2
0

changes.rst 83 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127
  1. Important notes
  2. ===============
  3. This section provides information about security and corruption issues.
  4. .. _tam_vuln:
  5. Pre-1.0.9 manifest spoofing vulnerability (CVE-2016-10099)
  6. ----------------------------------------------------------
  7. A flaw in the cryptographic authentication scheme in Borg allowed an attacker
  8. to spoof the manifest. The attack requires an attacker to be able to
  9. 1. insert files (with no additional headers) into backups
  10. 2. gain write access to the repository
  11. This vulnerability does not disclose plaintext to the attacker, nor does it
  12. affect the authenticity of existing archives.
  13. The vulnerability allows an attacker to create a spoofed manifest (the list of archives).
  14. Creating plausible fake archives may be feasible for small archives, but is unlikely
  15. for large archives.
  16. The fix adds a separate authentication tag to the manifest. For compatibility
  17. with prior versions this authentication tag is *not* required by default
  18. for existing repositories. Repositories created with 1.0.9 and later require it.
  19. Steps you should take:
  20. 1. Upgrade all clients to 1.0.9 or later.
  21. 2. Run ``borg upgrade --tam <repository>`` *on every client* for *each* repository.
  22. 3. This will list all archives, including archive IDs, for easy comparison with your logs.
  23. 4. Done.
  24. Prior versions can access and modify repositories with this measure enabled, however,
  25. to 1.0.9 or later their modifications are indiscernible from an attack and will
  26. raise an error until the below procedure is followed. We are aware that this can
  27. be be annoying in some circumstances, but don't see a way to fix the vulnerability
  28. otherwise.
  29. In case a version prior to 1.0.9 is used to modify a repository where above procedure
  30. was completed, and now you get an error message from other clients:
  31. 1. ``borg upgrade --tam --force <repository>`` once with *any* client suffices.
  32. This attack is mitigated by:
  33. - Noting/logging ``borg list``, ``borg info``, or ``borg create --stats``, which
  34. contain the archive IDs.
  35. We are not aware of others having discovered, disclosed or exploited this vulnerability.
  36. Vulnerability time line:
  37. * 2016-11-14: Vulnerability and fix discovered during review of cryptography by Marian Beermann (@enkore)
  38. * 2016-11-20: First patch
  39. * 2016-12-20: Released fixed version 1.0.9
  40. * 2017-01-02: CVE was assigned
  41. * 2017-01-15: Released fixed version 1.1.0b3 (fix was previously only available from source)
  42. .. _attic013_check_corruption:
  43. Pre-1.0.9 potential data loss
  44. -----------------------------
  45. If you have archives in your repository that were made with attic <= 0.13
  46. (and later migrated to borg), running borg check would report errors in these
  47. archives. See issue #1837.
  48. The reason for this is a invalid (and useless) metadata key that was
  49. always added due to a bug in these old attic versions.
  50. If you run borg check --repair, things escalate quickly: all archive items
  51. with invalid metadata will be killed. Due to that attic bug, that means all
  52. items in all archives made with these old attic versions.
  53. Pre-1.0.4 potential repo corruption
  54. -----------------------------------
  55. Some external errors (like network or disk I/O errors) could lead to
  56. corruption of the backup repository due to issue #1138.
  57. A sign that this happened is if "E" status was reported for a file that can
  58. not be explained by problems with the source file. If you still have logs from
  59. "borg create -v --list", you can check for "E" status.
  60. Here is what could cause corruption and what you can do now:
  61. 1) I/O errors (e.g. repo disk errors) while writing data to repo.
  62. This could lead to corrupted segment files.
  63. Fix::
  64. # check for corrupt chunks / segments:
  65. borg check -v --repository-only REPO
  66. # repair the repo:
  67. borg check -v --repository-only --repair REPO
  68. # make sure everything is fixed:
  69. borg check -v --repository-only REPO
  70. 2) Unreliable network / unreliable connection to the repo.
  71. This could lead to archive metadata corruption.
  72. Fix::
  73. # check for corrupt archives:
  74. borg check -v --archives-only REPO
  75. # delete the corrupt archives:
  76. borg delete --force REPO::CORRUPT_ARCHIVE
  77. # make sure everything is fixed:
  78. borg check -v --archives-only REPO
  79. 3) In case you want to do more intensive checking.
  80. The best check that everything is ok is to run a dry-run extraction::
  81. borg extract -v --dry-run REPO::ARCHIVE
  82. .. _changelog:
  83. Changelog
  84. =========
  85. Version 1.0.13 (not released yet)
  86. ---------------------------------
  87. Please note: this is very likely the last 1.0.x release, please upgrade to 1.1.x.
  88. Bug fixes:
  89. - security fix: configure FUSE with "default_permissions", fixes #3903
  90. "default_permissions" is now enforced by borg by default to let the
  91. kernel check uid/gid/mode based permissions.
  92. "ignore_permissions" can be given to not enforce "default_permissions".
  93. - xattrs: fix borg exception handling on ENOSPC error, #3808
  94. New features:
  95. - read a passphrase from a file descriptor
  96. Read a passphrase from a file descriptor specified in the
  97. BORG_PASSPHRASE_FD environment variable.
  98. Other changes:
  99. - acl platform code: fix acl set return type
  100. - xattr:
  101. - add linux {list,get,set}xattr ctypes prototypes
  102. - fix darwin flistxattr ctypes prototype
  103. - testing / travis-ci:
  104. - fix the homebrew 1.9 issues on travis-ci, #4254
  105. - travis OS X: use xcode 8.3 (not broken)
  106. - tox.ini: lock requirements
  107. - unbreak 1.0-maint on travis, fixes #4123
  108. - vagrant:
  109. - misc. fixes
  110. - FUSE for macOS: upgrade 3.7.1 to 3.8.3
  111. - Python: upgrade 3.5.5 to 3.5.6
  112. - docs:
  113. - Update installation instructions for macOS
  114. - update release workflow using twine (docs, scripts), #4213
  115. Version 1.0.12 (2018-04-08)
  116. ---------------------------
  117. Bug fixes:
  118. - repository: cleanup/write: invalidate cached FDs, tests
  119. - serve: fix exitcode, #2910
  120. - extract: set bsdflags last (include immutable flag), #3263
  121. - create --timestamp: set start time, #2957
  122. - create: show excluded dir with "x" for tagged dirs / caches, #3189
  123. - migrate locks to child PID when daemonize is used
  124. - Buffer: fix wrong thread-local storage use, #2951
  125. - fix detection of non-local path, #3108
  126. - fix LDLP restoration for subprocesses, #3077
  127. - fix subprocess environments (xattr module's fakeroot version check,
  128. borg umount, BORG_PASSCOMMAND), #3050
  129. - remote: deal with partial lines, #2637
  130. - get rid of datetime.isoformat, use safe parse_timestamp to parse
  131. timestamps, #2994
  132. - build: do .h file content checks in binary mode, fixes build issue for
  133. non-ascii header files on pure-ascii locale platforms, #3544 #3639
  134. - remove platform.uname() call which caused library mismatch issues, #3732
  135. - add exception handler around deprecated platform.linux_distribution() call
  136. Other changes:
  137. - require msgpack-python >= 0.4.6 and < 0.5.0, see #3753
  138. - add parens for C preprocessor macro argument usages (did not cause
  139. malfunction)
  140. - ignore corrupt files cache, #2939
  141. - replace "modulo" with "if" to check for wraparound in hashmap
  142. - keymanager: don't depend on optional readline module, #2980
  143. - exclude broken pytest 3.3.0 release
  144. - exclude broken Cython 0.27(.0) release, #3066
  145. - flake8: add some ignores
  146. - docs:
  147. - create: document exclusion through nodump
  148. - document good and problematic option placements, fix examples, #3356
  149. - update docs about hardlinked symlinks limitation
  150. - faq: we do not implement futile attempts of ETA / progress displays
  151. - simplified rate limiting wrapper in FAQ
  152. - twitter account @borgbackup, #2948
  153. - add note about metadata dedup and --no[ac]time, #2518
  154. - change-passphrase only changes the passphrase, #2990
  155. - clarify encrypted key format for borg key export, #3296
  156. - document sshfs rename workaround, #3315
  157. - update release checklist about security fixes
  158. - docs about how to verify a signed release, #3634
  159. - chunk seed is generated per /repository/
  160. - vagrant:
  161. - use FUSE for macOS 3.7.1 to build the macOS binary
  162. - use python 3.5.5 to build the binaries
  163. - add exe location to PATH when we build an exe
  164. - use https pypi url for wheezy
  165. - netbsd: bash is already installed
  166. - netbsd: fix netbsd version in PKG_PATH
  167. - use self-made FreeBSD 10.3 box, #3022
  168. - backport fs_init (including related updates) from 1.1
  169. - the boxcutter wheezy boxes are 404, use local ones
  170. - travis:
  171. - don't perform full Travis build on docs-only changes, #2531
  172. - only short-circuit docs-only changes for pull requests
  173. Version 1.0.11 (2017-07-21)
  174. ---------------------------
  175. Bug fixes:
  176. - use limited unpacker for outer key (security precaution), #2174
  177. - fix paperkey import bug
  178. Other changes:
  179. - change --checkpoint-interval default from 600s to 1800s, #2841.
  180. this improves efficiency for big repositories a lot.
  181. - docs: fix OpenSUSE command and add OpenSUSE section
  182. - tests: add tests for split_lstring and paperkey
  183. - vagrant:
  184. - fix openbsd shell
  185. - backport cpu/ram setup from master
  186. - add stretch64 VM
  187. Version 1.0.11rc1 (2017-06-27)
  188. ------------------------------
  189. Bug fixes:
  190. - performance: rebuild hashtable if we have too few empty buckets, #2246.
  191. this fixes some sporadic, but severe performance breakdowns.
  192. - Archive: allocate zeros when needed, #2308
  193. fixes huge memory usage of mount (8 MiB × number of archives)
  194. - IPv6 address support
  195. also: Location: more informative exception when parsing fails
  196. - borg single-file binary: use pyinstaller v3.2.1, #2396
  197. this fixes that the prelink cronjob on some distros kills the
  198. borg binary by stripping away parts of it.
  199. - extract:
  200. - warning for unextracted big extended attributes, #2258
  201. - also create parent dir for device files, if needed.
  202. - don't write to disk with --stdout, #2645
  203. - archive check: detect and fix missing all-zero replacement chunks, #2180
  204. - fix (de)compression exceptions, #2224 #2221
  205. - files cache: update inode number, #2226
  206. - borg rpc: use limited msgpack.Unpacker (security precaution), #2139
  207. - Manifest: use limited msgpack.Unpacker (security precaution), #2175
  208. - Location: accept //servername/share/path
  209. - fix ChunkIndex.__contains__ assertion for big-endian archs (harmless)
  210. - create: handle BackupOSError on a per-path level in one spot
  211. - fix error msg, there is no --keep-last in borg 1.0.x, #2282
  212. - clamp (nano)second values to unproblematic range, #2304
  213. - fuse / borg mount:
  214. - fix st_blocks to be an integer (not float) value
  215. - fix negative uid/gid crash (they could come into archives e.g. when
  216. backing up external drives under cygwin), #2674
  217. - fix crash if empty (None) xattr is read
  218. - do pre-mount checks before opening repository
  219. - check llfuse is installed before asking for passphrase
  220. - borg rename: expand placeholders, #2386
  221. - borg serve: fix forced command lines containing BORG_ env vars
  222. - fix error msg, it is --keep-within, not --within
  223. - fix borg key/debug/benchmark crashing without subcommand, #2240
  224. - chunker: fix invalid use of types, don't do uint32_t >> 32
  225. - document follow_symlinks requirements, check libc, #2507
  226. New features:
  227. - added BORG_PASSCOMMAND environment variable, #2573
  228. - add minimal version of in repository mandatory feature flags, #2134
  229. This should allow us to make sure older borg versions can be cleanly
  230. prevented from doing operations that are no longer safe because of
  231. repository format evolution. This allows more fine grained control than
  232. just incrementing the manifest version. So for example a change that
  233. still allows new archives to be created but would corrupt the repository
  234. when an old version tries to delete an archive or check the repository
  235. would add the new feature to the check and delete set but leave it out
  236. of the write set.
