Commit Graph
413 Commits
Author SHA1 Message Date
Kenneth SkovhedeandGitHub baca571ef8 Merge pull request #6727 from duplicati/feature/prevent-restore-target-escape
Prevent restore target escape
2026-02-06 14:33:01 +01:00
Kenneth Skovhede 44bef1e855 Implement support for filesystem snapshots on macOS using APFS (Apple File System). This allows disks-consistent backups and backing up files that are locked by other processes by creating and mounting local snapshots using tmutil.
Key changes:
- Add `MacOSSnapshot` class implementing `SnapshotBase`
- Add helper scripts for creating, finding, and removing APFS snapshots
- Update `SnapshotUtility` to initialize macOS snapshots
- Enable `snapshot-policy` option for macOS in `Options.cs`
- Update build configuration to include APFS scripts
- Update snapshot test utility with macOS support

This fixes #6409
2026-02-04 15:02:31 +01:00
Kenneth SkovhedeandGitHub 26f7dd8586 Merge branch 'master' into feature/add-office-365-backup 2026-01-29 20:04:42 +01:00
Kenneth SkovhedeandGitHub e79d30731c Merge pull request #6724 from duplicati/feature/add-soft-delete
Added a soft-delete feature
2026-01-28 15:19:49 +01:00
Kenneth Skovhede c765a5658b Improved query for purge broken files
This PR improves the query used to calculate the size of removed files when issuing the purge-broken-files command.

This PR also adds the option `--reduced-purge-statistics` which will fully skip the size calculation, in the event the query is still performing poorly.

This fixes #6366
2026-01-27 21:15:50 +01:00
Kenneth Skovhede 655d6cbe65 Prevent restore target escape
This PR adds checks on limited restores, where the user has asked for files to be restored within a specific folder.

This PR adds explicit checks to ensure that the restore data cannot accidentially or maliciously constructed in such a way that it will affect files outside of the restore target folder.
2026-01-27 15:51:30 +01:00
Kenneth Skovhede 8996955dc1 Added a soft-delete feature
This PR adds an option to give a soft-delete prefix. If the prefix is set, files are renamed instead of actually being deleted. For backends that support life-cycle rules, this can be used to provide protection agains accidental deletion.

The intended use is that the client credentials do not have permissions to delete files, but can rename files. When a file is soft-deleted, it is then renamed and no longer "visible" to Duplicati. The destination can then have lifecycle rules that deletes files with the designated prefix after a set interval, or by another service that has permissions to actually delete files.
2026-01-27 14:10:31 +01:00
Kenneth Skovhede 1523f730e3 Added support for storing metadata in the database 2026-01-14 10:01:20 +01:00
Kenneth Skovhede 6e6e993765 Fixed issues with database transaction not being comitted.
Renamed the options to be more descriptive.
Rewrote the dependency query to be more readable and also check for metadata dependency.

Fixed an edge case where there were no modified files, and no new backup is created.

Fixed some issues with local/utc datetime compares.

Fixed logic for deleting filesets to only look at the filesets themselves. This makes the version lock follow the dlist file, and can create "dangling" volumes that have no filesets, but these will be picked up by compaction.

Updated tests to work correctly.

Added lock-info update option for the backup recreate call, so the UI can also re-create lock information on database rebuilds.
2025-12-17 22:27:38 +01:00
Kenneth Skovhede 0f81b42146 Add support for remote locks
This PR adds support for locking files if the backend supports it.

To activate locking, set the option `--file-lock-duration=30D` and the backup will lock the files.

If the database is rebuilt with the intention of continuing the backups, use the option `--repair-refresh-lock-info` which will update lock information in the database after recreating the database.

The locking works by asking the backend to lock files after a backup has completed.

The implementation keeps track of which files are currently assigned a lock and prevents attempting to delete the files that are currently locked.

Note that the bucket should not have a default lock policy as Duplicati needs to finish the backup before the locking is applied.

In this initial version, Azure Blob Storage, B2, S3 and iDrive are supported with locking.

The CLI is updated to allow setting locks on a specific version. The backend tool is updated to allow setting locks on specific files.
2025-12-14 17:17:48 +01:00
David Kartchner 5113d0e989 added an option to supply a new passphrase for reencryption with RecoveryTool recompress command 2025-12-02 02:24:06 -07:00
Kenneth Skovhede e1b9015a85 Added support for exclusion of files based on xattrs
This PR adds detection of exclusion attributes on files and folders. If a file or folder has an exclusion extended attribute, the file or folder is excluded from the backup.

