391. - borg rcreate --other-repo=OTHER_REPO: reuse key material from OTHER_REPO, #6554.
  392. This is useful if you want to use borg transfer to transfer archives from an
  393. existing borg 1.1/1.2 repo. If the chunker secret and the id key and algorithm
  394. stay the same, the deduplication will also work between past and future backups.
  395. - borg transfer:
  396. - efficiently copy archives from a borg 1.1/1.2 repo to a new repo.
  397. uses deduplication and does not decompress/recompress file content data.
  398. - does some cleanups / fixes / conversions:
  399. - disallow None value for .user/group/chunks/chunks_healthy
  400. - cleanup msgpack related str/bytes mess, use new msgpack spec, #968
  401. - obfuscation: fix byte order for size, #6701
  402. - compression: use the 2 bytes for type and level, #6698
  403. - use version 2 for new archives
  404. - convert timestamps int/bigint -> msgpack.Timestamp, see #2323
  405. - all hardlinks have chunks, maybe chunks_healthy, hlid
  406. - remove the zlib type bytes hack
  407. - make sure items with chunks have precomputed size
  408. - removes the csize element from the tuples in the Item.chunks list
  409. - clean item of attic 0.13 'acl' bug remnants
  410. - crypto: see 1.3.0a1 log entry
  411. - removed "borg upgrade" command (not needed any more)
  412. - compact: removed --cleanup-commits option
  413. - docs: fixed quickstart and usage docs with new cli command syntax
  414. - docs: removed the parts talking about potential AES-CTR mode issues
  415. (we will not use that any more).
  416. Version 1.3.0a1 (2022-04-15)
  417. ----------------------------
  418. Although this was released as 1.3.0a1, it can be also seen as 2.0.0a1 as it was
  419. later decided to do breaking changes and thus the major release number had to
  420. be increased (thus, there will not be a 1.3.0 release, but 2.0.0).
  421. New features:
  422. - init: new --encryption=(repokey|keyfile)-[blake2-](aes-ocb|chacha20-poly1305)
  423. - New, better, faster crypto (see encryption-aead diagram in the docs), #6463.
  424. - New AEAD cipher suites: AES-OCB and CHACHA20-POLY1305.
  425. - Session keys are derived via HKDF from random session id and master key.
  426. - Nonces/MessageIVs are counters starting from 0 for each session.
  427. - AAD: chunk id, key type, messageIV, sessionID are now authenticated also.
  428. - Solves the potential AES-CTR mode counter management issues of the legacy crypto.
  429. - init: --key-algorithm=argon2 (new default KDF, older pbkdf2 also still available)
  430. borg key change-passphrase / change-location keeps the key algorithm unchanged.
  431. - key change-algorithm: to upgrade existing keys to argon2 or downgrade to pbkdf2.
  432. We recommend you to upgrade unless you have to keep the key compatible with older versions of borg.
  433. - key change-location: usable for repokey <-> keyfile location change
  434. - benchmark cpu: display benchmarks of cpu bound stuff
  435. - export-tar: new --tar-format=PAX (default: GNU)
  436. - import-tar/export-tar: can use PAX format for ctime and atime support
  437. - import-tar/export-tar: --tar-format=BORG: roundtrip ALL item metadata, #5830
  438. - repository: create and use version 2 repos only for now
  439. - repository: implement PUT2: header crc32, overall xxh64, #1704
  440. Other changes:
  441. - require python >= 3.9, #6315
  442. - simplify libs setup, #6482
  443. - unbundle most bundled 3rd party code, use libs, #6316
  444. - use libdeflate.crc32 (Linux and all others) or zlib.crc32 (macOS)
  445. - repository: code cleanups / simplifications
  446. - internal crypto api: speedups / cleanups / refactorings / modernisation
  447. - remove "borg upgrade" support for "attic backup" repos
  448. - remove PassphraseKey code and borg key migrate-to-repokey command
  449. - OpenBSD: build borg with OpenSSL (not: LibreSSL), #6474
  450. - remove support for LibreSSL, #6474
  451. - remove support for OpenSSL < 1.1.1