This PR adds support for generating a self-signed CA and then using that CA to generate TLS certificates.
A new tool `duplicati-configure` / `Duplicati.CommandLine.ConfigureTool.exe` is added to manage the certificates. The tool saves the configuration in the database and is meant to run with elevated privileges for the initial CA installation.
The option `--configure-https` can be added to server/trayicon, and if the process has permissions, this will automatically install the CA certificate.
If a CA is configured, the server will automatically issue, renew and use a TLS certificate.
With this setup, the TLS is opt-in, but once the flow is well tested, we can switch it to opt-out.
This fixes compatibility with OpenSUSE by using the target filenames as dependencies instead of the package names that differ (libICE vs libICE6).
This fixes#6166
This adds back support for Synology DSM.
The implementation is compatible with DSM 7.2+ and integrates with DSM to forward requests through the DSM server into Duplicati.
The setup features database locks, using a random auth-key so DSM handles authentication.
The database is encrypted with a random key, and all data is stored in the `var` folder.
The uninstall can optionally remove the `var` data.
This is still a work in progress. The authentication integration with DSM does not currently work.
This PR adds detection of the MacOS Photos folder, and intercepts reads and replaces them with PhotoKit calls.
With this, it is possible to make backups of all MacOS Photos, even if they are not stored locally.
The previous versions would just make a backup of the on-disk structure, which was not guaranteed to contain all photos, but instead has various indexing for finding photos, and may contain some original photos.
The option `--photos-handling` controls how Duplicati now deals with the Photos folder. The options are:
- `LibraryOnly`: Same as before, just treat it as a folder
- `PhotosOnly`: Ignore the folder contents and just back up the actual photos
- `PhotosAndLibrary` (default): Make a backup of the photos and the library on-disk. This may cause images to be stored twice, but de-duplication will usually limit the storage increase.
The option `--photos-library-path` can be used to point to the on-disk Photo library that should be handled, in case the auto-detection does not pick it up. If this does not point to a valid Photoslibrary, or the path is not being backed up, no special handling will be done.
Note that the restore is not restoring into Photos itself, but instead restores into a sub-folder in the Photolibrary that is called `dup_backup`. To get the photos out after a restore, one needs to right-click the Photolibrary folder, and choose "Show package contents" and then the `dup_backup` folder is revealed.
This is done to keep all photos in the same folder, but avoid messing with the structure of the on-disk Photolibrary.
A future update could allow restoring back into Photos, and metadata is captured for each image to eventually allow this.
This fixes#6381
Since .NET dynamically loads libicu, it is not prone to ABI breakage and can load virtually any version.
However, there is no `Depends: libicu*` option in Debian packages, so we need the explicit package version. This is prone to breaking as new Debian version bump the version number.
This PR changes the `Depends:` to `Recommends:` so `libicu` is installed if possible, but does not prevent installation.
For cases where the is no `libicu` on the system, there is now a `preinst` script which will warn if the library is missing, but not prevent installation.
The warning should only show in Docker images or similar slim contexts, as `libicu` is otherwise installed with the base system.
This updates VSS to default use Vanara in favor of AlphaVSS which is no longer maintained.
The build for Vanara requires targeting `net8.0-windows7.0`, which will cause significant build overhead and complexity for cross platform builds.
To counter this, the setup is to have a single project, `Duplicati.Library.WindowsModules`, that is targeting `net8.0-windows7.0`.
The output from this project is then hoisted into the TrayIcon project for Windows builds so the files are available when debugging on Windows.
A top-level dummy executable project is added to ensure the project always builds.
The built modules are then loaded with reflection when requested.
With the use of Vanara there is now also support for using BackupRead to read files without making a VSS snapshot.
With BackupRead, it is possible to read locked files, but it still requires the SeBackupPrivilege as VSS does as well.
Unfortunately, the `vssapi.dll` file is not shipped for Arm64 on Windows, so even with Vanara this will not work, and only WMIC is supported on Arm64.
A workaround is to run Duplicati with x64 emulation if more advanced VSS features are needed (HyperV and MSSQL support).
This PR also updates options and filters out unsupported options for each operating system, so options that are not supported by the current OS are not reported and will give warnings if they are used, as opposed to just being ignored.
The release builder project has been updated to exclude the unused project, and purge unwanted outputs.
This adds a CI test for building releases so we know in advance if package versions are out-of-order.
This also sets the primary project for CLI to the Server as that covers more than the CLI project.
The logic is reverted to build each project into a build folder, and then copy the files into a shared common folder.
An additional check examines the log output and checks that there are no debug builds performed or used.
When building a release, it is now possible to also offer that release in "lower" channels, meaning the stable release will show as an update to instances running beta or experimental.