borgbackup: Update to version 1.4.5

Message ID 20261007105658.104404-3-adolf.belka@ipfire.org
State New
Headers
Series borgbackup: Update to version 1.4.5 |

Commit Message

Adolf Belka 7 Oct 2026, 10:56 a.m. UTC
- Update from version 1.4.1 to 1.4.5
- Update of rootfile
- 1 CVE fix in 1.4.5
- patch to remove reference to python 3.14 otherwise build fails as a module has a name
   change in python 3.14. Borgbackup is still able to be built with python 3.10 or newer
- Changelog
1.4.5
  New features:
    create/import-tar/delete/prune --quick-stats: faster than --stats by omitting
	“All archives” and repository chunk statistics, #9579, #9757
    prune: show total vs matching archives in output, #9262
    create --exclude-dataless: macOS: skip cloud files not materialized locally, #9746
    support BORG_HOSTNAME and BORG_USERNAME env vars to override the
	hostname/username stored in archives and used by the {hostname}/{user}
	placeholders, #9651
    Minimal implementation of “related repositories”, #9645
    This feature allows multiple repositories to share deduplication-relevant
     secrets (id_key and chunk_seed) while maintaining secure, independent encryption
     keys.
        borg key export-related-secrets <REPO> <SPATH>
        borg init --import-related-secrets <SPATH> <REPO>
    BORG_JSON_INDENT env var for JSON output formatting, #3605
    BORG_HOSTNAME and BORG_USERNAME env vars, #9651
  Fixes:
    extract: security fixes for CVE-2026-62268 (low severity: attacker would need
	repository write access and, if the repo is encrypted, also borg key and
	passphrase).
    create: do not wrap repository writes in backup_io(“read”), #9854
    Archive.delete: don’t reuse msgpack Unpacker after an unpacking failure
    slashdot hack: fix exclusion of source directory metadata, #9534
    hashindex: fix new checks for big endian archs, #9521
    Note:
        Many of the fixed issues listed below relate to rather rare or theoretical
	 issues and were found by automated code checking.
    LRUCache: resolve KeyError and memory leaks, #9587
    crypto.low_level: fix freeing of memory, #9585
    extract: resolve memory leak on abandoned async requests in RemoteRepository,
	 (#9588). This can happen if borg fails to extract a file due to permission
	 or other errors or if the archived file had all-zero replacement chunks or
	 inconsistent size.
    Chunker fixes, #9586:
        Strictly check the return value of fd.read(n) and reject if it returns more
	 bytes than requested.
        Avoid giving len <= 0 to posix_fadvise(), which could drop the rest of the
	 file from the cache.
        buzhash: check for len == 0 edge case
        Correctly Py_DECREF in cases of errors.
        Check for malloc/calloc failures.
    Hashindex fixes, #9575:
        Make it possible to look up in compacted hashtables.
        Avoid buckets_length integer overflow on 32-bit systems via huge num_buckets.
        Deal safely with empty index: we must use num_buckets = 1 to avoid division
	 by zero and sanity check in hashindex_read.
        Always initialize min_empty and num_empty.
        Reinitialize upper/lower limit and min_empty after compact.
        Fix size_idx / fit_size / grow_size / shrink_size (mind array bounds).
        Deal with growing when already at max capacity.
        hashindex_resize: replace num_entries assertion, return an error instead.
        Correctly free memory when header validation fails.
        BaseIndex.clear: always stay in valid state. Do not free the old index before
	 we successfully have allocated a new one.
  Other changes:
    msgpack: also allow up to 1.2.1
    use F_FULLFSYNC on macOS for SyncFile data durability, #9383
    mount: drop runtime warning about symlinks and improve corresponding docs
    mount: improve error msg when uid/gid cannot be resolved, #9574
    properly handle invalid and dev versions in version parser, fixes #9014
    tests: reset borg.output.progress logger between tests to fix flakiness
    docs:
        borgbackup.readthedocs.io: offer PDF and html downloads in sidebar, #9731
        fix ‘borg key change-passphrase’ docs, #9697
        impact of the slashdot hack on pattern matching, #9647
        pull-backup.rst minor fixes
        sshfs + chroot does not support different CPU architectures, #6878
        document max_segment_size adjustment, #7858
        add section about rolling back a transaction, #9270
        clarify storage quota run-time settings, #3948
        add FAQ entry about scalability, #4742
        add FAQ entry for full repository filesystem, #9573
        add FAQ entry for bad backups and deduplication, #4744
        add FAQ entry for SSH connection timeouts, #5629
        improve macOS Keychain instructions, #5156
        add DoS warning for none encryption mode, #6715
        document error handling in borg create, #4912
        update year in LICENSE and docs/conf.py
1.4.4
  New features:
    prune: added -v / --info output, #9262.
    mount: warn about symlinks pointing outside of the mount point, #9254.
    create/info: remember/show cwd at the time of archive creation, #6191.
  Fixes:
    hashindex: fix memory leak, #9497.
    hashindex: check values in read HashHeader, #9485.
    hashindex_size: return int64_t, #9423.
    hashindex: fix iteritems segfaulting with non-existent marker, #9368. Never
	happened in borg, because borg always gives existing markers to iteritems.
    compress: make Padme size obfuscation usable (“obfuscate,250,…”).
    borgfs/mount: get_base_dir: avoid using incorrect HOME, #3395.
  Other changes:
    PyInstaller binary: do not exclude SSL, needed for pyfuse3/trio, #9196.
    mount: FUSE FS performance improvement.
