From patchwork Wed Oct 7 10:56:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Adolf Belka X-Patchwork-Id: 10314 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4j097H2tcGz3wr8 for ; Wed, 07 Oct 2026 10:57:15 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE2" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4j097H07TBz85f for ; Wed, 07 Oct 2026 10:57:15 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4j097D6dh0z32c1 for ; Wed, 07 Oct 2026 10:57:12 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4j09795Flvz339h for ; Wed, 07 Oct 2026 10:57:09 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4j09732WQ3z3db; Wed, 07 Oct 2026 10:57:03 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1791370623; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Ff1Kd2zw7m3ebGCcL9EdPAWNNGtkNlkFPq6TD5sTgOE=; b=AQMXJeg3GEflJxw+mLA+bbnp3O9ha8EWJLksat1dWidM6Uweob0DRO+yfS6kc7vWLJtsWK FBfqoEezMhVbgpCg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1791370623; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Ff1Kd2zw7m3ebGCcL9EdPAWNNGtkNlkFPq6TD5sTgOE=; b=EFJpz6Cy8KbSKQIAF/3eJOuSKdLpV+3YznBTGI/f96C+UuNnMXM/KCJp94fz/T1x4csYdj 7qo19yufllblLscE3k/oH0fYEjoF4M1NbD1R1Wyv9l912NJu+ztbueqYhuQmMhfGEAsa+u zXNhvglLl4bVmDDvMafhtJS8qYTFanUthmEmze9X3f9eTt0AP0yRomKoXihgoF3anAL/Iq QaaZl/3cCdHBxHAF6TAHjs8SpWU7ua5gmEIjRG3OqPi/Eyik52VbuyitpnT8ICOEybwu+D SQGSyoZk4lMKxHoXVcvHzZdIOXY9c8QB2P+e13reOoITVJN1oSJ1J+lct6m8Qw== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] borgbackup: Update to version 1.4.5 Date: Wed, 7 Oct 2026 12:56:51 +0200 Message-ID: <20261007105658.104404-3-adolf.belka@ipfire.org> In-Reply-To: <20261007105658.104404-1-adolf.belka@ipfire.org> References: <20261007105658.104404-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 - Update from version 1.4.1 to 1.4.5 - Update of rootfile - 1 CVE fix in 1.4.5 - patch to remove reference to python 3.14 otherwise build fails as a module has a name change in python 3.14. Borgbackup is still able to be built with python 3.10 or newer - Changelog 1.4.5 New features: create/import-tar/delete/prune --quick-stats: faster than --stats by omitting “All archives” and repository chunk statistics, #9579, #9757 prune: show total vs matching archives in output, #9262 create --exclude-dataless: macOS: skip cloud files not materialized locally, #9746 support BORG_HOSTNAME and BORG_USERNAME env vars to override the hostname/username stored in archives and used by the {hostname}/{user} placeholders, #9651 Minimal implementation of “related repositories”, #9645 This feature allows multiple repositories to share deduplication-relevant secrets (id_key and chunk_seed) while maintaining secure, independent encryption keys. borg key export-related-secrets borg init --import-related-secrets BORG_JSON_INDENT env var for JSON output formatting, #3605 BORG_HOSTNAME and BORG_USERNAME env vars, #9651 Fixes: extract: security fixes for CVE-2026-62268 (low severity: attacker would need repository write access and, if the repo is encrypted, also borg key and passphrase). create: do not wrap repository writes in backup_io(“read”), #9854 Archive.delete: don’t reuse msgpack Unpacker after an unpacking failure slashdot hack: fix exclusion of source directory metadata, #9534 hashindex: fix new checks for big endian archs, #9521 Note: Many of the fixed issues listed below relate to rather rare or theoretical issues and were found by automated code checking. LRUCache: resolve KeyError and memory leaks, #9587 crypto.low_level: fix freeing of memory, #9585 extract: resolve memory leak on abandoned async requests in RemoteRepository, (#9588). This can happen if borg fails to extract a file due to permission or other errors or if the archived file had all-zero replacement chunks or inconsistent size. Chunker fixes, #9586: Strictly check the return value of fd.read(n) and reject if it returns more bytes than requested. Avoid giving len <= 0 to posix_fadvise(), which could drop the rest of the file from the cache. buzhash: