Files
duplicati/ReleaseBuilder
Kenneth Skovhede 3b695cf065 Added support for Photos on MacOS
This PR adds detection of the MacOS Photos folder, and intercepts reads and replaces them with PhotoKit calls.
With this, it is possible to make backups of all MacOS Photos, even if they are not stored locally.

The previous versions would just make a backup of the on-disk structure, which was not guaranteed to contain all photos, but instead has various indexing for finding photos, and may contain some original photos.

The option `--photos-handling` controls how Duplicati now deals with the Photos folder. The options are:
- `LibraryOnly`: Same as before, just treat it as a folder
- `PhotosOnly`: Ignore the folder contents and just back up the actual photos
- `PhotosAndLibrary` (default): Make a backup of the photos and the library on-disk. This may cause images to be stored twice, but de-duplication will usually limit the storage increase.

The option `--photos-library-path` can be used to point to the on-disk Photo library that should be handled, in case the auto-detection does not pick it up. If this does not point to a valid Photoslibrary, or the path is not being backed up, no special handling will be done.

Note that the restore is not restoring into Photos itself, but instead restores into a sub-folder in the Photolibrary that is called `dup_backup`. To get the photos out after a restore, one needs to right-click the Photolibrary folder, and choose "Show package contents" and then the `dup_backup` folder is revealed.

This is done to keep all photos in the same folder, but avoid messing with the structure of the on-disk Photolibrary.

A future update could allow restoring back into Photos, and metadata is captured for each image to eventually allow this.

This fixes #6381
2025-11-17 17:12:10 +01:00
..
2025-11-14 15:05:39 +01:00
2025-11-17 17:12:10 +01:00
2025-04-14 22:31:49 +02:00
2025-04-14 22:24:23 +02:00
2025-11-14 15:05:39 +01:00
2025-11-14 15:05:39 +01:00
2025-01-16 21:24:18 +01:00

Release Builder tool

This folder contains the ReleaseBuilder tool which builds installers and packages for all supported operating systems.

The tool is tested and used only on MacOS, but can be configured for other operating systems, including WSL and to some extent Windows.

The setup is a mix of environment variables, settings files and commandline arguments.

Required environment

The environment variables used by the tool are:

  • UPDATER_KEYFILE: The file containing the key used to sign the manifest. Create one with the create-key command.
  • GPG_KEYFILE: A file encrypted with AESCrypt and the general password. The file has two lines: GPGID and GPGPassphrase which are given to the GPG command.
  • AUTHENTICODE_PFXFILE: A PFX file containing a signing key for Authenticode signing of Windows executables (needs to be purchased at a certificate vendor).
  • AUTHENTICODE_PASSWORD: A file encrypted with AESCrypt and the general password. The file contains a single line, which is the password used for osslsigncode
  • GITHUB_TOKEN_FILE: A personal access token for Github API used to create releases and upload packages to Github.
  • DISCOURSE_TOKEN_FILE: A personal access token for Discourse, used to create release posts.
  • CODESIGN_IDENTITY: The identity used for MacOS codesign when signing the binary packages.
  • NOTARIZE_PROFILE: The name of the profile used for notarizing MacOS packages.
  • AWS_UPLOAD_PROFILE: The name of the AWS profile (from aws-cli) used to upload packages.
  • AWS_UPLOAD_BUCKET: The name of the bucket where the package are uploaded to.
  • RELOAD_UPDATES_API_KEY: A key used to refresh the manifest files being cached by the update servers.

Tools used

These tools are used by the build process, each tool can be changed by using the environment variable name:

  • DOTNET=dotnet: Mandatory. Used to build the binary contents that will be packaged.
  • GPG=gpg: Optional. Used to created signed release files.
  • SIGNTOOL=osslsigncode: Optional. Used to make Authenticode signing of Windows executables (using SIGNTOOL=signtool.exe on Windows)
  • CODESIGN=codesign: Optional. Used to sign MacOS binaries and packages.
  • PRODUCTSIGN=productsign: Optional. Used to sign MacOS packages.
  • WIX=wixl: Optional. Required to build the Windows MSI packages.
  • DOCKER=docker: Optional. Required to build some Linux packages.

Invoking the tool

The tool has commandline documentation, which can be invoked with dotnet run help.

The two commands that are currently implemented are:

  • dotnet run create-key
  • dotnet run build <channel>

The create-key command creates a RSA 1024 bit signing, and encrypts it with the given password.

The build command creates the packages. An example command that builds all packages would be:

dotnet run build debug --version 1.0.0.1

To build only a single platform relase, disable all the features and choose the architectures:

dotnet run build debug --version 1.0.0.1 \
    --disable-docker-push true \
    --keep-builds true \
    --disable-authenticode true \
    --disable-signcode true \
    --disable-notarize-signing true \
    --disable-gpg-signing true \
    --disable-s3-upload true \
    --disable-github-upload true \
    --disable-update-server-reload true \
    --disable-discourse-announce true \
    --targets win-x86-gui.zip \
    --targets win-x64-gui.zip \