    warn when replaying segments, #9233.
    CI / tests:
        build Linux binaries with pyfuse3.
        use macOS 15 to build the binaries.
        scripts/linux-run: run commands (e.g. tox) in a Podman Linux container.
        fix race condition in test_with_lock, #8810.
        fix spurious sparse test failure on Win32, #7616.
        Cygwin: skip ~root base dir test.
        fix coverage collection for daemonized borg mount, #9448.
    docs:
        move RTD version selector to sidebar top-left, #8204.
        consolidate key backup info in borg key export help, #6204.
        clarify append-only != write-only, #9304.
        fix typos found by codespell.
        update binary README.
        GitHub: enhance pull request template.
1.4.3
  Fixes:
    compact: replace AssertionError with a warning, #8535.
    compact: also fix segment hints data for lost segment files.
    CI: FUSE-related fixes and improvements, #9182:
        The Linux and FreeBSD binaries built on GitHub now include working FUSE
	 support (based on llfuse).
        We can’t include FUSE support in the macOS binaries built on GitHub, because
	 we can’t install macFUSE there; use our Homebrew tap for that.
  Other changes:
    Drop Python 3.9 support (has reached end of life at python.org).
    CI:
        Install the correct FUSE library depending on the tox environment.
        PyInstaller binary building: build and upload early, then run CI tests.
        For now, use llfuse, as there is an issue with PyInstaller and pyfuse3.
        Backported vm_tests (FreeBSD/NetBSD/OpenBSD/Haiku) from the master branch.
        Dynamic code analysis (Address and Undefined Behavior Sanitizers), #6819.
        Add tag-based workflows and provenance attestation for GitHub-built binaries,
	(#9135, #9136).
    Docs:
        Some fixes and updates to the FAQ, #9188.
        Update binary README; release binaries are built on GitHub now.
1.4.2
  New features:
    BORG_MSGPACK_VERSION_CHECK=no to optionally disable the msgpack version check;
	default is “yes”; use at your own risk, #9109.
    fat binary builds on GitHub (see assets on the GitHub releases page):
        for Linux with glibc 2.35+ (Intel/AMD and ARM64)
        for macOS 14+ (Apple Silicon/ARM64) and macOS 13+ (Intel)
    diff --sort-by: enhanced sorting, #8998
    create: add --files-changed=MODE option (controls how borg detects whether a file
	has changed while it is being backed up)
    improve tty-less progress reporting (--progress)
  Fixes:
    extract: fs flags: use get/set to influence only specific flags, #9039,
	Linux/macOS/FreeBSD only.
    extract: fs flags: remove support for the compression flag; this wasn’t working
	correctly anyway.
    create/info: fix discrepancies in archive stats, #8898, #9003
    import-tar: fix the dot-slash issue; add a test, #8947
    import-tar: when printing the path, use the already-normalized item.path
    preprocess_args: fix option name matching
    fix ChunkerParams validation
    mount --show-rc: display main process rc, #8308
    json: include archive keys in JSON lines when requested via --format, #9095
  Other changes:
    support Python 3.14
    msgpack: allow 1.1.2
    Brewfile: use openssl@3 rather than openssl@3.0, to have a more recent OpenSSL.
    msgpack version check: ignore “rc” and other version elements
    pyproject.toml: use SPDX expression for license, add license-files, #8771. Also
	raise the setuptools version requirement appropriately.
    If the setuptools requirement is problematic when packaging borg for an OS
	distribution that must use an older setuptools, apply a reverse patch when
	packaging borg; using an older setuptools should not be a problem.
    Chunker params: warn about an even window size for buzhash, #8868
    suppress compiler warning about CYTHON_FALLTHROUGH
    remove unnecessary check that Padmé overhead is at most 12%
    PyInstaller spec: avoid pkg_resources warning
    update requirements.lock.txt to current versions
    docs:
        borg-serve: simplify example of environment variables in authorized_keys, #8318
        unify master and 1.4-maint installation docs
        update install docs to include SETUPTOOLS_SCM_PRETEND_VERSION
        add Arch Linux to the “Installing from source” docs
        add systemd-inhibit and examples, #8989
        fix typos / grammar in docs and code
        document how to debug borg mount, #5461
        document what happens when a new keyfile repo is created at the same path, #6230
        borg serve: recommend using a simple shell, #8318
        update the README for the binaries
        extract: document how to use wildcards in PATHs, #8589
        improve borg help patterns, #7144
        clarify the scope of the default pattern style, #9004
        explain how to get maximum compaction with --threshold 0 and trade-offs,
	 (#9112, #8716)
        rewrite borg init --encryption docs
    tests:
        save temporary space
        test_chunkpoints_unchanged: do not use blake2b_256
        fix diff command test on macOS HFS+, #8860
        fuzzing test for default chunker
        read_only CM: skip test if cmd_immutable is unsuccessful, #9021
        pyproject.toml: correctly define test environments for FUSE testing
        coverage/tox: use pyproject.toml, disable no-ctracer warning
        CI: speed up pull requests
        vagrant:
            use Python 3.11.14
            add debian trixie box
            drop broken/EOL debian buster VM / borg-linux-glibc228
            drop outdated/slow/unsupported macOS 10.12 VM / borg-macos1012 (Intel)
            add an OpenBSD 7.7 box
            try to fix OpenIndiana box, please see #9118

