- Update from version 1.4.1 to 1.4.5
- Update of rootfile
- 1 CVE fix in 1.4.5
- patch to remove reference to python 3.14 otherwise build fails as a module has a name
change in python 3.14. Borgbackup is still able to be built with python 3.10 or newer
- Changelog
1.4.5
New features:
create/import-tar/delete/prune --quick-stats: faster than --stats by omitting
“All archives” and repository chunk statistics, #9579, #9757
prune: show total vs matching archives in output, #9262
create --exclude-dataless: macOS: skip cloud files not materialized locally, #9746
support BORG_HOSTNAME and BORG_USERNAME env vars to override the
hostname/username stored in archives and used by the {hostname}/{user}
placeholders, #9651
Minimal implementation of “related repositories”, #9645
This feature allows multiple repositories to share deduplication-relevant
secrets (id_key and chunk_seed) while maintaining secure, independent encryption
keys.
borg key export-related-secrets <REPO> <SPATH>
borg init --import-related-secrets <SPATH> <REPO>
BORG_JSON_INDENT env var for JSON output formatting, #3605
BORG_HOSTNAME and BORG_USERNAME env vars, #9651
Fixes:
extract: security fixes for CVE-2026-62268 (low severity: attacker would need
repository write access and, if the repo is encrypted, also borg key and
passphrase).
create: do not wrap repository writes in backup_io(“read”), #9854
Archive.delete: don’t reuse msgpack Unpacker after an unpacking failure
slashdot hack: fix exclusion of source directory metadata, #9534
hashindex: fix new checks for big endian archs, #9521
Note:
Many of the fixed issues listed below relate to rather rare or theoretical
issues and were found by automated code checking.
LRUCache: resolve KeyError and memory leaks, #9587
crypto.low_level: fix freeing of memory, #9585
extract: resolve memory leak on abandoned async requests in RemoteRepository,
(#9588). This can happen if borg fails to extract a file due to permission
or other errors or if the archived file had all-zero replacement chunks or
inconsistent size.
Chunker fixes, #9586:
Strictly check the return value of fd.read(n) and reject if it returns more
bytes than requested.
Avoid giving len <= 0 to posix_fadvise(), which could drop the rest of the
file from the cache.
buzhash: check for len == 0 edge case
Correctly Py_DECREF in cases of errors.
Check for malloc/calloc failures.
Hashindex fixes, #9575:
Make it possible to look up in compacted hashtables.
Avoid buckets_length integer overflow on 32-bit systems via huge num_buckets.
Deal safely with empty index: we must use num_buckets = 1 to avoid division
by zero and sanity check in hashindex_read.
Always initialize min_empty and num_empty.
Reinitialize upper/lower limit and min_empty after compact.
Fix size_idx / fit_size / grow_size / shrink_size (mind array bounds).
Deal with growing when already at max capacity.
hashindex_resize: replace num_entries assertion, return an error instead.
Correctly free memory when header validation fails.
BaseIndex.clear: always stay in valid state. Do not free the old index before
we successfully have allocated a new one.
Other changes:
msgpack: also allow up to 1.2.1
use F_FULLFSYNC on macOS for SyncFile data durability, #9383
mount: drop runtime warning about symlinks and improve corresponding docs
mount: improve error msg when uid/gid cannot be resolved, #9574
properly handle invalid and dev versions in version parser, fixes #9014
tests: reset borg.output.progress logger between tests to fix flakiness
docs:
borgbackup.readthedocs.io: offer PDF and html downloads in sidebar, #9731
fix ‘borg key change-passphrase’ docs, #9697
impact of the slashdot hack on pattern matching, #9647
pull-backup.rst minor fixes
sshfs + chroot does not support different CPU architectures, #6878
document max_segment_size adjustment, #7858
add section about rolling back a transaction, #9270
clarify storage quota run-time settings, #3948
add FAQ entry about scalability, #4742
add FAQ entry for full repository filesystem, #9573
add FAQ entry for bad backups and deduplication, #4744
add FAQ entry for SSH connection timeouts, #5629
improve macOS Keychain instructions, #5156
add DoS warning for none encryption mode, #6715
document error handling in borg create, #4912
update year in LICENSE and docs/conf.py
1.4.4
New features:
prune: added -v / --info output, #9262.
mount: warn about symlinks pointing outside of the mount point, #9254.
create/info: remember/show cwd at the time of archive creation, #6191.
Fixes:
hashindex: fix memory leak, #9497.
hashindex: check values in read HashHeader, #9485.
hashindex_size: return int64_t, #9423.
hashindex: fix iteritems segfaulting with non-existent marker, #9368. Never
happened in borg, because borg always gives existing markers to iteritems.
compress: make Padme size obfuscation usable (“obfuscate,250,…”).
borgfs/mount: get_base_dir: avoid using incorrect HOME, #3395.