  237. - borg delete --force --force to delete severely corrupted archives, #1975
  238. Other changes:
  239. - embrace y2038 issue to support 32bit platforms
  240. - be more clear that this is a "beyond repair" case, #2427
  241. - key file names: limit to 100 characters and remove colons from host name
  242. - upgrade FUSE for macOS to 3.5.8, #2346
  243. - split up parsing and filtering for --keep-within, better error message, #2610
  244. - docs:
  245. - fix caskroom link, #2299
  246. - address SSH batch mode, #2202 #2270
  247. - improve remote-path description
  248. - document snapshot usage, #2178
  249. - document relative path usage, #1868
  250. - one link per distro in the installation page
  251. - development: new branching model in git repository
  252. - kill api page
  253. - added FAQ section about backing up root partition
  254. - add bountysource badge, #2558
  255. - create empty docs.txt reequirements, #2694
  256. - README: how to help the project
  257. - note -v/--verbose requirement on affected options, #2542
  258. - document borg init behaviour via append-only borg serve, #2440
  259. - be clear about what buzhash is used for (chunking) and want it is not
  260. used for (deduplication)- also say already in the readme that we use a
  261. cryptohash for dedupe, so people don't worry, #2390
  262. - add hint about chunker params to borg upgrade docs, #2421
  263. - clarify borg upgrade docs, #2436
  264. - quickstart: delete problematic BORG_PASSPRHASE use, #2623
  265. - faq: specify "using inline shell scripts"
  266. - document pattern denial of service, #2624
  267. - tests:
  268. - remove attic dependency of the tests, #2505
  269. - travis:
  270. - enhance travis setuptools_scm situation
  271. - install fakeroot for Linux
  272. - add test for borg delete --force
  273. - enable remote tests on cygwin (the cygwin issue that caused these tests
  274. to break was fixed in cygwin at least since cygwin 2.8, maybe even since
  275. 2.7.0).
  276. - remove skipping the noatime tests on GNU/Hurd, #2710
  277. - fix borg import issue, add comment, #2718
  278. - include attic.tar.gz when installing the package
  279. also: add include_package_data=True
  280. Version 1.0.10 (2017-02-13)
  281. ---------------------------
  282. Bug fixes:
  283. - Manifest timestamps are now monotonically increasing,
  284. this fixes issues when the system clock jumps backwards
  285. or is set inconsistently across computers accessing the same repository, #2115
  286. - Fixed testing regression in 1.0.10rc1 that lead to a hard dependency on
  287. py.test >= 3.0, #2112
  288. New features:
  289. - "key export" can now generate a printable HTML page with both a QR code and
  290. a human-readable "paperkey" representation (and custom text) through the
  291. ``--qr-html`` option.
  292. The same functionality is also available through `paperkey.html <paperkey.html>`_,
  293. which is the same HTML page generated by ``--qr-html``. It works with existing
  294. "key export" files and key files.
  295. Other changes:
  296. - docs:
  297. - language clarification - "borg create --one-file-system" option does not respect
  298. mount points, but considers different file systems instead, #2141
  299. - setup.py: build_api: sort file list for determinism
  300. Version 1.0.10rc1 (2017-01-29)
  301. ------------------------------
  302. Bug fixes:
  303. - borg serve: fix transmission data loss of pipe writes, #1268
  304. This affects only the cygwin platform (not Linux, BSD, OS X).
  305. - Avoid triggering an ObjectiveFS bug in xattr retrieval, #1992
  306. - When running out of buffer memory when reading xattrs, only skip the
  307. current file, #1993
  308. - Fixed "borg upgrade --tam" crashing with unencrypted repositories. Since
  309. :ref:`the issue <tam_vuln>` is not relevant for unencrypted repositories,
  310. it now does nothing and prints an error, #1981.
  311. - Fixed change-passphrase crashing with unencrypted repositories, #1978
  312. - Fixed "borg check repo::archive" indicating success if "archive" does not exist, #1997
  313. - borg check: print non-exit-code warning if --last or --prefix aren't fulfilled
  314. - fix bad parsing of wrong repo location syntax
  315. - create: don't create hard link refs to failed files,
  316. mount: handle invalid hard link refs, #2092
  317. - detect mingw byte order, #2073
  318. - creating a new segment: use "xb" mode, #2099
  319. - mount: umount on SIGINT/^C when in foreground, #2082
  320. Other changes:
  321. - binary: use fixed AND freshly compiled pyinstaller bootloader, #2002
  322. - xattr: ignore empty names returned by llistxattr(2) et al
  323. - Enable the fault handler: install handlers for the SIGSEGV, SIGFPE, SIGABRT,
  324. SIGBUS and SIGILL signals to dump the Python traceback.
  325. - Also print a traceback on SIGUSR2.
  326. - borg change-passphrase: print key location (simplify making a backup of it)
  327. - officially support Python 3.6 (setup.py: add Python 3.6 qualifier)
  328. - tests:
  329. - vagrant / travis / tox: add Python 3.6 based testing
  330. - vagrant: fix openbsd repo, #2042
  331. - vagrant: fix the freebsd64 machine, #2037 #2067
  332. - vagrant: use python 3.5.3 to build binaries, #2078
  333. - vagrant: use osxfuse 3.5.4 for tests / to build binaries
  334. vagrant: improve darwin64 VM settings
  335. - travis: fix osxfuse install (fixes OS X testing on Travis CI)
  336. - travis: require succeeding OS X tests, #2028
  337. - travis: use latest pythons for OS X based testing
  338. - use pytest-xdist to parallelize testing
  339. - fix xattr test race condition, #2047
  340. - setup.cfg: fix pytest deprecation warning, #2050
  341. - docs:
  342. - language clarification - VM backup FAQ
  343. - borg create: document how to backup stdin, #2013
  344. - borg upgrade: fix incorrect title levels
  345. - add CVE numbers for issues fixed in 1.0.9, #2106
  346. - fix typos (taken from Debian package patch)
  347. - remote: include data hexdump in "unexpected RPC data" error message
  348. - remote: log SSH command line at debug level
  349. - API_VERSION: use numberspaces, #2023
  350. - remove .github from pypi package, #2051
  351. - add pip and setuptools to requirements file, #2030
  352. - SyncFile: fix use of fd object after close (cosmetic)
  353. - Manifest.in: simplify, exclude \*.{so,dll,orig}, #2066
  354. - ignore posix_fadvise errors in repository.py, #2095
  355. (works around issues with docker on ARM)
  356. - make LoggedIO.close_segment reentrant, avoid reentrance
  357. Version 1.0.9 (2016-12-20)
  358. --------------------------
  359. Security fixes:
  360. - A flaw in the cryptographic authentication scheme in Borg allowed an attacker
  361. to spoof the manifest. See :ref:`tam_vuln` above for the steps you should
  362. take.
  363. CVE-2016-10099 was assigned to this vulnerability.
  364. - borg check: When rebuilding the manifest (which should only be needed very rarely)
  365. duplicate archive names would be handled on a "first come first serve" basis, allowing
  366. an attacker to apparently replace archives.
  367. CVE-2016-10100 was assigned to this vulnerability.
  368. Bug fixes:
  369. - borg check:
  370. - rebuild manifest if it's corrupted
  371. - skip corrupted chunks during manifest rebuild
  372. - fix TypeError in integrity error handler, #1903, #1894
  373. - fix location parser for archives with @ char (regression introduced in 1.0.8), #1930
  374. - fix wrong duration/timestamps if system clock jumped during a create
  375. - fix progress display not updating if system clock jumps backwards
  376. - fix checkpoint interval being incorrect if system clock jumps
  377. Other changes:
  378. - docs:
  379. - add python3-devel as a dependency for cygwin-based installation
  380. - clarify extract is relative to current directory
  381. - FAQ: fix link to changelog
  382. - markup fixes
  383. - tests:
  384. - test_get\_(cache|keys)_dir: clean env state, #1897
  385. - get back pytest's pretty assertion failures, #1938
  386. - setup.py build_usage:
  387. - fixed build_usage not processing all commands
  388. - fixed build_usage not generating includes for debug commands
  389. Version 1.0.9rc1 (2016-11-27)
  390. -----------------------------
  391. Bug fixes:
  392. - files cache: fix determination of newest mtime in backup set (which is
  393. used in cache cleanup and led to wrong "A" [added] status for unchanged
  394. files in next backup), #1860.
  395. - borg check:
  396. - fix incorrectly reporting attic 0.13 and earlier archives as corrupt
  397. - handle repo w/o objects gracefully and also bail out early if repo is
  398. *completely* empty, #1815.
  399. - fix tox/pybuild in 1.0-maint
  400. - at xattr module import time, loggers are not initialized yet
  401. New features:
  402. - borg umount <mountpoint>
  403. exposed already existing umount code via the CLI api, so users can use it,
  404. which is more consistent than using borg to mount and fusermount -u (or
  405. umount) to un-mount, #1855.
  406. - implement borg create --noatime --noctime, fixes #1853
  407. Other changes:
  408. - docs:
  409. - display README correctly on PyPI
  410. - improve cache / index docs, esp. files cache docs, fixes #1825
  411. - different pattern matching for --exclude, #1779
  412. - datetime formatting examples for {now} placeholder, #1822
  413. - clarify passphrase mode attic repo upgrade, #1854
  414. - clarify --umask usage, #1859
  415. - clarify how to choose PR target branch
  416. - clarify prune behavior for different archive contents, #1824
  417. - fix PDF issues, add logo, fix authors, headings, TOC
  418. - move security verification to support section
  419. - fix links in standalone README (:ref: tags)
  420. - add link to security contact in README
  421. - add FAQ about security
  422. - move fork differences to FAQ
  423. - add more details about resource usage
  424. - tests: skip remote tests on cygwin, #1268
  425. - travis:
  426. - allow OS X failures until the brew cask osxfuse issue is fixed
  427. - caskroom osxfuse-beta gone, it's osxfuse now (3.5.3)
  428. - vagrant:
  429. - upgrade OSXfuse / FUSE for macOS to 3.5.3
  430. - remove llfuse from tox.ini at a central place
  431. - do not try to install llfuse on centos6
  432. - fix fuse test for darwin, #1546
  433. - add windows virtual machine with cygwin
  434. - Vagrantfile cleanup / code deduplication
  435. Version 1.0.8 (2016-10-29)
  436. --------------------------
  437. Bug fixes:
  438. - RemoteRepository: Fix busy wait in call_many, #940
  439. New features:
  440. - implement borgmajor/borgminor/borgpatch placeholders, #1694
  441. {borgversion} was already there (full version string). With the new
  442. placeholders you can now also get e.g. 1 or 1.0 or 1.0.8.