The option `--disable-backup-exclusion-xattr` can be used to revert to the previous behavior where the xattrs were not checked.

This has the biggest impact on MacOS where it will not perform like other backup software and avoid files that are marked as excluded from backup.

This fixes #6393
2025-11-21 10:59:28 +01:00
Kenneth Skovhede 3b695cf065 Added support for Photos on MacOS
This PR adds detection of the MacOS Photos folder, and intercepts reads and replaces them with PhotoKit calls.
With this, it is possible to make backups of all MacOS Photos, even if they are not stored locally.

The previous versions would just make a backup of the on-disk structure, which was not guaranteed to contain all photos, but instead has various indexing for finding photos, and may contain some original photos.

The option `--photos-handling` controls how Duplicati now deals with the Photos folder. The options are:
- `LibraryOnly`: Same as before, just treat it as a folder
- `PhotosOnly`: Ignore the folder contents and just back up the actual photos
- `PhotosAndLibrary` (default): Make a backup of the photos and the library on-disk. This may cause images to be stored twice, but de-duplication will usually limit the storage increase.

The option `--photos-library-path` can be used to point to the on-disk Photo library that should be handled, in case the auto-detection does not pick it up. If this does not point to a valid Photoslibrary, or the path is not being backed up, no special handling will be done.

Note that the restore is not restoring into Photos itself, but instead restores into a sub-folder in the Photolibrary that is called `dup_backup`. To get the photos out after a restore, one needs to right-click the Photolibrary folder, and choose "Show package contents" and then the `dup_backup` folder is revealed.

This is done to keep all photos in the same folder, but avoid messing with the structure of the on-disk Photolibrary.

A future update could allow restoring back into Photos, and metadata is captured for each image to eventually allow this.

This fixes #6381
2025-11-17 17:12:10 +01:00
Kenneth Skovhede 8224d84f57 Reverted to use the shorter name --asynchronous-upload-limit and then added an alias for --asynchronous-concurrent-upload-limit. 2025-10-16 13:25:34 +02:00
Kenneth Skovhede 55c19c8752 Removed more references to the unused option 2025-10-16 13:21:40 +02:00
Kenneth Skovhede d3b15f136e Removed unused option
The option `asynchronous-upload-limit` was not used, and has been removed.
2025-10-14 21:30:02 +02:00
Carl Johnsen a1e1afce28 Changed the default volume cache hint to be volumesize * 100 2025-10-03 08:50:35 +02:00
Kenneth SkovhedeandGitHub 926ff199f4 Merge pull request #6485 from duplicati/feature/revert-allow-empty-source
Invert `--allow-empty-source`
2025-08-15 11:41:07 +02:00
Kenneth Skovhede eb34f8a6b8 Revert "Reverted flag to be allow-empty-source so the check is on by default."
This reverts commit 139b4747af.
2025-08-15 11:01:34 +02:00
Carl Johnsen 0194d2a486 Merge branch 'master' into feature/restore-volume-cache-size-parameter 2025-08-14 17:22:41 +02:00
Carl Johnsen 3e10b8446a Changed the wording of the new volume cache parameter 2025-08-14 17:20:58 +02:00
Kenneth Skovhede ba2ea61ca4 Add option to log HTTP and socket requests
This adds the options `--log-http-requests` and `--log-socket-data` which can be activated to capture diagnostics about HTTP requests and socket operations.
2025-08-08 19:18:30 +02:00
Carl Johnsen dc4d8fa587 Added the option to control the size of the volume cache during restore 2025-08-08 12:44:59 +02:00
Kenneth Skovhede 139b4747af Reverted flag to be allow-empty-source so the check is on by default. 2025-08-06 08:18:38 +02:00
Kenneth Skovhede 3526b1f117 Added --prevent-empty-source 2025-08-05 15:19:25 +02:00
Kenneth Skovhede 6502017c57 Merge remote-tracking branch 'origin/master' into feature/vanara-vss-backup 2025-07-03 17:09:30 +02:00
Kenneth SkovhedeandGitHub 5ff613b5da Merge pull request #6360 from carljohnsen/performance/mssqlite-async
Performance/Asynchronous database backend
2025-07-03 11:07:26 +02:00
Kenneth SkovhedeandGitHub 29f5eb79e5 Merge branch 'master' into feature/vanara-vss-backup 2025-07-01 16:35:57 +02:00
Kenneth Skovhede 98deb8c576 Update support for VSS
This updates VSS to default use Vanara in favor of AlphaVSS which is no longer maintained.

