./sysutils/py-borgbackup, Deduplicating backup program with compression and encryption

[ Image CVSweb ] [ Image Homepage ] [ Image RSS ] [ Image Required by ]


Branch: CURRENT, Version: 1.4.5, Package name: py313-borgbackup-1.4.5, Maintainer: bsiegert

BorgBackup (short: Borg) is a deduplicating backup program. Optionally,
it supports compression and authenticated encryption.

The main goal of Borg is to provide an efficient and secure way to
backup data. The data deduplication technique used makes Borg suitable
for daily backups since only changes are stored. The authenticated
encryption technique makes it suitable for backups to not fully trusted
targets.


Required to run:
[security/openssl] [devel/py-setuptools] [devel/py-cython] [archivers/lz4] [archivers/zstd] [lang/python37] [security/libb2]

Required to build:
[pkgtools/cwrappers] [devel/py-setuptools_scm]

Master sites:

Filesize: 3940.09 KB

Version history: (Expand)


CVS history: (Expand)


   2026-10-05 15:18:30 by Adam Ciarcinski | Files touched by this commit (5) | Package updated
Log message:
py-borgbackup: updated to 1.4.5

1.4.5 (2026-07-19)

For upgrade and compatibility hints, please also read the "Upgrade \ 
Notes" section
above.

New features:

- create/import-tar/delete/prune --quick-stats: faster than --stats by omitting \ 
"All archives"
  and repository chunk statistics
- prune: show total vs matching archives in output
- create --exclude-dataless: macOS: skip cloud files not materialized locally
- support BORG_HOSTNAME and BORG_USERNAME env vars to override the \ 
hostname/username stored
  in archives and used by the {hostname}/{user} placeholders
- Minimal implementation of "related repositories"

  This feature allows multiple repositories to share deduplication-relevant secrets
  (id_key and chunk_seed) while maintaining secure, independent encryption keys.

  - borg key export-related-secrets <REPO> <SPATH>
  - borg init --import-related-secrets <SPATH> <REPO>
- BORG_JSON_INDENT env var for JSON output formatting
- BORG_HOSTNAME and BORG_USERNAME env vars

Fixes:

- extract: security fixes for CVE-2026-62268 (low severity: attacker would need
  repository write access and, if the repo is encrypted, also borg key and \ 
passphrase).
- create: do not wrap repository writes in backup_io("read")
- Archive.delete: don't reuse msgpack Unpacker after an unpacking failure
- slashdot hack: fix exclusion of source directory metadata
- hashindex: fix new checks for big endian archs

- Note:

    Many of the fixed issues listed below relate to rather rare or theoretical
    issues and were found by automated code checking.

- LRUCache: resolve KeyError and memory leaks
- crypto.low_level: fix freeing of memory
- extract: resolve memory leak on abandoned async requests in RemoteRepository
  This can happen if borg fails to extract a file due to permission or other errors
  or if the archived file had all-zero replacement chunks or inconsistent size.
- Chunker fixes

  - Strictly check the return value of fd.read(n) and reject if it returns more
    bytes than requested.
  - Avoid giving len <= 0 to posix_fadvise(), which could drop the rest of the
    file from the cache.
  - buzhash: check for len == 0 edge case
  - Correctly Py_DECREF in cases of errors.
  - Check for malloc/calloc failures.
- Hashindex fixes

  - Make it possible to look up in compacted hashtables.
  - Avoid buckets_length integer overflow on 32-bit systems via huge num_buckets.
  - Deal safely with empty index: we must use num_buckets = 1 to avoid division
    by zero and sanity check in hashindex_read.
  - Always initialize min_empty and num_empty.
  - Reinitialize upper/lower limit and min_empty after compact.
  - Fix size_idx / fit_size / grow_size / shrink_size (mind array bounds).
  - Deal with growing when already at max capacity.
  - hashindex_resize: replace num_entries assertion, return an error instead.
  - Correctly free memory when header validation fails.
  - BaseIndex.clear: always stay in valid state.
    Do not free the old index before we successfully have allocated a new one.

Other changes:

- msgpack: also allow up to 1.2.1
- use F_FULLFSYNC on macOS for SyncFile data durability
- mount: drop runtime warning about symlinks and improve corresponding docs
- mount: improve error msg when uid/gid cannot be resolved
- properly handle invalid and dev versions in version parser
- tests: reset borg.output.progress logger between tests to fix flakiness
- docs
   2026-07-21 16:10:28 by Havard Eidnes | Files touched by this commit (4)
Log message:
sysutils/py-borgbackup: make this accept a newer py-msgpack.

This is in contravention to the upstream policy which insists that
because the maintainers of py-msgpack in the distant past made a
non-compatible change (apparently in a version before 0.5.6 of
py-msgpack, many, many years ago), they now insist that you *cannot*
use a newer version of py-msgpack than what the code insists on,
ref.

   https://github.com/borgbackup/borg/issues/3753

This collides (hard) with the pkgsrc default stance which is to
"upgrade everything to the newest available version", and makes
this package break each time a new version of py-msgpack is integrated
in pkgsrc.