  443. Other changes:
  444. - avoid previous_location mismatch, #1741
  445. due to the changed canonicalization for relative pathes in PR #1711 / #1655
  446. (implement /./ relpath hack), there would be a changed repo location warning
  447. and the user would be asked if this is ok. this would break automation and
  448. require manual intervention, which is unwanted.
  449. thus, we automatically fix the previous_location config entry, if it only
  450. changed in the expected way, but still means the same location.
  451. - docs:
  452. - deployment.rst: do not use bare variables in ansible snippet
  453. - add clarification about append-only mode, #1689
  454. - setup.py: add comment about requiring llfuse, #1726
  455. - update usage.rst / api.rst
  456. - repo url / archive location docs + typo fix
  457. - quickstart: add a comment about other (remote) filesystems
  458. - vagrant / tests:
  459. - no chown when rsyncing (fixes boxes w/o vagrant group)
  460. - fix fuse permission issues on linux/freebsd, #1544
  461. - skip fuse test for borg binary + fakeroot
  462. - ignore security.selinux xattrs, fixes tests on centos, #1735
  463. Version 1.0.8rc1 (2016-10-17)
  464. -----------------------------
  465. Bug fixes:
  466. - fix signal handling (SIGINT, SIGTERM, SIGHUP), #1620 #1593
  467. Fixes e.g. leftover lock files for quickly repeated signals (e.g. Ctrl-C
  468. Ctrl-C) or lost connections or systemd sending SIGHUP.
  469. - progress display: adapt formatting to narrow screens, do not crash, #1628
  470. - borg create --read-special - fix crash on broken symlink, #1584.
  471. also correctly processes broken symlinks. before this regressed to a crash
  472. (5b45385) a broken symlink would've been skipped.
  473. - process_symlink: fix missing backup_io()
  474. Fixes a chmod/chown/chgrp/unlink/rename/... crash race between getting
  475. dirents and dispatching to process_symlink.
  476. - yes(): abort on wrong answers, saying so, #1622
  477. - fixed exception borg serve raised when connection was closed before reposiory
  478. was openend. add an error message for this.
  479. - fix read-from-closed-FD issue, #1551
  480. (this seems not to get triggered in 1.0.x, but was discovered in master)
  481. - hashindex: fix iterators (always raise StopIteration when exhausted)
  482. (this seems not to get triggered in 1.0.x, but was discovered in master)
  483. - enable relative pathes in ssh:// repo URLs, via /./relpath hack, #1655
  484. - allow repo pathes with colons, #1705
  485. - update changed repo location immediately after acceptance, #1524
  486. - fix debug get-obj / delete-obj crash if object not found and remote repo,
  487. #1684
  488. - pyinstaller: use a spec file to build borg.exe binary, exclude osxfuse dylib
  489. on Mac OS X (avoids mismatch lib <-> driver), #1619
  490. New features:
  491. - add "borg key export" / "borg key import" commands, #1555, so users are able
  492. to backup / restore their encryption keys more easily.
  493. Supported formats are the keyfile format used by borg internally and a
  494. special "paper" format with by line checksums for printed backups. For the
  495. paper format, the import is an interactive process which checks each line as
  496. soon as it is input.
  497. - add "borg debug-refcount-obj" to determine a repo objects' referrer counts,
  498. #1352
  499. Other changes:
  500. - add "borg debug ..." subcommands
  501. (borg debug-* still works, but will be removed in borg 1.1)
  502. - setup.py: Add subcommand support to build_usage.
  503. - remote: change exception message for unexpected RPC data format to indicate
  504. dataflow direction.
  505. - improved messages / error reporting:
  506. - IntegrityError: add placeholder for message, so that the message we give
  507. appears not only in the traceback, but also in the (short) error message,
  508. #1572
  509. - borg.key: include chunk id in exception msgs, #1571
  510. - better messages for cache newer than repo, #1700
  511. - vagrant (testing/build VMs):
  512. - upgrade OSXfuse / FUSE for macOS to 3.5.2
  513. - update Debian Wheezy boxes, #1686
  514. - openbsd / netbsd: use own boxes, fixes misc rsync installation and
  515. fuse/llfuse related testing issues, #1695 #1696 #1670 #1671 #1728
  516. - docs:
  517. - add docs for "key export" and "key import" commands, #1641
  518. - fix inconsistency in FAQ (pv-wrapper).
  519. - fix second block in "Easy to use" section not showing on GitHub, #1576
  520. - add bestpractices badge
  521. - link reference docs and faq about BORG_FILES_CACHE_TTL, #1561
  522. - improve borg info --help, explain size infos, #1532
  523. - add release signing key / security contact to README, #1560
  524. - add contribution guidelines for developers
  525. - development.rst: add sphinx_rtd_theme to the sphinx install command
  526. - adjust border color in borg.css
  527. - add debug-info usage help file
  528. - internals.rst: fix typos
  529. - setup.py: fix build_usage to always process all commands
  530. - added docs explaining multiple --restrict-to-path flags, #1602
  531. - add more specific warning about write-access debug commands, #1587
  532. - clarify FAQ regarding backup of virtual machines, #1672
  533. - tests:
  534. - work around fuse xattr test issue with recent fakeroot
  535. - simplify repo/hashindex tests
  536. - travis: test fuse-enabled borg, use trusty to have a recent FUSE
  537. - re-enable fuse tests for RemoteArchiver (no deadlocks any more)
  538. - clean env for pytest based tests, #1714
  539. - fuse_mount contextmanager: accept any options
  540. Version 1.0.7 (2016-08-19)
  541. --------------------------
  542. Security fixes:
  543. - borg serve: fix security issue with remote repository access, #1428
  544. If you used e.g. --restrict-to-path /path/client1/ (with or without trailing
  545. slash does not make a difference), it acted like a path prefix match using
  546. /path/client1 (note the missing trailing slash) - the code then also allowed
  547. working in e.g. /path/client13 or /path/client1000.
  548. As this could accidentally lead to major security/privacy issues depending on
  549. the pathes you use, the behaviour was changed to be a strict directory match.
  550. That means --restrict-to-path /path/client1 (with or without trailing slash
  551. does not make a difference) now uses /path/client1/ internally (note the
  552. trailing slash here!) for matching and allows precisely that path AND any
  553. path below it. So, /path/client1 is allowed, /path/client1/repo1 is allowed,
  554. but not /path/client13 or /path/client1000.
  555. If you willingly used the undocumented (dangerous) previous behaviour, you
  556. may need to rearrange your --restrict-to-path pathes now. We are sorry if
  557. that causes work for you, but we did not want a potentially dangerous
  558. behaviour in the software (not even using a for-backwards-compat option).
  559. Bug fixes:
  560. - fixed repeated LockTimeout exceptions when borg serve tried to write into
  561. a already write-locked repo (e.g. by a borg mount), #502 part b)
  562. This was solved by the fix for #1220 in 1.0.7rc1 already.
  563. - fix cosmetics + file leftover for "not a valid borg repository", #1490
  564. - Cache: release lock if cache is invalid, #1501
  565. - borg extract --strip-components: fix leak of preloaded chunk contents
  566. - Repository, when a InvalidRepository exception happens:
  567. - fix spurious, empty lock.roster
  568. - fix repo not closed cleanly
  569. New features:
  570. - implement borg debug-info, fixes #1122
  571. (just calls already existing code via cli, same output as below tracebacks)
  572. Other changes:
  573. - skip the O_NOATIME test on GNU Hurd, fixes #1315
  574. (this is a very minor issue and the GNU Hurd project knows the bug)
  575. - document using a clean repo to test / build the release
  576. Version 1.0.7rc2 (2016-08-13)
  577. -----------------------------
  578. Bug fixes:
  579. - do not write objects to repository that are bigger than the allowed size,
  580. borg will reject reading them, #1451.
  581. Important: if you created archives with many millions of files or
  582. directories, please verify if you can open them successfully,
  583. e.g. try a "borg list REPO::ARCHIVE".
  584. - lz4 compression: dynamically enlarge the (de)compression buffer, the static
  585. buffer was not big enough for archives with extremely many items, #1453
  586. - larger item metadata stream chunks, raise archive item limit by 8x, #1452
  587. - fix untracked segments made by moved DELETEs, #1442
  588. Impact: Previously (metadata) segments could become untracked when deleting data,
  589. these would never be cleaned up.
  590. - extended attributes (xattrs) related fixes:
  591. - fixed a race condition in xattrs querying that led to the entire file not
  592. being backed up (while logging the error, exit code = 1), #1469
  593. - fixed a race condition in xattrs querying that led to a crash, #1462
  594. - raise OSError including the error message derived from errno, deal with
  595. path being a integer FD
  596. Other changes:
  597. - print active env var override by default, #1467
  598. - xattr module: refactor code, deduplicate, clean up
  599. - repository: split object size check into too small and too big
  600. - add a transaction_id assertion, so borg init on a broken (inconsistent)
  601. filesystem does not look like a coding error in borg, but points to the
  602. real problem.
  603. - explain confusing TypeError caused by compat support for old servers, #1456
  604. - add forgotten usage help file from build_usage
  605. - refactor/unify buffer code into helpers.Buffer class, add tests
  606. - docs:
  607. - document archive limitation, #1452
  608. - improve prune examples
  609. Version 1.0.7rc1 (2016-08-05)
  610. -----------------------------
  611. Bug fixes:
  612. - fix repo lock deadlocks (related to lock upgrade), #1220
  613. - catch unpacker exceptions, resync, #1351
  614. - fix borg break-lock ignoring BORG_REPO env var, #1324
  615. - files cache performance fixes (fixes unneccessary re-reading/chunking/
  616. hashing of unmodified files for some use cases):
  617. - fix unintended file cache eviction, #1430
  618. - implement BORG_FILES_CACHE_TTL, update FAQ, raise default TTL from 10
  619. to 20, #1338
  620. - FUSE:
  621. - cache partially read data chunks (performance), #965, #966
  622. - always create a root dir, #1125
  623. - use an OrderedDict for helptext, making the build reproducible, #1346
  624. - RemoteRepository init: always call close on exceptions, #1370 (cosmetic)
  625. - ignore stdout/stderr broken pipe errors (cosmetic), #1116
  626. New features:
  627. - better borg versions management support (useful esp. for borg servers
  628. wanting to offer multiple borg versions and for clients wanting to choose
  629. a specific server borg version), #1392:
  630. - add BORG_VERSION environment variable before executing "borg serve" via ssh
  631. - add new placeholder {borgversion}
  632. - substitute placeholders in --remote-path
  633. - borg init --append-only option (makes using the more secure append-only mode
  634. more convenient. when used remotely, this requires 1.0.7+ also on the borg
  635. server), #1291.
  636. Other changes:
  637. - Vagrantfile:
  638. - darwin64: upgrade to FUSE for macOS 3.4.1 (aka osxfuse), #1378
  639. - xenial64: use user "ubuntu", not "vagrant" (as usual), #1331
  640. - tests:
  641. - fix fuse tests on OS X, #1433
  642. - docs:
  643. - FAQ: add backup using stable filesystem names recommendation
  644. - FAQ about glibc compatibility added, #491, glibc-check improved
  645. - FAQ: 'A' unchanged file; remove ambiguous entry age sentence.