The build for Vanara requires targeting `net8.0-windows7.0`, which will cause significant build overhead and complexity for cross platform builds.
To counter this, the setup is to have a single project, `Duplicati.Library.WindowsModules`, that is targeting `net8.0-windows7.0`.
The output from this project is then hoisted into the TrayIcon project for Windows builds so the files are available when debugging on Windows.
A top-level dummy executable project is added to ensure the project always builds.
The built modules are then loaded with reflection when requested.

With the use of Vanara there is now also support for using BackupRead to read files without making a VSS snapshot.
With BackupRead, it is possible to read locked files, but it still requires the SeBackupPrivilege as VSS does as well.

Unfortunately, the `vssapi.dll` file is not shipped for Arm64 on Windows, so even with Vanara this will not work, and only WMIC is supported on Arm64.
A workaround is to run Duplicati with x64 emulation if more advanced VSS features are needed (HyperV and MSSQL support).

This PR also updates options and filters out unsupported options for each operating system, so options that are not supported by the current OS are not reported and will give warnings if they are used, as opposed to just being ignored.

The release builder project has been updated to exclude the unused project, and purge unwanted outputs.
2025-07-01 16:32:19 +02:00
Kenneth Skovhede 3719935b1d No exempt throttle backends
This PR removes the default value of `file` as a throttle exempt backend, so all backends are  subject to throttle by default.

This change makes the option easier to work with as the empty string could not be used to undo the default value, and fixing this would make the options be applied inconsistently.

Also fixed two errors in the help text for the option.
2025-06-24 16:13:59 +02:00
Carl Johnsen f6ac30e831 Merge remote-tracking branch 'upstream/master' into performance/mssqlite-async 2025-06-19 12:17:30 +02:00
Carl Johnsen 2412800c0c Removed the sqlite page cache option. It should be set through the environment variable, or some other way of providing a custom database configurotion 2025-06-19 11:41:39 +02:00
Kenneth SkovhedeandGitHub 15eb009594 Merge pull request #6343 from duplicati/feature/fix-module-loading
Handle loading and unloading of modules
2025-06-13 10:47:26 +02:00
Kenneth SkovhedeandGitHub 35e389b507 Merge pull request #6333 from duplicati/feature/booleans-should-be-false-by-default
Ensure booleans are false by default
2025-06-13 10:46:54 +02:00
Kenneth Skovhede ee9c2a640b Secret provider option should be a password
This changes the `--secret-provider` type to be a password, as it may contain credentials for the key vault.
2025-06-13 09:12:16 +02:00
Kenneth SkovhedeandGitHub d74778bbf5 Merge branch 'master' into feature/booleans-should-be-false-by-default 2025-06-13 08:58:12 +02:00
Kenneth Skovhede 7c602106c3 Simplified priority sorting 2025-06-13 08:08:42 +02:00
Kenneth Skovhede f6094baddb Handle loading and unloading of modules
This PR fixes the issues with not correctly loading and disposing modules.

Prior to this PR, there would be only a single instance of each module loaded, which would be configured and later disposed, meaning that the same instance would be used after being disposed, and disposed multiple times.

This mostly worked, but it could carry configuration details over between unrelated runs.

This fixes #6314
2025-06-12 22:13:55 +02:00
Kenneth Skovhede 8c0e5e579d Ensure booleans are false by default
This PR changes `--replace-faulty-index-files` to `--dont-replace-faulty-index-files`, and swaps the default value.

This PR also adds a check that triggers a warning if any boolean values are introduced with a default value that is `true`.
2025-06-12 10:34:57 +02:00
Kenneth Skovhede 35058d333e Update handling of alternate OAuth url
This PR removes the `OAuthContextSettings` class, and makes the `--oauth-url` option available on each backend that uses it, so it can be configured as part of the destination.

To assemble everything related to configuring OAuth, the code was moved to the `AuthIdOptionsHelper`, such that the usage can be shared between implementations.

This PR also adds the option to set the default OAuth url from the environment variable `DUPLICATI_OAUTH_SERVICE`.

The server can then be set in the following locations (most important last):
- Environment variable
- Server-wide advanced settings
- Backup job advanced settings (or commandline)
- Destination url
2025-06-11 09:27:40 +02:00
Kenneth Skovhede 3ebc50a89d Adding repair for index files
Since index files only contains information related to recreating the database, they can be recreated directly from a working database.