check for len == 0 edge case Correctly Py_DECREF in cases of errors. Check for malloc/calloc failures. Hashindex fixes, #9575: Make it possible to look up in compacted hashtables. Avoid buckets_length integer overflow on 32-bit systems via huge num_buckets. Deal safely with empty index: we must use num_buckets = 1 to avoid division by zero and sanity check in hashindex_read. Always initialize min_empty and num_empty. Reinitialize upper/lower limit and min_empty after compact. Fix size_idx / fit_size / grow_size / shrink_size (mind array bounds). Deal with growing when already at max capacity. hashindex_resize: replace num_entries assertion, return an error instead. Correctly free memory when header validation fails. BaseIndex.clear: always stay in valid state. Do not free the old index before we successfully have allocated a new one. Other changes: msgpack: also allow up to 1.2.1 use F_FULLFSYNC on macOS for SyncFile data durability, #9383 mount: drop runtime warning about symlinks and improve corresponding docs mount: improve error msg when uid/gid cannot be resolved, #9574 properly handle invalid and dev versions in version parser, fixes #9014 tests: reset borg.output.progress logger between tests to fix flakiness docs: borgbackup.readthedocs.io: offer PDF and html downloads in sidebar, #9731 fix ‘borg key change-passphrase’ docs, #9697 impact of the slashdot hack on pattern matching, #9647 pull-backup.rst minor fixes sshfs + chroot does not support different CPU architectures, #6878 document max_segment_size adjustment, #7858 add section about rolling back a transaction, #9270 clarify storage quota run-time settings, #3948 add FAQ entry about scalability, #4742 add FAQ entry for full repository filesystem, #9573 add FAQ entry for bad backups and deduplication, #4744 add FAQ entry for SSH connection timeouts, #5629 improve macOS Keychain instructions, #5156 add DoS warning for none encryption mode, #6715 document error handling in borg create, #4912 update year in LICENSE and docs/conf.py 1.4.4 New features: prune: added -v / --info output, #9262. mount: warn about symlinks pointing outside of the mount point, #9254. create/info: remember/show cwd at the time of archive creation, #6191. Fixes: hashindex: fix memory leak, #9497. hashindex: check values in read HashHeader, #9485. hashindex_size: return int64_t, #9423. hashindex: fix iteritems segfaulting with non-existent marker, #9368. Never happened in borg, because borg always gives existing markers to iteritems. compress: make Padme size obfuscation usable (“obfuscate,250,…”). borgfs/mount: get_base_dir: avoid using incorrect HOME, #3395. Other changes: PyInstaller binary: do not exclude SSL, needed for pyfuse3/trio, #9196. mount: FUSE FS performance improvement. warn when replaying segments, #9233. CI / tests: build Linux binaries with pyfuse3. use macOS 15 to build the binaries. scripts/linux-run: run commands (e.g. tox) in a Podman Linux container. fix race condition in test_with_lock, #8810. fix spurious sparse test failure on Win32, #7616. Cygwin: skip ~root base dir test. fix coverage collection for daemonized borg mount, #9448. docs: move RTD version selector to sidebar top-left, #8204. consolidate key backup info in borg key export help, #6204. clarify append-only != write-only, #9304. fix typos found by codespell. update binary README. GitHub: enhance pull request template. 1.4.3 Fixes: compact: replace AssertionError with a warning, #8535. compact: also fix segment hints data for lost segment files. CI: FUSE-related fixes and improvements, #9182: The Linux and FreeBSD binaries built on GitHub now include working FUSE support (based on llfuse). We can’t include FUSE support in the macOS binaries built on GitHub, because we can’t install macFUSE there; use our Homebrew tap for that. Other changes: Drop Python 3.9 support (has reached end of life at python.org). CI: Install the correct FUSE library depending on the tox environment. PyInstaller binary building: build and