Other changes:
PyInstaller binary: do not exclude SSL, needed for pyfuse3/trio, #9196.
mount: FUSE FS performance improvement.
warn when replaying segments, #9233.
CI / tests:
build Linux binaries with pyfuse3.
use macOS 15 to build the binaries.
scripts/linux-run: run commands (e.g. tox) in a Podman Linux container.
fix race condition in test_with_lock, #8810.
fix spurious sparse test failure on Win32, #7616.
Cygwin: skip ~root base dir test.
fix coverage collection for daemonized borg mount, #9448.
docs:
move RTD version selector to sidebar top-left, #8204.
consolidate key backup info in borg key export help, #6204.
clarify append-only != write-only, #9304.
fix typos found by codespell.
update binary README.
GitHub: enhance pull request template.
1.4.3
Fixes:
compact: replace AssertionError with a warning, #8535.
compact: also fix segment hints data for lost segment files.
CI: FUSE-related fixes and improvements, #9182:
The Linux and FreeBSD binaries built on GitHub now include working FUSE
support (based on llfuse).
We can’t include FUSE support in the macOS binaries built on GitHub, because
we can’t install macFUSE there; use our Homebrew tap for that.
Other changes:
Drop Python 3.9 support (has reached end of life at python.org).
CI:
Install the correct FUSE library depending on the tox environment.
PyInstaller binary building: build and upload early, then run CI tests.
For now, use llfuse, as there is an issue with PyInstaller and pyfuse3.
Backported vm_tests (FreeBSD/NetBSD/OpenBSD/Haiku) from the master branch.
Dynamic code analysis (Address and Undefined Behavior Sanitizers), #6819.
Add tag-based workflows and provenance attestation for GitHub-built binaries,
(#9135, #9136).
Docs:
Some fixes and updates to the FAQ, #9188.
Update binary README; release binaries are built on GitHub now.
1.4.2
New features:
BORG_MSGPACK_VERSION_CHECK=no to optionally disable the msgpack version check;
default is “yes”; use at your own risk, #9109.
fat binary builds on GitHub (see assets on the GitHub releases page):
for Linux with glibc 2.35+ (Intel/AMD and ARM64)
for macOS 14+ (Apple Silicon/ARM64) and macOS 13+ (Intel)
diff --sort-by: enhanced sorting, #8998
create: add --files-changed=MODE option (controls how borg detects whether a file
has changed while it is being backed up)
improve tty-less progress reporting (--progress)
Fixes:
extract: fs flags: use get/set to influence only specific flags, #9039,
Linux/macOS/FreeBSD only.
extract: fs flags: remove support for the compression flag; this wasn’t working
correctly anyway.
create/info: fix discrepancies in archive stats, #8898, #9003
import-tar: fix the dot-slash issue; add a test, #8947
import-tar: when printing the path, use the already-normalized item.path
preprocess_args: fix option name matching
fix ChunkerParams validation
mount --show-rc: display main process rc, #8308
json: include archive keys in JSON lines when requested via --format, #9095
Other changes:
support Python 3.14
msgpack: allow 1.1.2
Brewfile: use openssl@3 rather than openssl@3.0, to have a more recent OpenSSL.
msgpack version check: ignore “rc” and other version elements
pyproject.toml: use SPDX expression for license, add license-files, #8771. Also
raise the setuptools version requirement appropriately.
If the setuptools requirement is problematic when packaging borg for an OS
distribution that must use an older setuptools, apply a reverse patch when
packaging borg; using an older setuptools should not be a problem.