  646. - OS X: install pkg-config to build with FUSE support, fixes #1400
  647. - add notes about shell/sudo pitfalls with env. vars, #1380
  648. - added platform feature matrix
  649. - implement borg debug-dump-repo-objs
  650. Version 1.0.6 (2016-07-12)
  651. --------------------------
  652. Bug fixes:
  653. - Linux: handle multiple LD_PRELOAD entries correctly, #1314, #1111
  654. - Fix crash with unclear message if the libc is not found, #1314, #1111
  655. Other changes:
  656. - tests:
  657. - Fixed O_NOATIME tests for Solaris and GNU Hurd, #1315
  658. - Fixed sparse file tests for (file) systems not supporting it, #1310
  659. - docs:
  660. - Fixed syntax highlighting, #1313
  661. - misc docs: added data processing overview picture
  662. Version 1.0.6rc1 (2016-07-10)
  663. -----------------------------
  664. New features:
  665. - borg check --repair: heal damaged files if missing chunks re-appear (e.g. if
  666. the previously missing chunk was added again in a later backup archive),
  667. #148. (*) Also improved logging.
  668. Bug fixes:
  669. - sync_dir: silence fsync() failing with EINVAL, #1287
  670. Some network filesystems (like smbfs) don't support this and we use this in
  671. repository code.
  672. - borg mount (FUSE):
  673. - fix directories being shadowed when contained paths were also specified,
  674. #1295
  675. - raise I/O Error (EIO) on damaged files (unless -o allow_damaged_files is
  676. used), #1302. (*)
  677. - borg extract: warn if a damaged file is extracted, #1299. (*)
  678. - Added some missing return code checks (ChunkIndex._add, hashindex_resize).
  679. - borg check: fix/optimize initial hash table size, avoids resize of the table.
  680. Other changes:
  681. - tests:
  682. - add more FUSE tests, #1284
  683. - deduplicate fuse (u)mount code
  684. - fix borg binary test issues, #862
  685. - docs:
  686. - changelog: added release dates to older borg releases
  687. - fix some sphinx (docs generator) warnings, #881
  688. Notes:
  689. (*) Some features depend on information (chunks_healthy list) added to item
  690. metadata when a file with missing chunks was "repaired" using all-zero
  691. replacement chunks. The chunks_healthy list is generated since borg 1.0.4,
  692. thus borg can't recognize such "repaired" (but content-damaged) files if the
  693. repair was done with an older borg version.
  694. Version 1.0.5 (2016-07-07)
  695. --------------------------
  696. Bug fixes:
  697. - borg mount: fix FUSE crash in xattr code on Linux introduced in 1.0.4, #1282
  698. Other changes:
  699. - backport some FAQ entries from master branch
  700. - add release helper scripts
  701. - Vagrantfile:
  702. - centos6: no FUSE, don't build binary
  703. - add xz for redhat-like dists
  704. Version 1.0.4 (2016-07-07)
  705. --------------------------
  706. New features:
  707. - borg serve --append-only, #1168
  708. This was included because it was a simple change (append-only functionality
  709. was already present via repository config file) and makes better security now
  710. practically usable.
  711. - BORG_REMOTE_PATH environment variable, #1258
  712. This was included because it was a simple change (--remote-path cli option
  713. was already present) and makes borg much easier to use if you need it.
  714. - Repository: cleanup incomplete transaction on "no space left" condition.
  715. In many cases, this can avoid a 100% full repo filesystem (which is very
  716. problematic as borg always needs free space - even to delete archives).
  717. Bug fixes:
  718. - Fix wrong handling and reporting of OSErrors in borg create, #1138.
  719. This was a serious issue: in the context of "borg create", errors like
  720. repository I/O errors (e.g. disk I/O errors, ssh repo connection errors)
  721. were handled badly and did not lead to a crash (which would be good for this
  722. case, because the repo transaction would be incomplete and trigger a
  723. transaction rollback to clean up).
  724. Now, error handling for source files is cleanly separated from every other
  725. error handling, so only problematic input files are logged and skipped.
  726. - Implement fail-safe error handling for borg extract.
  727. Note that this isn't nearly as critical as the borg create error handling
  728. bug, since nothing is written to the repo. So this was "merely" misleading
  729. error reporting.
  730. - Add missing error handler in directory attr restore loop.
  731. - repo: make sure write data hits disk before the commit tag (#1236) and also
  732. sync the containing directory.
  733. - FUSE: getxattr fail must use errno.ENOATTR, #1126
  734. (fixes Mac OS X Finder malfunction: "zero bytes" file length, access denied)
  735. - borg check --repair: do not lose information about the good/original chunks.
  736. If we do not lose the original chunk IDs list when "repairing" a file
  737. (replacing missing chunks with all-zero chunks), we have a chance to "heal"
  738. the file back into its original state later, in case the chunks re-appear
  739. (e.g. in a fresh backup). Healing is not implemented yet, see #148.
  740. - fixes for --read-special mode:
  741. - ignore known files cache, #1241
  742. - fake regular file mode, #1214
  743. - improve symlinks handling, #1215
  744. - remove passphrase from subprocess environment, #1105
  745. - Ignore empty index file (will trigger index rebuild), #1195
  746. - add missing placeholder support for --prefix, #1027
  747. - improve exception handling for placeholder replacement
  748. - catch and format exceptions in arg parsing
  749. - helpers: fix "undefined name 'e'" in exception handler
  750. - better error handling for missing repo manifest, #1043
  751. - borg delete:
  752. - make it possible to delete a repo without manifest
  753. - borg delete --forced allows to delete corrupted archives, #1139
  754. - borg check:
  755. - make borg check work for empty repo
  756. - fix resync and msgpacked item qualifier, #1135
  757. - rebuild_manifest: fix crash if 'name' or 'time' key were missing.
  758. - better validation of item metadata dicts, #1130
  759. - better validation of archive metadata dicts
  760. - close the repo on exit - even if rollback did not work, #1197.
  761. This is rather cosmetic, it avoids repo closing in the destructor.
  762. - tests:
  763. - fix sparse file test, #1170
  764. - flake8: ignore new F405, #1185
  765. - catch "invalid argument" on cygwin, #257
  766. - fix sparseness assertion in test prep, #1264
  767. Other changes:
  768. - make borg build/work on OpenSSL 1.0 and 1.1, #1187
  769. - docs / help:
  770. - fix / clarify prune help, #1143
  771. - fix "patterns" help formatting
  772. - add missing docs / help about placeholders
  773. - resources: rename atticmatic to borgmatic
  774. - document sshd settings, #545
  775. - more details about checkpoints, add split trick, #1171
  776. - support docs: add freenode web chat link, #1175
  777. - add prune visualization / example, #723
  778. - add note that Fnmatch is default, #1247
  779. - make clear that lzma levels > 6 are a waste of cpu cycles
  780. - add a "do not edit" note to auto-generated files, #1250
  781. - update cygwin installation docs
  782. - repository interoperability with borg master (1.1dev) branch:
  783. - borg check: read item metadata keys from manifest, #1147
  784. - read v2 hints files, #1235
  785. - fix hints file "unknown version" error handling bug
  786. - tests: add tests for format_line
  787. - llfuse: update version requirement for freebsd
  788. - Vagrantfile:
  789. - use openbsd 5.9, #716
  790. - do not install llfuse on netbsd (broken)
  791. - update OSXfuse to version 3.3.3
  792. - use Python 3.5.2 to build the binaries
  793. - glibc compatibility checker: scripts/glibc_check.py
  794. - add .eggs to .gitignore
  795. Version 1.0.3 (2016-05-20)
  796. --------------------------
  797. Bug fixes:
  798. - prune: avoid that checkpoints are kept and completed archives are deleted in
  799. a prune run), #997
  800. - prune: fix commandline argument validation - some valid command lines were
  801. considered invalid (annoying, but harmless), #942
  802. - fix capabilities extraction on Linux (set xattrs last, after chown()), #1069
  803. - repository: fix commit tags being seen in data
  804. - when probing key files, do binary reads. avoids crash when non-borg binary
  805. files are located in borg's key files directory.
  806. - handle SIGTERM and make a clean exit - avoids orphan lock files.
  807. - repository cache: don't cache large objects (avoid using lots of temp. disk
  808. space), #1063
  809. Other changes:
  810. - Vagrantfile: OS X: update osxfuse / install lzma package, #933
  811. - setup.py: add check for platform_darwin.c
  812. - setup.py: on freebsd, use a llfuse release that builds ok
  813. - docs / help:
  814. - update readthedocs URLs, #991
  815. - add missing docs for "borg break-lock", #992
  816. - borg create help: add some words to about the archive name
  817. - borg create help: document format tags, #894
  818. Version 1.0.2 (2016-04-16)
  819. --------------------------
  820. Bug fixes:
  821. - fix malfunction and potential corruption on (nowadays rather rare) big-endian
  822. architectures or bi-endian archs in (rare) BE mode. #886, #889
  823. cache resync / index merge was malfunctioning due to this, potentially
  824. leading to data loss. borg info had cosmetic issues (displayed wrong values).
  825. note: all (widespread) little-endian archs (like x86/x64) or bi-endian archs
  826. in (widespread) LE mode (like ARMEL, MIPSEL, ...) were NOT affected.
  827. - add overflow and range checks for 1st (special) uint32 of the hashindex
  828. values, switch from int32 to uint32.
  829. - fix so that refcount will never overflow, but just stick to max. value after
  830. a overflow would have occured.
  831. - borg delete: fix --cache-only for broken caches, #874
  832. Makes --cache-only idempotent: it won't fail if the cache is already deleted.
  833. - fixed borg create --one-file-system erroneously traversing into other
  834. filesystems (if starting fs device number was 0), #873
  835. - workround a bug in Linux fadvise FADV_DONTNEED, #907
  836. Other changes:
  837. - better test coverage for hashindex, incl. overflow testing, checking correct
  838. computations so endianness issues would be discovered.
  839. - reproducible doc for ProgressIndicator*, make the build reproducible.
  840. - use latest llfuse for vagrant machines
  841. - docs:
  842. - use /path/to/repo in examples, fixes #901
  843. - fix confusing usage of "repo" as archive name (use "arch")
  844. Version 1.0.1 (2016-04-08)
  845. --------------------------
  846. New features:
  847. Usually there are no new features in a bugfix release, but these were added
  848. due to their high impact on security/safety/speed or because they are fixes
  849. also:
  850. - append-only mode for repositories, #809, #36 (see docs)
  851. - borg create: add --ignore-inode option to make borg detect unmodified files
  852. even if your filesystem does not have stable inode numbers (like sshfs and
  853. possibly CIFS).
  854. - add options --warning, --error, --critical for missing log levels, #826.
  855. it's not recommended to suppress warnings or errors, but the user may decide
  856. this on his own.
  857. note: --warning is not given to borg serve so a <= 1.0.0 borg will still
  858. work as server (it is not needed as it is the default).
  859. do not use --error or --critical when using a <= 1.0.0 borg server.