upload early, then run CI tests. For now, use llfuse, as there is an issue with PyInstaller and pyfuse3. Backported vm_tests (FreeBSD/NetBSD/OpenBSD/Haiku) from the master branch. Dynamic code analysis (Address and Undefined Behavior Sanitizers), #6819. Add tag-based workflows and provenance attestation for GitHub-built binaries, (#9135, #9136). Docs: Some fixes and updates to the FAQ, #9188. Update binary README; release binaries are built on GitHub now. 1.4.2 New features: BORG_MSGPACK_VERSION_CHECK=no to optionally disable the msgpack version check; default is “yes”; use at your own risk, #9109. fat binary builds on GitHub (see assets on the GitHub releases page): for Linux with glibc 2.35+ (Intel/AMD and ARM64) for macOS 14+ (Apple Silicon/ARM64) and macOS 13+ (Intel) diff --sort-by: enhanced sorting, #8998 create: add --files-changed=MODE option (controls how borg detects whether a file has changed while it is being backed up) improve tty-less progress reporting (--progress) Fixes: extract: fs flags: use get/set to influence only specific flags, #9039, Linux/macOS/FreeBSD only. extract: fs flags: remove support for the compression flag; this wasn’t working correctly anyway. create/info: fix discrepancies in archive stats, #8898, #9003 import-tar: fix the dot-slash issue; add a test, #8947 import-tar: when printing the path, use the already-normalized item.path preprocess_args: fix option name matching fix ChunkerParams validation mount --show-rc: display main process rc, #8308 json: include archive keys in JSON lines when requested via --format, #9095 Other changes: support Python 3.14 msgpack: allow 1.1.2 Brewfile: use openssl@3 rather than openssl@3.0, to have a more recent OpenSSL. msgpack version check: ignore “rc” and other version elements pyproject.toml: use SPDX expression for license, add license-files, #8771. Also raise the setuptools version requirement appropriately. If the setuptools requirement is problematic when packaging borg for an OS distribution that must use an older setuptools, apply a reverse patch when packaging borg; using an older setuptools should not be a problem. Chunker params: warn about an even window size for buzhash, #8868 suppress compiler warning about CYTHON_FALLTHROUGH remove unnecessary check that Padmé overhead is at most 12% PyInstaller spec: avoid pkg_resources warning update requirements.lock.txt to current versions docs: borg-serve: simplify example of environment variables in authorized_keys, #8318 unify master and 1.4-maint installation docs update install docs to include SETUPTOOLS_SCM_PRETEND_VERSION add Arch Linux to the “Installing from source” docs add systemd-inhibit and examples, #8989 fix typos / grammar in docs and code document how to debug borg mount, #5461 document what happens when a new keyfile repo is created at the same path, #6230 borg serve: recommend using a simple shell, #8318 update the README for the binaries extract: document how to use wildcards in PATHs, #8589 improve borg help patterns, #7144 clarify the scope of the default pattern style, #9004 explain how to get maximum compaction with --threshold 0 and trade-offs, (#9112, #8716) rewrite borg init --encryption docs tests: save temporary space test_chunkpoints_unchanged: do not use blake2b_256 fix diff command test on macOS HFS+, #8860 fuzzing test for default chunker read_only CM: skip test if cmd_immutable is unsuccessful, #9021 pyproject.toml: correctly define test environments for FUSE testing coverage/tox: use pyproject.toml, disable no-ctracer warning CI: speed up pull requests vagrant: use Python 3.11.14 add debian trixie box drop broken/EOL debian buster VM / borg-linux-glibc228 drop outdated/slow/unsupported macOS 10.12 VM / borg-macos1012 (Intel) add an OpenBSD 7.7 box try to fix OpenIndiana box, please see #9118 Signed-off-by: Adolf Belka --- config/rootfiles/packages/borgbackup | 19 +++++++++++-------- lfs/borgbackup | 9 +++++---- 2 files changed, 16 insertions(+), 12 deletions(-) diff --git