Commit Graph
40 Commits
Author SHA1 Message Date
Kenneth Skovhede a7ef8e42f2 Lock permissions on datafolder
This PR is a security hardning change and will break some setups.

The hardning is done to ensure the datafolder is not compromised and particularly that it is not maliciously seeded.

The changes now **requires** that the datafolder is locked down with exact permissions, or Duplicati will refuse to use it. This is a change to prior functionality where the folder would simply be locked down if it was not already locked.

Previously, a file named `insecure-permissions.txt` could be placed in the folder to instruct Duplicati not to set permissions. With this change that file is no longer supported.

The only way to opt-out of the permission check is to supply `--allow-insecure-datafolder` or the environment variable `DUPLICATI__ALLOW_INSECURE_DATAFOLDER`. Once either of those are set, Duplicati will no longer check permissions and accept folders with other permissions.

The setting can be applied to `preload.json`, but the file needs to be in a trusted location, which is either the directory with the binaries or the file pointed to by `DUPLICATI_PRELOAD_SETTINGS`. The setting cannot be placed in a `preload.json` file that is in an insecure folder as the folder is not read if the permissions are not correct.

The previous paths `/usr/local/share/Duplicati/preload.json` and `C:\ProgramData\Duplicati\preload.json` are no longer supported as they cannot be guaranteed to be locked down.

A `preload.json` in the datafolder is still supported, provided the folder passes the permission check (or the `--allow-insecure-datafolder` is passed to the executable).

For most users, this should not cause any problems as Duplicati has been locking down the folders, so they should be correctly locked down already.

The configuretool has been updated with a `secure-datafolder` command that can be used to force the correct permissions on a folder, in case the folder did not have the correct permissions.

For some Docker setups it may not be possible to set the permissions and the check will fail. These setup will need to apply `DUPLICATI__ALLOW_INSECURE_DATAFOLDER=true` in the image to run without the protections.
2026-07-10 15:03:32 +02:00
Kenneth Skovhede 67af546a7f Fix database tool to support sync databases 2026-06-28 19:39:42 +02:00
Kenneth Skovhede 355e3ce6b2 Merge commit 'e91a7ea7d59bc67fc783ec7a897c747f3bd05402' into feature/add-file-sync-operation 2026-06-25 22:05:26 +02:00
Kenneth Skovhede 3a3e87fa2f Added support for creating "backup" configurations that perform a sync instead of the regular backup. 2026-06-25 17:16:38 +02:00
Kenneth Skovhede 62ea2d23f5 Added a sync command to the Controller and CLI.
This refactors a part of the database and adds a new "sync" command that reuses a lot of the backup logic to take a set of sources and apply them to a backend.

Unlike the backup process, the sync copies files verbatim without any encryption.
2026-06-25 15:49:00 +02:00
Kenneth Skovhede 5c1b477cda Use relative database paths
This PR changes to use relative database paths by default. The default mode is to store all databases in the same folder.

With this update, the paths stored in the server database can now be relative, in which case they are resolved relative to the datafolder.

This makes it simpler to move the data folder as the paths are not stored in full.

For new backups, relative paths are assigned.
For existing backups, the full paths are retained.
If the database path is updated manually, the path will be made relative, if it is relative to the datafolder; otherwise a full path is stored.

This fixes #6677
2026-06-19 08:42:58 +02:00
Kenneth Skovhede 179d1ceb47 Make controller Async
This PR has a large blast radius because it takes the final step and bumps up the Controller to be fully async.

We have historically done a piece-by-piece update, so all operations were already async but the controller interface was kept synchronous.

With this update, the controller is now fully async and all tests are updated.

Most places where the new C# compiler warns about function names not ending in `Async` were also adressed, giving a massive refactor change.

Functionally, no changes are done.
2026-05-13 15:04:13 +02:00
Kenneth Skovhede c0f40e19ca Updated copyright year to 2026 across the project 2026-04-16 15:21:24 +02:00
Kenneth Skovhede 8b2475ee93 Add verify and cleanup to database tool
Adds two new commands to the database CLI tool:

- verify: Lists all databases with their status (Found, Missing, Orphaned)
  across dbconfig.json, server database, and filesystem

- cleanup: Removes orphaned database files not referenced in dbconfig.json
  or server database, with --dry-run and --force options

Includes unit tests for both commands.
2026-03-11 10:27:45 +01:00
Kenneth Skovhede ea6d94b035 Added support for storing multiple targets in database with backwards compatibility. 2026-02-18 11:06:08 +01:00
Kenneth SkovhedeandGitHub 562cb1199a Merge branch 'master' into feature/add-destination-repo 2026-02-02 11:00:39 +01:00
Kenneth Skovhede cf17d2617e Added a connection string repo
This adds a connection string repo, where connection strings can be stored.

The general idea is that it is possible to store connection strings, say an S3 connection, and then re-use the connection string for multiple backups, editing as needed.

The implementation supports listing connection strings, creating, updating, and deleting them.

The connection strings are masked so sensitive information is not available in the browser, and the logic patches connection strings internally to ensure markers are replaced with the correct values.