  860. Bug fixes:
  861. - fix silently skipping EIO, #748
  862. - add context manager for Repository (avoid orphan repository locks), #285
  863. - do not sleep for >60s while waiting for lock, #773
  864. - unpack file stats before passing to FUSE
  865. - fix build on illumos
  866. - don't try to backup doors or event ports (Solaris and derivates)
  867. - remove useless/misleading libc version display, #738
  868. - test suite: reset exit code of persistent archiver, #844
  869. - RemoteRepository: clean up pipe if remote open() fails
  870. - Remote: don't print tracebacks for Error exceptions handled downstream, #792
  871. - if BORG_PASSPHRASE is present but wrong, don't prompt for password, but fail
  872. instead, #791
  873. - ArchiveChecker: move "orphaned objects check skipped" to INFO log level, #826
  874. - fix capitalization, add ellipses, change log level to debug for 2 messages,
  875. #798
  876. Other changes:
  877. - update llfuse requirement, llfuse 1.0 works
  878. - update OS / dist packages on build machines, #717
  879. - prefer showing --info over -v in usage help, #859
  880. - docs:
  881. - fix cygwin requirements (gcc-g++)
  882. - document how to debug / file filesystem issues, #664
  883. - fix reproducible build of api docs
  884. - RTD theme: CSS !important overwrite, #727
  885. - Document logo font. Recreate logo png. Remove GIMP logo file.
  886. Version 1.0.0 (2016-03-05)
  887. --------------------------
  888. The major release number change (0.x -> 1.x) indicates bigger incompatible
  889. changes, please read the compatibility notes, adapt / test your scripts and
  890. check your backup logs.
  891. Compatibility notes:
  892. - drop support for python 3.2 and 3.3, require 3.4 or 3.5, #221 #65 #490
  893. note: we provide binaries that include python 3.5.1 and everything else
  894. needed. they are an option in case you are stuck with < 3.4 otherwise.
  895. - change encryption to be on by default (using "repokey" mode)
  896. - moved keyfile keys from ~/.borg/keys to ~/.config/borg/keys,
  897. you can either move them manually or run "borg upgrade <REPO>"
  898. - remove support for --encryption=passphrase,
  899. use borg migrate-to-repokey to switch to repokey mode, #97
  900. - remove deprecated --compression <number>,
  901. use --compression zlib,<number> instead
  902. in case of 0, you could also use --compression none
  903. - remove deprecated --hourly/daily/weekly/monthly/yearly
  904. use --keep-hourly/daily/weekly/monthly/yearly instead
  905. - remove deprecated --do-not-cross-mountpoints,
  906. use --one-file-system instead
  907. - disambiguate -p option, #563:
  908. - -p now is same as --progress
  909. - -P now is same as --prefix
  910. - remove deprecated "borg verify",
  911. use "borg extract --dry-run" instead
  912. - cleanup environment variable semantics, #355
  913. the environment variables used to be "yes sayers" when set, this was
  914. conceptually generalized to "automatic answerers" and they just give their
  915. value as answer (as if you typed in that value when being asked).
  916. See the "usage" / "Environment Variables" section of the docs for details.
  917. - change the builtin default for --chunker-params, create 2MiB chunks, #343
  918. --chunker-params new default: 19,23,21,4095 - old default: 10,23,16,4095
  919. one of the biggest issues with borg < 1.0 (and also attic) was that it had a
  920. default target chunk size of 64kiB, thus it created a lot of chunks and thus
  921. also a huge chunk management overhead (high RAM and disk usage).
  922. please note that the new default won't change the chunks that you already
  923. have in your repository. the new big chunks do not deduplicate with the old
  924. small chunks, so expect your repo to grow at least by the size of every
  925. changed file and in the worst case (e.g. if your files cache was lost / is
  926. not used) by the size of every file (minus any compression you might use).
  927. in case you want to immediately see a much lower resource usage (RAM / disk)
  928. for chunks management, it might be better to start with a new repo than
  929. continuing in the existing repo (with an existing repo, you'ld have to wait
  930. until all archives with small chunks got pruned to see a lower resource
  931. usage).
  932. if you used the old --chunker-params default value (or if you did not use
  933. --chunker-params option at all) and you'ld like to continue using small
  934. chunks (and you accept the huge resource usage that comes with that), just
  935. explicitly use borg create --chunker-params=10,23,16,4095.
  936. - archive timestamps: the 'time' timestamp now refers to archive creation
  937. start time (was: end time), the new 'time_end' timestamp refers to archive
  938. creation end time. This might affect prune if your backups take rather long.
  939. if you give a timestamp via cli this is stored into 'time', therefore it now
  940. needs to mean archive creation start time.
  941. New features:
  942. - implement password roundtrip, #695
  943. Bug fixes:
  944. - remote end does not need cache nor keys directories, do not create them, #701
  945. - added retry counter for passwords, #703
  946. Other changes:
  947. - fix compiler warnings, #697
  948. - docs:
  949. - update README.rst to new changelog location in docs/changes.rst
  950. - add Teemu to AUTHORS
  951. - changes.rst: fix old chunker params, #698
  952. - FAQ: how to limit bandwidth
  953. Version 1.0.0rc2 (2016-02-28)
  954. -----------------------------
  955. New features:
  956. - format options for location: user, pid, fqdn, hostname, now, utcnow, user
  957. - borg list --list-format
  958. - borg prune -v --list enables the keep/prune list output, #658
  959. Bug fixes:
  960. - fix _open_rb noatime handling, #657
  961. - add a simple archivename validator, #680
  962. - borg create --stats: show timestamps in localtime, use same labels/formatting
  963. as borg info, #651
  964. - llfuse compatibility fixes (now compatible with: 0.40, 0.41, 0.42)
  965. Other changes:
  966. - it is now possible to use "pip install borgbackup[fuse]" to automatically
  967. install the llfuse dependency using the correct version requirement
  968. for it. you still need to care about having installed the FUSE / build
  969. related OS package first, though, so that building llfuse can succeed.
  970. - Vagrant: drop Ubuntu Precise (12.04) - does not have Python >= 3.4
  971. - Vagrant: use pyinstaller v3.1.1 to build binaries
  972. - docs:
  973. - borg upgrade: add to docs that only LOCAL repos are supported
  974. - borg upgrade also handles borg 0.xx -> 1.0
  975. - use pip extras or requirements file to install llfuse
  976. - fix order in release process
  977. - updated usage docs and other minor / cosmetic fixes
  978. - verified borg examples in docs, #644
  979. - freebsd dependency installation and fuse configuration, #649
  980. - add example how to restore a raw device, #671
  981. - add a hint about the dev headers needed when installing from source
  982. - add examples for delete (and handle delete after list, before prune), #656
  983. - update example for borg create -v --stats (use iso datetime format), #663
  984. - added example to BORG_RSH docs
  985. - "connection closed by remote": add FAQ entry and point to issue #636
  986. Version 1.0.0rc1 (2016-02-07)
  987. -----------------------------
  988. New features:
  989. - borg migrate-to-repokey ("passphrase" -> "repokey" encryption key mode)
  990. - implement --short for borg list REPO, #611
  991. - implement --list for borg extract (consistency with borg create)
  992. - borg serve: overwrite client's --restrict-to-path with ssh forced command's
  993. option value (but keep everything else from the client commandline), #544
  994. - use $XDG_CONFIG_HOME/keys for keyfile keys (~/.config/borg/keys), #515
  995. - "borg upgrade" moves the keyfile keys to the new location
  996. - display both archive creation start and end time in "borg info", #627
  997. Bug fixes:
  998. - normalize trailing slashes for the repository path, #606
  999. - Cache: fix exception handling in __init__, release lock, #610
  1000. Other changes:
  1001. - suppress unneeded exception context (PEP 409), simpler tracebacks
  1002. - removed special code needed to deal with imperfections / incompatibilities /
  1003. missing stuff in py 3.2/3.3, simplify code that can be done simpler in 3.4
  1004. - removed some version requirements that were kept on old versions because
  1005. newer did not support py 3.2 any more
  1006. - use some py 3.4+ stdlib code instead of own/openssl/pypi code:
  1007. - use os.urandom instead of own cython openssl RAND_bytes wrapper, #493
  1008. - use hashlib.pbkdf2_hmac from py stdlib instead of own openssl wrapper
  1009. - use hmac.compare_digest instead of == operator (constant time comparison)
  1010. - use stat.filemode instead of homegrown code
  1011. - use "mock" library from stdlib, #145
  1012. - remove borg.support (with non-broken argparse copy), it is ok in 3.4+, #358
  1013. - Vagrant: copy CHANGES.rst as symlink, #592
  1014. - cosmetic code cleanups, add flake8 to tox/travis, #4
  1015. - docs / help:
  1016. - make "borg -h" output prettier, #591
  1017. - slightly rephrase prune help
  1018. - add missing example for --list option of borg create
  1019. - quote exclude line that includes an asterisk to prevent shell expansion
  1020. - fix dead link to license
  1021. - delete Ubuntu Vivid, it is not supported anymore (EOL)
  1022. - OS X binary does not work for older OS X releases, #629
  1023. - borg serve's special support for forced/original ssh commands, #544
  1024. - misc. updates and fixes
  1025. Version 0.30.0 (2016-01-23)
  1026. ---------------------------
  1027. Compatibility notes:
  1028. - you may need to use -v (or --info) more often to actually see output emitted
  1029. at INFO log level (because it is suppressed at the default WARNING log level).
  1030. See the "general" section in the usage docs.
  1031. - for borg create, you need --list (additionally to -v) to see the long file
  1032. list (was needed so you can have e.g. --stats alone without the long list)
  1033. - see below about BORG_DELETE_I_KNOW_WHAT_I_AM_DOING (was:
  1034. BORG_CHECK_I_KNOW_WHAT_I_AM_DOING)
  1035. Bug fixes:
  1036. - fix crash when using borg create --dry-run --keep-tag-files, #570
  1037. - make sure teardown with cleanup happens for Cache and RepositoryCache,
  1038. avoiding leftover locks and TEMP dir contents, #285 (partially), #548
  1039. - fix locking KeyError, partial fix for #502
  1040. - log stats consistently, #526
  1041. - add abbreviated weekday to timestamp format, fixes #496
  1042. - strip whitespace when loading exclusions from file
  1043. - unset LD_LIBRARY_PATH before invoking ssh, fixes strange OpenSSL library
  1044. version warning when using the borg binary, #514
  1045. - add some error handling/fallback for C library loading, #494
  1046. - added BORG_DELETE_I_KNOW_WHAT_I_AM_DOING for check in "borg delete", #503
  1047. - remove unused "repair" rpc method name
  1048. New features:
  1049. - borg create: implement exclusions using regular expression patterns.
  1050. - borg create: implement inclusions using patterns.
  1051. - borg extract: support patterns, #361
  1052. - support different styles for patterns:
  1053. - fnmatch (`fm:` prefix, default when omitted), like borg <= 0.29.
  1054. - shell (`sh:` prefix) with `*` not matching directory separators and
  1055. `**/` matching 0..n directories
  1056. - path prefix (`pp:` prefix, for unifying borg create pp1 pp2 into the
  1057. patterns system), semantics like in borg <= 0.29
  1058. - regular expression (`re:`), new!