Chunker params: warn about an even window size for buzhash, #8868
suppress compiler warning about CYTHON_FALLTHROUGH
remove unnecessary check that Padmé overhead is at most 12%
PyInstaller spec: avoid pkg_resources warning
update requirements.lock.txt to current versions
docs:
borg-serve: simplify example of environment variables in authorized_keys, #8318
unify master and 1.4-maint installation docs
update install docs to include SETUPTOOLS_SCM_PRETEND_VERSION
add Arch Linux to the “Installing from source” docs
add systemd-inhibit and examples, #8989
fix typos / grammar in docs and code
document how to debug borg mount, #5461
document what happens when a new keyfile repo is created at the same path, #6230
borg serve: recommend using a simple shell, #8318
update the README for the binaries
extract: document how to use wildcards in PATHs, #8589
improve borg help patterns, #7144
clarify the scope of the default pattern style, #9004
explain how to get maximum compaction with --threshold 0 and trade-offs,
(#9112, #8716)
rewrite borg init --encryption docs
tests:
save temporary space
test_chunkpoints_unchanged: do not use blake2b_256
fix diff command test on macOS HFS+, #8860
fuzzing test for default chunker
read_only CM: skip test if cmd_immutable is unsuccessful, #9021
pyproject.toml: correctly define test environments for FUSE testing
coverage/tox: use pyproject.toml, disable no-ctracer warning
CI: speed up pull requests
vagrant:
use Python 3.11.14
add debian trixie box
drop broken/EOL debian buster VM / borg-linux-glibc228
drop outdated/slow/unsupported macOS 10.12 VM / borg-macos1012 (Intel)
add an OpenBSD 7.7 box
try to fix OpenIndiana box, please see #9118
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/packages/borgbackup | 19 +++++++++++--------
lfs/borgbackup | 9 +++++----
2 files changed, 16 insertions(+), 12 deletions(-)
@@ -73,8 +73,9 @@ usr/lib/python3.10/site-packages/borg/testsuite/crypto.py
usr/lib/python3.10/site-packages/borg/testsuite/efficient_collection_queue.py
usr/lib/python3.10/site-packages/borg/testsuite/file_integrity.py
usr/lib/python3.10/site-packages/borg/testsuite/hashindex.py
-usr/lib/python3.10/site-packages/borg/testsuite/hashindex_stress.py
+usr/lib/python3.10/site-packages/borg/testsuite/hashindex_pytest.py
usr/lib/python3.10/site-packages/borg/testsuite/helpers.py
+usr/lib/python3.10/site-packages/borg/testsuite/issue_8535.py
usr/lib/python3.10/site-packages/borg/testsuite/item.py
usr/lib/python3.10/site-packages/borg/testsuite/key.py
usr/lib/python3.10/site-packages/borg/testsuite/locking.py
@@ -93,10 +94,12 @@ usr/lib/python3.10/site-packages/borg/testsuite/xattr.py
usr/lib/python3.10/site-packages/borg/upgrader.py
usr/lib/python3.10/site-packages/borg/version.py
usr/lib/python3.10/site-packages/borg/xattr.py
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/PKG-INFO
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/SOURCES.txt
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/dependency_links.txt
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/entry_points.txt
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/requires.txt
-usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/top_level.txt
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/PKG-INFO
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/SOURCES.txt
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/dependency_links.txt
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/entry_points.txt
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/requires.txt
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/scm_file_list.json
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/scm_version.json
+usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/top_level.txt
@@ -1,7 +1,7 @@
###############################################################################
# #
# IPFire.org - A linux based firewall #
-# Copyright (C) 2007-2025 IPFire Team <info@ipfire.org> #
+# Copyright (C) 2007-2026 IPFire Team <info@ipfire.org> #
# #
# This program is free software: you can redistribute it and/or modify #
# it under the terms of the GNU General Public License as published by #
@@ -24,7 +24,7 @@
include Config
-VER = 1.4.1
+VER = 1.4.5
SUMMARY = Deduplicating backup program with compression and authenticated encryption
THISAPP = borgbackup-$(VER)
@@ -33,7 +33,7 @@ DL_FROM = $(URL_IPFIRE)
DIR_APP = $(DIR_SRC)/$(THISAPP)
TARGET = $(DIR_INFO)/$(THISAPP)
PROG = borgbackup
-PAK_VER = 19
+PAK_VER = 20
DEPS = python3-msgpack python3-packaging python3-pyfuse3 libxxhash
# borgbackup only works with specific versions of python3-msgpack
@@ -48,7 +48,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = fbf5cd06bcddd5b90db75ed1b2276d2eba0d17d0545a751acfd40d051053d9d3e1a0ea2f1dd87e6541aeca6199e98ad1885b9d3155696268752069b763b660a4
+$(DL_FILE)_BLAKE2 = 4a72bf303edb3fc680ef90000a4183e6951c5995a15abe1e1f9a330a6d0e57ca236ec5ebc2b4f46e89b272cb14b4d6e73b62c041310a7461d2c83679c6cf974f
install : $(TARGET)
@@ -81,6 +81,7 @@ $(subst %,%_BLAKE2,$(objects)) :
$(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
@$(PREBUILD)
@rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar zxf $(DIR_DL)/$(DL_FILE)
+ cd $(DIR_APP) && patch -Np1 < $(DIR_SRC)/src/patches/borgbackup-1.4.5_remove_python_3.14_reference.patch
cd $(DIR_APP) && python3 setup.py build
cd $(DIR_APP) && python3 setup.py install --root=/
@rm -rf $(DIR_APP)