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/packages/borgbackup | 19 +++++++++++--------
 lfs/borgbackup                       |  9 +++++----
 2 files changed, 16 insertions(+), 12 deletions(-)
  

Patch

diff --git a/config/rootfiles/packages/borgbackup b/config/rootfiles/packages/borgbackup
index d17f41212..bd804e2fa 100644
--- a/config/rootfiles/packages/borgbackup
+++ b/config/rootfiles/packages/borgbackup
@@ -73,8 +73,9 @@  usr/lib/python3.10/site-packages/borg/testsuite/crypto.py
 usr/lib/python3.10/site-packages/borg/testsuite/efficient_collection_queue.py
 usr/lib/python3.10/site-packages/borg/testsuite/file_integrity.py
 usr/lib/python3.10/site-packages/borg/testsuite/hashindex.py
-usr/lib/python3.10/site-packages/borg/testsuite/hashindex_stress.py
+usr/lib/python3.10/site-packages/borg/testsuite/hashindex_pytest.py
 usr/lib/python3.10/site-packages/borg/testsuite/helpers.py
+usr/lib/python3.10/site-packages/borg/testsuite/issue_8535.py
 usr/lib/python3.10/site-packages/borg/testsuite/item.py
 usr/lib/python3.10/site-packages/borg/testsuite/key.py
 usr/lib/python3.10/site-packages/borg/testsuite/locking.py
@@ -93,10 +94,12 @@  usr/lib/python3.10/site-packages/borg/testsuite/xattr.py
 usr/lib/python3.10/site-packages/borg/upgrader.py
 usr/lib/python3.10/site-packages/borg/version.py
 usr/lib/python3.10/site-packages/borg/xattr.py
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/PKG-INFO
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/SOURCES.txt
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/dependency_links.txt
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/entry_points.txt
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/requires.txt
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/top_level.txt
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/PKG-INFO
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/SOURCES.txt
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/dependency_links.txt
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/entry_points.txt
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/requires.txt
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/scm_file_list.json
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/scm_version.json
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/top_level.txt
diff --git a/lfs/borgbackup b/lfs/borgbackup
index 2e64177e9..5fe2eaaaf 100644
--- a/lfs/borgbackup
+++ b/lfs/borgbackup
@@ -1,7 +1,7 @@ 
 ###############################################################################
 #                                                                             #
 # IPFire.org - A linux based firewall                                         #
-# Copyright (C) 2007-2025  IPFire Team  <info@ipfire.org>                     #
+# Copyright (C) 2007-2026  IPFire Team  <info@ipfire.org>                     #
 #                                                                             #
 # This program is free software: you can redistribute it and/or modify        #
 # it under the terms of the GNU General Public License as published by        #
@@ -24,7 +24,7 @@ 
 
 include Config
 
-VER        = 1.4.1
+VER        = 1.4.5
 SUMMARY    = Deduplicating backup program with compression and authenticated encryption
 
 THISAPP    = borgbackup-$(VER)
@@ -33,7 +33,7 @@  DL_FROM    = $(URL_IPFIRE)
 DIR_APP    = $(DIR_SRC)/$(THISAPP)
 TARGET     = $(DIR_INFO)/$(THISAPP)
 PROG       = borgbackup
-PAK_VER    = 19
+PAK_VER    = 20
 
 DEPS       = python3-msgpack python3-packaging python3-pyfuse3 libxxhash
 # borgbackup only works with specific versions of python3-msgpack
@@ -48,7 +48,7 @@  objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = fbf5cd06bcddd5b90db75ed1b2276d2eba0d17d0545a751acfd40d051053d9d3e1a0ea2f1dd87e6541aeca6199e98ad1885b9d3155696268752069b763b660a4
+$(DL_FILE)_BLAKE2 = 4a72bf303edb3fc680ef90000a4183e6951c5995a15abe1e1f9a330a6d0e57ca236ec5ebc2b4f46e89b272cb14b4d6e73b62c041310a7461d2c83679c6cf974f
 
 install : $(TARGET)
 
@@ -81,6 +81,7 @@  $(subst %,%_BLAKE2,$(objects)) :
 $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
 	@$(PREBUILD)
 	@rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar zxf $(DIR_DL)/$(DL_FILE)
+	cd $(DIR_APP) && patch -Np1 < $(DIR_SRC)/src/patches/borgbackup-1.4.5_remove_python_3.14_reference.patch
 	cd $(DIR_APP) && python3 setup.py build
 	cd $(DIR_APP) && python3 setup.py install --root=/
 	@rm -rf $(DIR_APP)