  1059. - --progress option for borg upgrade (#291) and borg delete <archive>
  1060. - update progress indication more often (e.g. for borg create within big
  1061. files or for borg check repo), #500
  1062. - finer chunker granularity for items metadata stream, #547, #487
  1063. - borg create --list now used (additionally to -v) to enable the verbose
  1064. file list output
  1065. - display borg version below tracebacks, #532
  1066. Other changes:
  1067. - hashtable size (and thus: RAM and disk consumption) follows a growth policy:
  1068. grows fast while small, grows slower when getting bigger, #527
  1069. - Vagrantfile: use pyinstaller 3.1 to build binaries, freebsd sqlite3 fix,
  1070. fixes #569
  1071. - no separate binaries for centos6 any more because the generic linux binaries
  1072. also work on centos6 (or in general: on systems with a slightly older glibc
  1073. than debian7
  1074. - dev environment: require virtualenv<14.0 so we get a py32 compatible pip
  1075. - docs:
  1076. - add space-saving chunks.archive.d trick to FAQ
  1077. - important: clarify -v and log levels in usage -> general, please read!
  1078. - sphinx configuration: create a simple man page from usage docs
  1079. - add a repo server setup example
  1080. - disable unneeded SSH features in authorized_keys examples for security.
  1081. - borg prune only knows "--keep-within" and not "--within"
  1082. - add gource video to resources docs, #507
  1083. - add netbsd install instructions
  1084. - authors: make it more clear what refers to borg and what to attic
  1085. - document standalone binary requirements, #499
  1086. - rephrase the mailing list section
  1087. - development docs: run build_api and build_usage before tagging release
  1088. - internals docs: hash table max. load factor is 0.75 now
  1089. - markup, typo, grammar, phrasing, clarifications and other fixes.
  1090. - add gcc gcc-c++ to redhat/fedora/corora install docs, fixes #583
  1091. Version 0.29.0 (2015-12-13)
  1092. ---------------------------
  1093. Compatibility notes:
  1094. - when upgrading to 0.29.0 you need to upgrade client as well as server
  1095. installations due to the locking and commandline interface changes otherwise
  1096. you'll get an error msg about a RPC protocol mismatch or a wrong commandline
  1097. option.
  1098. if you run a server that needs to support both old and new clients, it is
  1099. suggested that you have a "borg-0.28.2" and a "borg-0.29.0" command.
  1100. clients then can choose via e.g. "borg --remote-path=borg-0.29.0 ...".
  1101. - the default waiting time for a lock changed from infinity to 1 second for a
  1102. better interactive user experience. if the repo you want to access is
  1103. currently locked, borg will now terminate after 1s with an error message.
  1104. if you have scripts that shall wait for the lock for a longer time, use
  1105. --lock-wait N (with N being the maximum wait time in seconds).
  1106. Bug fixes:
  1107. - hash table tuning (better chosen hashtable load factor 0.75 and prime initial
  1108. size of 1031 gave ~1000x speedup in some scenarios)
  1109. - avoid creation of an orphan lock for one case, #285
  1110. - --keep-tag-files: fix file mode and multiple tag files in one directory, #432
  1111. - fixes for "borg upgrade" (attic repo converter), #466
  1112. - remove --progress isatty magic (and also --no-progress option) again, #476
  1113. - borg init: display proper repo URL
  1114. - fix format of umask in help pages, #463
  1115. New features:
  1116. - implement --lock-wait, support timeout for UpgradableLock, #210
  1117. - implement borg break-lock command, #157
  1118. - include system info below traceback, #324
  1119. - sane remote logging, remote stderr, #461:
  1120. - remote log output: intercept it and log it via local logging system,
  1121. with "Remote: " prefixed to message. log remote tracebacks.
  1122. - remote stderr: output it to local stderr with "Remote: " prefixed.
  1123. - add --debug and --info (same as --verbose) to set the log level of the
  1124. builtin logging configuration (which otherwise defaults to warning), #426
  1125. note: there are few messages emitted at DEBUG level currently.
  1126. - optionally configure logging via env var BORG_LOGGING_CONF
  1127. - add --filter option for status characters: e.g. to show only the added
  1128. or modified files (and also errors), use "borg create -v --filter=AME ...".
  1129. - more progress indicators, #394
  1130. - use ISO-8601 date and time format, #375
  1131. - "borg check --prefix" to restrict archive checking to that name prefix, #206
  1132. Other changes:
  1133. - hashindex_add C implementation (speed up cache re-sync for new archives)
  1134. - increase FUSE read_size to 1024 (speed up metadata operations)
  1135. - check/delete/prune --save-space: free unused segments quickly, #239
  1136. - increase rpc protocol version to 2 (see also Compatibility notes), #458
  1137. - silence borg by default (via default log level WARNING)
  1138. - get rid of C compiler warnings, #391
  1139. - upgrade OS X FUSE to 3.0.9 on the OS X binary build system
  1140. - use python 3.5.1 to build binaries
  1141. - docs:
  1142. - new mailing list borgbackup@python.org, #468
  1143. - readthedocs: color and logo improvements
  1144. - load coverage icons over SSL (avoids mixed content)
  1145. - more precise binary installation steps
  1146. - update release procedure docs about OS X FUSE
  1147. - FAQ entry about unexpected 'A' status for unchanged file(s), #403
  1148. - add docs about 'E' file status
  1149. - add "borg upgrade" docs, #464
  1150. - add developer docs about output and logging
  1151. - clarify encryption, add note about client-side encryption
  1152. - add resources section, with videos, talks, presentations, #149
  1153. - Borg moved to Arch Linux [community]
  1154. - fix wrong installation instructions for archlinux
  1155. Version 0.28.2 (2015-11-15)
  1156. ---------------------------
  1157. New features:
  1158. - borg create --exclude-if-present TAGFILE - exclude directories that have the
  1159. given file from the backup. You can additionally give --keep-tag-files to
  1160. preserve just the directory roots and the tag-files (but not backup other
  1161. directory contents), #395, attic #128, attic #142
  1162. Other changes:
  1163. - do not create docs sources at build time (just have them in the repo),
  1164. completely remove have_cython() hack, do not use the "mock" library at build
  1165. time, #384
  1166. - avoid hidden import, make it easier for PyInstaller, easier fix for #218
  1167. - docs:
  1168. - add description of item flags / status output, fixes #402
  1169. - explain how to regenerate usage and API files (build_api or
  1170. build_usage) and when to commit usage files directly into git, #384
  1171. - minor install docs improvements
  1172. Version 0.28.1 (2015-11-08)
  1173. ---------------------------
  1174. Bug fixes:
  1175. - do not try to build api / usage docs for production install,
  1176. fixes unexpected "mock" build dependency, #384
  1177. Other changes:
  1178. - avoid using msgpack.packb at import time
  1179. - fix formatting issue in changes.rst
  1180. - fix build on readthedocs
  1181. Version 0.28.0 (2015-11-08)
  1182. ---------------------------
  1183. Compatibility notes:
  1184. - changed return codes (exit codes), see docs. in short:
  1185. old: 0 = ok, 1 = error. now: 0 = ok, 1 = warning, 2 = error
  1186. New features:
  1187. - refactor return codes (exit codes), fixes #61
  1188. - add --show-rc option enable "terminating with X status, rc N" output, fixes 58, #351
  1189. - borg create backups atime and ctime additionally to mtime, fixes #317
  1190. - extract: support atime additionally to mtime
  1191. - FUSE: support ctime and atime additionally to mtime
  1192. - support borg --version
  1193. - emit a warning if we have a slow msgpack installed
  1194. - borg list --prefix=thishostname- REPO, fixes #205
  1195. - Debug commands (do not use except if you know what you do: debug-get-obj,
  1196. debug-put-obj, debug-delete-obj, debug-dump-archive-items.
  1197. Bug fixes:
  1198. - setup.py: fix bug related to BORG_LZ4_PREFIX processing
  1199. - fix "check" for repos that have incomplete chunks, fixes #364
  1200. - borg mount: fix unlocking of repository at umount time, fixes #331
  1201. - fix reading files without touching their atime, #334
  1202. - non-ascii ACL fixes for Linux, FreeBSD and OS X, #277
  1203. - fix acl_use_local_uid_gid() and add a test for it, attic #359
  1204. - borg upgrade: do not upgrade repositories in place by default, #299
  1205. - fix cascading failure with the index conversion code, #269
  1206. - borg check: implement 'cmdline' archive metadata value decoding, #311
  1207. - fix RobustUnpacker, it missed some metadata keys (new atime and ctime keys
  1208. were missing, but also bsdflags). add check for unknown metadata keys.
  1209. - create from stdin: also save atime, ctime (cosmetic)
  1210. - use default_notty=False for confirmations, fixes #345
  1211. - vagrant: fix msgpack installation on centos, fixes #342
  1212. - deal with unicode errors for symlinks in same way as for regular files and
  1213. have a helpful warning message about how to fix wrong locale setup, fixes #382
  1214. - add ACL keys the RobustUnpacker must know about
  1215. Other changes:
  1216. - improve file size displays, more flexible size formatters
  1217. - explicitly commit to the units standard, #289
  1218. - archiver: add E status (means that an error occurred when processing this
  1219. (single) item
  1220. - do binary releases via "github releases", closes #214
  1221. - create: use -x and --one-file-system (was: --do-not-cross-mountpoints), #296
  1222. - a lot of changes related to using "logging" module and screen output, #233
  1223. - show progress display if on a tty, output more progress information, #303
  1224. - factor out status output so it is consistent, fix surrogates removal,
  1225. maybe fixes #309
  1226. - move away from RawConfigParser to ConfigParser
  1227. - archive checker: better error logging, give chunk_id and sequence numbers
  1228. (can be used together with borg debug-dump-archive-items).
  1229. - do not mention the deprecated passphrase mode
  1230. - emit a deprecation warning for --compression N (giving a just a number)
  1231. - misc .coverragerc fixes (and coverage measurement improvements), fixes #319
  1232. - refactor confirmation code, reduce code duplication, add tests
  1233. - prettier error messages, fixes #307, #57
  1234. - tests:
  1235. - add a test to find disk-full issues, #327
  1236. - travis: also run tests on Python 3.5
  1237. - travis: use tox -r so it rebuilds the tox environments
  1238. - test the generated pyinstaller-based binary by archiver unit tests, #215
  1239. - vagrant: tests: announce whether fakeroot is used or not
  1240. - vagrant: add vagrant user to fuse group for debianoid systems also
  1241. - vagrant: llfuse install on darwin needs pkgconfig installed
  1242. - vagrant: use pyinstaller from develop branch, fixes #336
  1243. - benchmarks: test create, extract, list, delete, info, check, help, fixes #146
  1244. - benchmarks: test with both the binary and the python code
  1245. - archiver tests: test with both the binary and the python code, fixes #215
  1246. - make basic test more robust
  1247. - docs:
  1248. - moved docs to borgbackup.readthedocs.org, #155
  1249. - a lot of fixes and improvements, use mobile-friendly RTD standard theme
  1250. - use zlib,6 compression in some examples, fixes #275
  1251. - add missing rename usage to docs, closes #279
  1252. - include the help offered by borg help <topic> in the usage docs, fixes #293
  1253. - include a list of major changes compared to attic into README, fixes #224
  1254. - add OS X install instructions, #197
  1255. - more details about the release process, #260
  1256. - fix linux glibc requirement (binaries built on debian7 now)
  1257. - build: move usage and API generation to setup.py
  1258. - update docs about return codes, #61
  1259. - remove api docs (too much breakage on rtd)
  1260. - borgbackup install + basics presentation (asciinema)
  1261. - describe the current style guide in documentation
  1262. - add section about debug commands
  1263. - warn about not running out of space
  1264. - add example for rename
  1265. - improve chunker params docs, fixes #362
  1266. - minor development docs update
  1267. Version 0.27.0 (2015-10-07)
  1268. ---------------------------
  1269. New features:
  1270. - "borg upgrade" command - attic -> borg one time converter / migration, #21
  1271. - temporary hack to avoid using lots of disk space for chunks.archive.d, #235:
  1272. To use it: rm -rf chunks.archive.d ; touch chunks.archive.d
  1273. - respect XDG_CACHE_HOME, attic #181
  1274. - add support for arbitrary SSH commands, attic #99
  1275. - borg delete --cache-only REPO (only delete cache, not REPO), attic #123
  1276. Bug fixes:
  1277. - use Debian 7 (wheezy) to build pyinstaller borgbackup binaries, fixes slow
  1278. down observed when running the Centos6-built binary on Ubuntu, #222
  1279. - do not crash on empty lock.roster, fixes #232
  1280. - fix multiple issues with the cache config version check, #234
  1281. - fix segment entry header size check, attic #352
  1282. plus other error handling improvements / code deduplication there.