a/config/rootfiles/packages/borgbackup b/config/rootfiles/packages/borgbackup index d17f41212..bd804e2fa 100644 --- a/config/rootfiles/packages/borgbackup +++ b/config/rootfiles/packages/borgbackup @@ -73,8 +73,9 @@ usr/lib/python3.10/site-packages/borg/testsuite/crypto.py usr/lib/python3.10/site-packages/borg/testsuite/efficient_collection_queue.py usr/lib/python3.10/site-packages/borg/testsuite/file_integrity.py usr/lib/python3.10/site-packages/borg/testsuite/hashindex.py -usr/lib/python3.10/site-packages/borg/testsuite/hashindex_stress.py +usr/lib/python3.10/site-packages/borg/testsuite/hashindex_pytest.py usr/lib/python3.10/site-packages/borg/testsuite/helpers.py +usr/lib/python3.10/site-packages/borg/testsuite/issue_8535.py usr/lib/python3.10/site-packages/borg/testsuite/item.py usr/lib/python3.10/site-packages/borg/testsuite/key.py usr/lib/python3.10/site-packages/borg/testsuite/locking.py @@ -93,10 +94,12 @@ usr/lib/python3.10/site-packages/borg/testsuite/xattr.py usr/lib/python3.10/site-packages/borg/upgrader.py usr/lib/python3.10/site-packages/borg/version.py usr/lib/python3.10/site-packages/borg/xattr.py -usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info -usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/PKG-INFO -usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/SOURCES.txt -usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/dependency_links.txt -usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/entry_points.txt -usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/requires.txt -usr/lib/python3.10/site-packages/borgbackup-1.4.1-py3.10.egg-info/top_level.txt +usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info +usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/PKG-INFO +usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/SOURCES.txt +usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/dependency_links.txt +usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/entry_points.txt +usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/requires.txt +usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/scm_file_list.json +usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/scm_version.json +usr/lib/python3.10/site-packages/borgbackup-1.4.5-py3.10.egg-info/top_level.txt diff --git a/lfs/borgbackup b/lfs/borgbackup index 2e64177e9..5fe2eaaaf 100644 --- a/lfs/borgbackup +++ b/lfs/borgbackup @@ -1,7 +1,7 @@ ############################################################################### # # # IPFire.org - A linux based firewall # -# Copyright (C) 2007-2025 IPFire Team # +# Copyright (C) 2007-2026 IPFire Team # # # # This program is free software: you can redistribute it and/or modify # # it under the terms of the GNU General Public License as published by # @@ -24,7 +24,7 @@ include Config -VER = 1.4.1 +VER = 1.4.5 SUMMARY = Deduplicating backup program with compression and authenticated encryption THISAPP = borgbackup-$(VER) @@ -33,7 +33,7 @@ DL_FROM = $(URL_IPFIRE) DIR_APP = $(DIR_SRC)/$(THISAPP) TARGET = $(DIR_INFO)/$(THISAPP) PROG = borgbackup -PAK_VER = 19 +PAK_VER = 20 DEPS = python3-msgpack python3-packaging python3-pyfuse3 libxxhash # borgbackup only works with specific versions of python3-msgpack @@ -48,7 +48,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = fbf5cd06bcddd5b90db75ed1b2276d2eba0d17d0545a751acfd40d051053d9d3e1a0ea2f1dd87e6541aeca6199e98ad1885b9d3155696268752069b763b660a4 +$(DL_FILE)_BLAKE2 = 4a72bf303edb3fc680ef90000a4183e6951c5995a15abe1e1f9a330a6d0e57ca236ec5ebc2b4f46e89b272cb14b4d6e73b62c041310a7461d2c83679c6cf974f install : $(TARGET) @@ -81,6 +81,7 @@ $(subst %,%_BLAKE2,$(objects)) : $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects)) @$(PREBUILD) @rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar zxf $(DIR_DL)/$(DL_FILE) + cd $(DIR_APP) && patch -Np1 < $(DIR_SRC)/src/patches/borgbackup-1.4.5_remove_python_3.14_reference.patch cd $(DIR_APP) && python3 setup.py build cd $(DIR_APP) && python3 setup.py install --root=/ @rm -rf $(DIR_APP)