The connection string itself is stored in full, such that a Duplicati version roll-back will not make the connectionstring become invalid.

There is also an endpoint that allows updating existing backups using the connection string, so it is easy to rotate keys. The logic for this feature is that it retains: scheme, port, host, path, and any extra settings on the target url.
It does not remove settings from the target, but will overwrite or add settings from the connectionstring.
2026-01-30 13:59:47 +01:00
Kenneth Skovhede 1523f730e3 Added support for storing metadata in the database 2026-01-14 10:01:20 +01:00
Kenneth Skovhede 0f81b42146 Add support for remote locks
This PR adds support for locking files if the backend supports it.

To activate locking, set the option `--file-lock-duration=30D` and the backup will lock the files.

If the database is rebuilt with the intention of continuing the backups, use the option `--repair-refresh-lock-info` which will update lock information in the database after recreating the database.

The locking works by asking the backend to lock files after a backup has completed.

The implementation keeps track of which files are currently assigned a lock and prevents attempting to delete the files that are currently locked.

Note that the bucket should not have a default lock policy as Duplicati needs to finish the backup before the locking is applied.

In this initial version, Azure Blob Storage, B2, S3 and iDrive are supported with locking.

The CLI is updated to allow setting locks on a specific version. The backend tool is updated to allow setting locks on specific files.
2025-12-14 17:17:48 +01:00
Kenneth Skovhede 1ea74a3c63 Updated to .NET10 2025-11-14 15:05:39 +01:00
Kenneth Skovhede 1d772127df Fixed wrong downgrade script 2025-09-22 14:29:52 +02:00
Kenneth Skovhede 34b6f9ea55 Implemented remotely managed backup configurations
This PR adds the ability to manage backup configurations outside of the the client.

The implementation ensures that locally created configurations cannot be affected by the remotely managed backups.

If the instance is not connected to a remote console, this has no effect.

This PR updates the local database to add the column `ExternalID` that tracks backups that are managed remotely.
2025-09-17 15:07:09 +02:00
Carl Johnsen 2412800c0c Removed the sqlite page cache option. It should be set through the environment variable, or some other way of providing a custom database configurotion 2025-06-19 11:41:39 +02:00
Carl Johnsen 9b0d89363b Removed whitespace 2025-06-19 11:40:23 +02:00
Carl Johnsen 78d649f5a3 All of the non-internal-library methods calling the database functions forwards CancellationToken.None 2025-06-19 11:00:24 +02:00
Carl Johnsen 9ac583db94 Made all relevant using statements use await to use DisposeAsync 2025-06-18 11:53:11 +02:00
Carl Johnsen f221098c28 Formatted SQL queries - mainly adding double quotes where they were missing. 2025-06-18 10:42:08 +02:00
Carl Johnsen e81100de04 Started on adding docstrings 2025-06-17 09:59:22 +02:00
Carl Johnsen 3d11a05400 Added .ConfigureAwait(false) to all of the await statements 2025-06-12 08:34:29 +02:00
Carl Johnsen 17cabeb329 Updated the DatabaseTool to use the new async database backend 2025-06-11 08:57:14 +02:00
Carl Johnsen eda3d5321b Removed whitespace 2025-06-11 08:56:58 +02:00
Kenneth SkovhedeandGitHub 8a2f028f7a Merge branch 'master' into feature/add-blocksetentry-index 2025-05-16 19:02:26 +02:00
Kenneth SkovhedeandGitHub 292107b9de Merge pull request #6262 from duplicati/feature/fix-dbtool-tests-should-fail
Check exit code in dbtool tests
2025-05-16 19:01:47 +02:00
Kenneth Skovhede b3f43830cf Fixed query for Windows/Linux 2025-05-16 15:51:30 +02:00
Kenneth Skovhede 531664cb23 Added missing index for blocksetentry 2025-05-16 15:36:24 +02:00
Carl Johnsen 8be97bcefd Whitespace changes 2025-05-16 10:22:51 +02:00
Kenneth Skovhede 424ef6c5bf Rolled in index from #4706
This closes #4706
2025-05-10 22:30:05 +02:00
Kenneth Skovhede c3b082e9f5 Fixed rollback script 2025-05-10 22:13:41 +02:00
Kenneth Skovhede 2f12473398 Added missing index on remotevolume name 2025-05-10 10:02:08 +02:00
Kenneth Skovhede 32f44a1ea7 Fixed issues with compile after merges 2025-04-25 17:21:39 +02:00
Kenneth Skovhede 0d413737b9 Set defaults for downgrade version to match 2.1.0.5 stable 2025-04-25 13:44:57 +02:00
Kenneth Skovhede ba298df915 Added an upgrade command to the database tool 2025-04-25 12:30:03 +02:00
Kenneth Skovhede 1eb95c046f Added option to scan for databases that are not connected to CLI or server database. 2025-04-25 11:13:50 +02:00
Kenneth Skovhede c8f8fb1a37 Less cryptic script comment 2025-04-24 16:42:57 +02:00
Kenneth Skovhede a0ecc5e05d Added a database downgrade tool 2025-04-24 16:36:14 +02:00