  1283. - always give segment and offset in repo IntegrityErrors
  1284. Other changes:
  1285. - stop producing binary wheels, remove docs about it, #147
  1286. - docs:
  1287. - add warning about prune
  1288. - generate usage include files only as needed
  1289. - development docs: add Vagrant section
  1290. - update / improve / reformat FAQ
  1291. - hint to single-file pyinstaller binaries from README
  1292. Version 0.26.1 (2015-09-28)
  1293. ---------------------------
  1294. This is a minor update, just docs and new pyinstaller binaries.
  1295. - docs update about python and binary requirements
  1296. - better docs for --read-special, fix #220
  1297. - re-built the binaries, fix #218 and #213 (glibc version issue)
  1298. - update web site about single-file pyinstaller binaries
  1299. Note: if you did a python-based installation, there is no need to upgrade.
  1300. Version 0.26.0 (2015-09-19)
  1301. ---------------------------
  1302. New features:
  1303. - Faster cache sync (do all in one pass, remove tar/compression stuff), #163
  1304. - BORG_REPO env var to specify the default repo, #168
  1305. - read special files as if they were regular files, #79
  1306. - implement borg create --dry-run, attic issue #267
  1307. - Normalize paths before pattern matching on OS X, #143
  1308. - support OpenBSD and NetBSD (except xattrs/ACLs)
  1309. - support / run tests on Python 3.5
  1310. Bug fixes:
  1311. - borg mount repo: use absolute path, attic #200, attic #137
  1312. - chunker: use off_t to get 64bit on 32bit platform, #178
  1313. - initialize chunker fd to -1, so it's not equal to STDIN_FILENO (0)
  1314. - fix reaction to "no" answer at delete repo prompt, #182
  1315. - setup.py: detect lz4.h header file location
  1316. - to support python < 3.2.4, add less buggy argparse lib from 3.2.6 (#194)
  1317. - fix for obtaining ``char *`` from temporary Python value (old code causes
  1318. a compile error on Mint 17.2)
  1319. - llfuse 0.41 install troubles on some platforms, require < 0.41
  1320. (UnicodeDecodeError exception due to non-ascii llfuse setup.py)
  1321. - cython code: add some int types to get rid of unspecific python add /
  1322. subtract operations (avoid ``undefined symbol FPE_``... error on some platforms)
  1323. - fix verbose mode display of stdin backup
  1324. - extract: warn if a include pattern never matched, fixes #209,
  1325. implement counters for Include/ExcludePatterns
  1326. - archive names with slashes are invalid, attic issue #180
  1327. - chunker: add a check whether the POSIX_FADV_DONTNEED constant is defined -
  1328. fixes building on OpenBSD.
  1329. Other changes:
  1330. - detect inconsistency / corruption / hash collision, #170
  1331. - replace versioneer with setuptools_scm, #106
  1332. - docs:
  1333. - pkg-config is needed for llfuse installation
  1334. - be more clear about pruning, attic issue #132
  1335. - unit tests:
  1336. - xattr: ignore security.selinux attribute showing up
  1337. - ext3 seems to need a bit more space for a sparse file
  1338. - do not test lzma level 9 compression (avoid MemoryError)
  1339. - work around strange mtime granularity issue on netbsd, fixes #204
  1340. - ignore st_rdev if file is not a block/char device, fixes #203
  1341. - stay away from the setgid and sticky mode bits
  1342. - use Vagrant to do easy cross-platform testing (#196), currently:
  1343. - Debian 7 "wheezy" 32bit, Debian 8 "jessie" 64bit
  1344. - Ubuntu 12.04 32bit, Ubuntu 14.04 64bit
  1345. - Centos 7 64bit
  1346. - FreeBSD 10.2 64bit
  1347. - OpenBSD 5.7 64bit
  1348. - NetBSD 6.1.5 64bit
  1349. - Darwin (OS X Yosemite)
  1350. Version 0.25.0 (2015-08-29)
  1351. ---------------------------
  1352. Compatibility notes:
  1353. - lz4 compression library (liblz4) is a new requirement (#156)
  1354. - the new compression code is very compatible: as long as you stay with zlib
  1355. compression, older borg releases will still be able to read data from a
  1356. repo/archive made with the new code (note: this is not the case for the
  1357. default "none" compression, use "zlib,0" if you want a "no compression" mode
  1358. that can be read by older borg). Also the new code is able to read repos and
  1359. archives made with older borg versions (for all zlib levels 0..9).
  1360. Deprecations:
  1361. - --compression N (with N being a number, as in 0.24) is deprecated.
  1362. We keep the --compression 0..9 for now to not break scripts, but it is
  1363. deprecated and will be removed later, so better fix your scripts now:
  1364. --compression 0 (as in 0.24) is the same as --compression zlib,0 (now).
  1365. BUT: if you do not want compression, you rather want --compression none
  1366. (which is the default).
  1367. --compression 1 (in 0.24) is the same as --compression zlib,1 (now)
  1368. --compression 9 (in 0.24) is the same as --compression zlib,9 (now)
  1369. New features:
  1370. - create --compression none (default, means: do not compress, just pass through
  1371. data "as is". this is more efficient than zlib level 0 as used in borg 0.24)
  1372. - create --compression lz4 (super-fast, but not very high compression)
  1373. - create --compression zlib,N (slower, higher compression, default for N is 6)
  1374. - create --compression lzma,N (slowest, highest compression, default N is 6)
  1375. - honor the nodump flag (UF_NODUMP) and do not backup such items
  1376. - list --short just outputs a simple list of the files/directories in an archive
  1377. Bug fixes:
  1378. - fixed --chunker-params parameter order confusion / malfunction, fixes #154
  1379. - close fds of segments we delete (during compaction)
  1380. - close files which fell out the lrucache
  1381. - fadvise DONTNEED now is only called for the byte range actually read, not for
  1382. the whole file, fixes #158.
  1383. - fix issue with negative "all archives" size, fixes #165
  1384. - restore_xattrs: ignore if setxattr fails with EACCES, fixes #162
  1385. Other changes:
  1386. - remove fakeroot requirement for tests, tests run faster without fakeroot
  1387. (test setup does not fail any more without fakeroot, so you can run with or
  1388. without fakeroot), fixes #151 and #91.
  1389. - more tests for archiver
  1390. - recover_segment(): don't assume we have an fd for segment
  1391. - lrucache refactoring / cleanup, add dispose function, py.test tests
  1392. - generalize hashindex code for any key length (less hardcoding)
  1393. - lock roster: catch file not found in remove() method and ignore it
  1394. - travis CI: use requirements file
  1395. - improved docs:
  1396. - replace hack for llfuse with proper solution (install libfuse-dev)
  1397. - update docs about compression
  1398. - update development docs about fakeroot
  1399. - internals: add some words about lock files / locking system
  1400. - support: mention BountySource and for what it can be used
  1401. - theme: use a lighter green
  1402. - add pypi, wheel, dist package based install docs
  1403. - split install docs into system-specific preparations and generic instructions
  1404. Version 0.24.0 (2015-08-09)
  1405. ---------------------------
  1406. Incompatible changes (compared to 0.23):
  1407. - borg now always issues --umask NNN option when invoking another borg via ssh
  1408. on the repository server. By that, it's making sure it uses the same umask
  1409. for remote repos as for local ones. Because of this, you must upgrade both
  1410. server and client(s) to 0.24.
  1411. - the default umask is 077 now (if you do not specify via --umask) which might
  1412. be a different one as you used previously. The default umask avoids that
  1413. you accidentally give access permissions for group and/or others to files
  1414. created by borg (e.g. the repository).
  1415. Deprecations:
  1416. - "--encryption passphrase" mode is deprecated, see #85 and #97.
  1417. See the new "--encryption repokey" mode for a replacement.
  1418. New features:
  1419. - borg create --chunker-params ... to configure the chunker, fixes #16
  1420. (attic #302, attic #300, and somehow also #41).
  1421. This can be used to reduce memory usage caused by chunk management overhead,
  1422. so borg does not create a huge chunks index/repo index and eats all your RAM
  1423. if you back up lots of data in huge files (like VM disk images).
  1424. See docs/misc/create_chunker-params.txt for more information.
  1425. - borg info now reports chunk counts in the chunk index.
  1426. - borg create --compression 0..9 to select zlib compression level, fixes #66
  1427. (attic #295).
  1428. - borg init --encryption repokey (to store the encryption key into the repo),
  1429. fixes #85
  1430. - improve at-end error logging, always log exceptions and set exit_code=1
  1431. - LoggedIO: better error checks / exceptions / exception handling
  1432. - implement --remote-path to allow non-default-path borg locations, #125
  1433. - implement --umask M and use 077 as default umask for better security, #117
  1434. - borg check: give a named single archive to it, fixes #139
  1435. - cache sync: show progress indication
  1436. - cache sync: reimplement the chunk index merging in C
  1437. Bug fixes:
  1438. - fix segfault that happened for unreadable files (chunker: n needs to be a
  1439. signed size_t), #116
  1440. - fix the repair mode, #144
  1441. - repo delete: add destroy to allowed rpc methods, fixes issue #114
  1442. - more compatible repository locking code (based on mkdir), maybe fixes #92
  1443. (attic #317, attic #201).
  1444. - better Exception msg if no Borg is installed on the remote repo server, #56
  1445. - create a RepositoryCache implementation that can cope with >2GiB,
  1446. fixes attic #326.
  1447. - fix Traceback when running check --repair, attic #232
  1448. - clarify help text, fixes #73.
  1449. - add help string for --no-files-cache, fixes #140
  1450. Other changes:
  1451. - improved docs:
  1452. - added docs/misc directory for misc. writeups that won't be included
  1453. "as is" into the html docs.