This PR adds an automatic repair feature that replaces index files if they are missing content. This will gradually repair remote index files if they are affected by the compact bug that re-wrote index files without the blocklists.

To fully repair, it is possible to run the `Test` command with the option `--full-remote-verification=indexonly` and a large number of samples. Since the new option `--replace-faulty-index-files` is default set to `true` this will repair any defective index files and ignore all others.

This update uncovered that the Test method would previously not verify the presence of blocklists in the index files. This is likely a very old bug, caused by the fact that the original implementation did not place blocklisthashes in the index files. The omission of this check is the reason the extent of the compact issue was not discovered earlier.

With this PR it is now also visible that there is ample room for error in creating the index files during the backup process. This is caused by the parallel processing and carry-over, where the index files are created on-the-go, so they are ready to upload once the blocks are filled.

While this is likely good for performance, it has some drawbacks.
- A failed block upload will cause a rewrite of the index file
- An elaborate callback system is needed to update the index file
- It is possible to race against the database and create extra blocklist hashes, bloating the index files (causes problems on verification)

A subsequent task is to rewrite the logic to not touch the index files outside the backend manager, so the backend manager will just use the database to create the index file. This means the same code will be invoked for both the create, the recreate, and the replacement.

For now, extra content in index files is logged with the verbose log level.

This fixes #6296
2025-05-27 17:15:02 +02:00
Kenneth SkovhedeandGitHub 6f5505f2a2 Merge pull request #6279 from duplicati/feature/issue2685
Default disable throttle for local destinations
2025-05-26 08:29:29 +02:00
Kenneth Skovhede a4234a342c Default disable throttle for local destinations
This PR adds the option to disable throttle on a backup, so it will ignore throttle settings both from the server and the job.

Additionally, a list of backend keys can be provided, where backups will disable throttling. This can be used to set advanced options with a set of backends that should not be throttled.

By default, the `file` backend is now exempt from throttling by default.
This fixes #2685
2025-05-20 19:06:35 +02:00
Kenneth Skovhede ded55740de Set VSS to Auto if user has permissions
If th user has the SeBackupPrivilege, set the default snapshot policy to `Auto` and otherwise use `Off` (the current default).

This ensures that if the process is running with the correct permissions, there will be fewer warnings.

This only changes the default value on Windows.

This fixes #2833
2025-05-20 16:53:11 +02:00
Kenneth Skovhede 1cfacca794 Enabled nullable for FilterExpression and Options
This adds nullability to FilterExpression and Options.
It also updates almost all properties in Options to use a common format that enforces uniform parsing of the values.

A few options have been updates to have the default values specified as a constant, to avoid replicating the value in two places.
2025-05-20 14:36:39 +02:00
Kenneth Skovhede ef631a1199 Added feature to suppress warnings
This PR adds the option to suppress warnings by their log id. Warning IDs that are supplied to `--suppress-warnings` will be converted to information messages before being logged.

If a specific warning is disabled, such as `CompressionReadErrorFallback`, this will then no longer count as a warning for the job, and the log file will see the warning as an information message.

This PR also adds two simpler filter options that makes it possible to filter log messages by supplying the log IDs. This can already be achieved with log filters, but the ID filter is a bit simpler to apply, as you only need to know the ID.

Finally, this PR also adds common logging for errors in the categories:
- Permission denied, id = `PermissionDenied`
- File locked, id = `FileLocked`
- Path not found, id = `PathNotFound`
- Path too long, id = `PathTooLong`

These new log ids makes it simpler to ignore warnings about locked or inaccesible files.
2025-05-20 14:26:10 +02:00
Kenneth Skovhede fe866ceb9f Implemented support for repairing the database when only parts of the source data is available.
This repair will leave the database in a still-broken state, but if this is run prior to purge-broken-files, less data will be lost.

Also updated the purge-broken-files operation to keep files and directories in the set, if they are only missing metadata.
2025-05-09 11:12:29 +02:00
Kenneth SkovhedeandGitHub 5464dc0940 Merge pull request #5133 from duplicati/feature/support-cachedir-tag
Added `CACHEDIR.TAG` as the default marker for ignoring directories
2025-04-26 10:39:01 +02:00
Kenneth SkovhedeandGitHub 1bbe04a782 Merge branch 'master' into feature/add-sqlite-cache-value 2025-04-25 13:58:24 +02:00
Kenneth SkovhedeandGitHub f3d7905f0e Merge branch 'master' into feature/support-cachedir-tag 2025-04-23 22:04:06 +02:00