  1454. - document environment variables and return codes (attic #324, attic #52)
  1455. - web site: add related projects, fix web site url, IRC #borgbackup
  1456. - Fedora/Fedora-based install instructions added to docs
  1457. - Cygwin-based install instructions added to docs
  1458. - updated AUTHORS
  1459. - add FAQ entries about redundancy / integrity
  1460. - clarify that borg extract uses the cwd as extraction target
  1461. - update internals doc about chunker params, memory usage and compression
  1462. - added docs about development
  1463. - add some words about resource usage in general
  1464. - document how to backup a raw disk
  1465. - add note about how to run borg from virtual env
  1466. - add solutions for (ll)fuse installation problems
  1467. - document what borg check does, fixes #138
  1468. - reorganize borgbackup.github.io sidebar, prev/next at top
  1469. - deduplicate and refactor the docs / README.rst
  1470. - use borg-tmp as prefix for temporary files / directories
  1471. - short prune options without "keep-" are deprecated, do not suggest them
  1472. - improved tox configuration
  1473. - remove usage of unittest.mock, always use mock from pypi
  1474. - use entrypoints instead of scripts, for better use of the wheel format and
  1475. modern installs
  1476. - add requirements.d/development.txt and modify tox.ini
  1477. - use travis-ci for testing based on Linux and (new) OS X
  1478. - use coverage.py, pytest-cov and codecov.io for test coverage support
  1479. I forgot to list some stuff already implemented in 0.23.0, here they are:
  1480. New features:
  1481. - efficient archive list from manifest, meaning a big speedup for slow
  1482. repo connections and "list <repo>", "delete <repo>", "prune" (attic #242,
  1483. attic #167)
  1484. - big speedup for chunks cache sync (esp. for slow repo connections), fixes #18
  1485. - hashindex: improve error messages
  1486. Other changes:
  1487. - explicitly specify binary mode to open binary files
  1488. - some easy micro optimizations
  1489. Version 0.23.0 (2015-06-11)
  1490. ---------------------------
  1491. Incompatible changes (compared to attic, fork related):
  1492. - changed sw name and cli command to "borg", updated docs
  1493. - package name (and name in urls) uses "borgbackup" to have less collisions
  1494. - changed repo / cache internal magic strings from ATTIC* to BORG*,
  1495. changed cache location to .cache/borg/ - this means that it currently won't
  1496. accept attic repos (see issue #21 about improving that)
  1497. Bug fixes:
  1498. - avoid defect python-msgpack releases, fixes attic #171, fixes attic #185
  1499. - fix traceback when trying to do unsupported passphrase change, fixes attic #189
  1500. - datetime does not like the year 10.000, fixes attic #139
  1501. - fix "info" all archives stats, fixes attic #183
  1502. - fix parsing with missing microseconds, fixes attic #282
  1503. - fix misleading hint the fuse ImportError handler gave, fixes attic #237
  1504. - check unpacked data from RPC for tuple type and correct length, fixes attic #127
  1505. - fix Repository._active_txn state when lock upgrade fails
  1506. - give specific path to xattr.is_enabled(), disable symlink setattr call that
  1507. always fails
  1508. - fix test setup for 32bit platforms, partial fix for attic #196
  1509. - upgraded versioneer, PEP440 compliance, fixes attic #257
  1510. New features:
  1511. - less memory usage: add global option --no-cache-files
  1512. - check --last N (only check the last N archives)
  1513. - check: sort archives in reverse time order
  1514. - rename repo::oldname newname (rename repository)
  1515. - create -v output more informative
  1516. - create --progress (backup progress indicator)
  1517. - create --timestamp (utc string or reference file/dir)
  1518. - create: if "-" is given as path, read binary from stdin
  1519. - extract: if --stdout is given, write all extracted binary data to stdout
  1520. - extract --sparse (simple sparse file support)
  1521. - extra debug information for 'fread failed'
  1522. - delete <repo> (deletes whole repo + local cache)
  1523. - FUSE: reflect deduplication in allocated blocks
  1524. - only allow whitelisted RPC calls in server mode
  1525. - normalize source/exclude paths before matching
  1526. - use posix_fadvise to not spoil the OS cache, fixes attic #252
  1527. - toplevel error handler: show tracebacks for better error analysis
  1528. - sigusr1 / sigint handler to print current file infos - attic PR #286
  1529. - RPCError: include the exception args we get from remote
  1530. Other changes:
  1531. - source: misc. cleanups, pep8, style
  1532. - docs and faq improvements, fixes, updates
  1533. - cleanup crypto.pyx, make it easier to adapt to other AES modes
  1534. - do os.fsync like recommended in the python docs
  1535. - source: Let chunker optionally work with os-level file descriptor.
  1536. - source: Linux: remove duplicate os.fsencode calls
  1537. - source: refactor _open_rb code a bit, so it is more consistent / regular
  1538. - source: refactor indicator (status) and item processing
  1539. - source: use py.test for better testing, flake8 for code style checks
  1540. - source: fix tox >=2.0 compatibility (test runner)
  1541. - pypi package: add python version classifiers, add FreeBSD to platforms
  1542. Attic Changelog
  1543. ---------------
  1544. Here you can see the full list of changes between each Attic release until Borg
  1545. forked from Attic:
  1546. Version 0.17
  1547. ~~~~~~~~~~~~
  1548. (bugfix release, released on X)
  1549. - Fix hashindex ARM memory alignment issue (#309)
  1550. - Improve hashindex error messages (#298)
  1551. Version 0.16
  1552. ~~~~~~~~~~~~
  1553. (bugfix release, released on May 16, 2015)
  1554. - Fix typo preventing the security confirmation prompt from working (#303)
  1555. - Improve handling of systems with improperly configured file system encoding (#289)
  1556. - Fix "All archives" output for attic info. (#183)
  1557. - More user friendly error message when repository key file is not found (#236)
  1558. - Fix parsing of iso 8601 timestamps with zero microseconds (#282)
  1559. Version 0.15
  1560. ~~~~~~~~~~~~
  1561. (bugfix release, released on Apr 15, 2015)
  1562. - xattr: Be less strict about unknown/unsupported platforms (#239)
  1563. - Reduce repository listing memory usage (#163).
  1564. - Fix BrokenPipeError for remote repositories (#233)
  1565. - Fix incorrect behavior with two character directory names (#265, #268)
  1566. - Require approval before accessing relocated/moved repository (#271)
  1567. - Require approval before accessing previously unknown unencrypted repositories (#271)
  1568. - Fix issue with hash index files larger than 2GB.
  1569. - Fix Python 3.2 compatibility issue with noatime open() (#164)
  1570. - Include missing pyx files in dist files (#168)
  1571. Version 0.14
  1572. ~~~~~~~~~~~~
  1573. (feature release, released on Dec 17, 2014)
  1574. - Added support for stripping leading path segments (#95)
  1575. "attic extract --strip-segments X"
  1576. - Add workaround for old Linux systems without acl_extended_file_no_follow (#96)
  1577. - Add MacPorts' path to the default openssl search path (#101)
  1578. - HashIndex improvements, eliminates unnecessary IO on low memory systems.
  1579. - Fix "Number of files" output for attic info. (#124)
  1580. - limit create file permissions so files aren't read while restoring
  1581. - Fix issue with empty xattr values (#106)
  1582. Version 0.13
  1583. ~~~~~~~~~~~~
  1584. (feature release, released on Jun 29, 2014)
  1585. - Fix sporadic "Resource temporarily unavailable" when using remote repositories
  1586. - Reduce file cache memory usage (#90)
  1587. - Faster AES encryption (utilizing AES-NI when available)
  1588. - Experimental Linux, OS X and FreeBSD ACL support (#66)
  1589. - Added support for backup and restore of BSDFlags (OSX, FreeBSD) (#56)
  1590. - Fix bug where xattrs on symlinks were not correctly restored
  1591. - Added cachedir support. CACHEDIR.TAG compatible cache directories
  1592. can now be excluded using ``--exclude-caches`` (#74)
  1593. - Fix crash on extreme mtime timestamps (year 2400+) (#81)
  1594. - Fix Python 3.2 specific lockf issue (EDEADLK)
  1595. Version 0.12
  1596. ~~~~~~~~~~~~
  1597. (feature release, released on April 7, 2014)
  1598. - Python 3.4 support (#62)
  1599. - Various documentation improvements a new style
  1600. - ``attic mount`` now supports mounting an entire repository not only
  1601. individual archives (#59)
  1602. - Added option to restrict remote repository access to specific path(s):
  1603. ``attic serve --restrict-to-path X`` (#51)
  1604. - Include "all archives" size information in "--stats" output. (#54)
  1605. - Added ``--stats`` option to ``attic delete`` and ``attic prune``
  1606. - Fixed bug where ``attic prune`` used UTC instead of the local time zone
  1607. when determining which archives to keep.
  1608. - Switch to SI units (Power of 1000 instead 1024) when printing file sizes
  1609. Version 0.11
  1610. ~~~~~~~~~~~~
  1611. (feature release, released on March 7, 2014)
  1612. - New "check" command for repository consistency checking (#24)
  1613. - Documentation improvements
  1614. - Fix exception during "attic create" with repeated files (#39)
  1615. - New "--exclude-from" option for attic create/extract/verify.
  1616. - Improved archive metadata deduplication.
  1617. - "attic verify" has been deprecated. Use "attic extract --dry-run" instead.
  1618. - "attic prune --hourly|daily|..." has been deprecated.
  1619. Use "attic prune --keep-hourly|daily|..." instead.
  1620. - Ignore xattr errors during "extract" if not supported by the filesystem. (#46)
  1621. Version 0.10
  1622. ~~~~~~~~~~~~
  1623. (bugfix release, released on Jan 30, 2014)
  1624. - Fix deadlock when extracting 0 sized files from remote repositories
  1625. - "--exclude" wildcard patterns are now properly applied to the full path
  1626. not just the file name part (#5).
  1627. - Make source code endianness agnostic (#1)
  1628. Version 0.9
  1629. ~~~~~~~~~~~
  1630. (feature release, released on Jan 23, 2014)
  1631. - Remote repository speed and reliability improvements.
  1632. - Fix sorting of segment names to ignore NFS left over files. (#17)
  1633. - Fix incorrect display of time (#13)
  1634. - Improved error handling / reporting. (#12)
  1635. - Use fcntl() instead of flock() when locking repository/cache. (#15)
  1636. - Let ssh figure out port/user if not specified so we don't override .ssh/config (#9)
  1637. - Improved libcrypto path detection (#23).
  1638. Version 0.8.1
  1639. ~~~~~~~~~~~~~
  1640. (bugfix release, released on Oct 4, 2013)
  1641. - Fix segmentation fault issue.
  1642. Version 0.8
  1643. ~~~~~~~~~~~
  1644. (feature release, released on Oct 3, 2013)
  1645. - Fix xattr issue when backing up sshfs filesystems (#4)
  1646. - Fix issue with excessive index file size (#6)
  1647. - Support access of read only repositories.
  1648. - New syntax to enable repository encryption:
  1649. attic init --encryption="none|passphrase|keyfile".
  1650. - Detect and abort if repository is older than the cache.
  1651. Version 0.7
  1652. ~~~~~~~~~~~
  1653. (feature release, released on Aug 5, 2013)
  1654. - Ported to FreeBSD
  1655. - Improved documentation
  1656. - Experimental: Archives mountable as fuse filesystems.
  1657. - The "user." prefix is no longer stripped from xattrs on Linux
  1658. Version 0.6.1
  1659. ~~~~~~~~~~~~~
  1660. (bugfix release, released on July 19, 2013)
  1661. - Fixed an issue where mtime was not always correctly restored.
  1662. Version 0.6
  1663. ~~~~~~~~~~~
  1664. First public release on July 9, 2013