For now just patch this to accept py-msgpack versions between
0.5.6 and 1.2.1 and not just between 0.5.6 and 1.1.2.

At least testing by doing a backup run makes that backup run
complete successfully with py-mgspack 1.2.1 installed, instead
of a sour error message that a non-supported version of msgpack
is installed.

This time I'll leave a comment over on the py-msgpack package,
in an attempt at preventing this problem from once again creep
into a pkgsrc maintenance branch.

Bump PKGREVISION.
   2026-06-28 17:41:51 by Thomas Klausner | Files touched by this commit (364)
Log message:
*: limit Python versions due to py-numpy dropping Python 3.11 support
   2026-04-20 20:26:59 by Adam Ciarcinski | Files touched by this commit (3) | Package updated
Log message:
py-borgbackup: updated to 1.4.4

Version 1.4.4 (2026-03-19)

For upgrade and compatibility hints, please also read the "Upgrade \ 
Notes" section
above.

New features:

- prune: added -v / --info output,
- mount: warn about symlinks pointing outside of the mount point,
- create/info: remember/show cwd at the time of archive creation,

Fixes:

- hashindex: fix memory leak,
- hashindex: check values in read HashHeader,
- hashindex_size: return int64_t,
- hashindex: fix iteritems segfaulting with non-existent marker,
  Never happened in borg, because borg always gives existing markers to iteritems.
- compress: make Padme size obfuscation usable ("obfuscate,250,...").
- borgfs/mount: get_base_dir: avoid using incorrect HOME,

Other changes:

- PyInstaller binary: do not exclude SSL, needed for pyfuse3/trio,
- mount: FUSE FS performance improvement.
- warn when replaying segments,
- CI / tests:

  - build Linux binaries with pyfuse3.
  - use macOS 15 to build the binaries.
  - scripts/linux-run: run commands (e.g. tox) in a Podman Linux container.
  - fix race condition in test_with_lock,
  - fix spurious sparse test failure on Win32,
  - Cygwin: skip ~root base dir test.
  - fix coverage collection for daemonized `borg mount`,
- docs:

  - move RTD version selector to sidebar top-left,
  - consolidate key backup info in `borg key export` help,
  - clarify append-only != write-only,
  - fix typos found by codespell.
  - update binary README.
  - GitHub: enhance pull request template.
   2025-12-30 09:32:20 by Adam Ciarcinski | Files touched by this commit (3) | Package updated
Log message:
py-borgbackup: updated to 1.4.3

Version 1.4.3 (2025-12-02)

For upgrade and compatibility hints, please also read the “Upgrade Notes” \ 
section above.

New features:

None.

Fixes:

compact: replace AssertionError with a warning,

compact: also fix segment hints data for lost segment files.

CI: FUSE-related fixes and improvements,

The Linux and FreeBSD binaries built on GitHub now include working FUSE support \ 
(based on llfuse).

We can’t include FUSE support in the macOS binaries built on GitHub, because \ 
we can’t install macFUSE there; use our Homebrew tap for that.

Other changes:

Drop Python 3.9 support (has reached end of life at python.org).

CI:

Install the correct FUSE library depending on the tox environment.

PyInstaller binary building: build and upload early, then run CI tests.

For now, use llfuse, as there is an issue with PyInstaller and pyfuse3.

Backported vm_tests (FreeBSD/NetBSD/OpenBSD/Haiku) from the master branch.

Dynamic code analysis (Address and Undefined Behavior Sanitizers),

Add tag-based workflows and provenance attestation for GitHub-built binaries,

Docs:

Some fixes and updates to the FAQ,

Update binary README; release binaries are built on GitHub now.
   2025-11-10 20:44:33 by Benny Siegert | Files touched by this commit (4) | Package updated
Log message:
py-borgbackup: update to 1.4.2.

Now officially supports msgpack 1.1.2, so these patches are no longer
needed.

New features:

- BORG_MSGPACK_VERSION_CHECK=no to optionally disable the msgpack
  version check; default is “yes”; use at your own risk.
- diff --sort-by: enhanced sorting
- create: add --files-changed=MODE option (controls how borg detects
  whether a file has changed while it is being backed up)
- improve tty-less progress reporting (--progress)

Fixes:

- extract: fs flags: use get/set to influence only specific flags,
  Linux/macOS/FreeBSD only.
- extract: fs flags: remove support for the compression flag; this
  wasn’t working correctly anyway.
- create/info: fix discrepancies in archive stats
- import-tar: fix the dot-slash issue; add a test
- import-tar: when printing the path, use the already-normalized
  item.path
- preprocess_args: fix option name matching
- fix ChunkerParams validation
- mount --show-rc: display main process rc
- json: include archive keys in JSON lines when requested via --format

Other changes:

- support Python 3.14
- msgpack: allow 1.1.2
- Brewfile: use openssl@3 rather than openssl@3.0, to have a more recent OpenSSL.
- msgpack version check: ignore “rc” and other version elements
   2025-10-16 23:30:21 by Havard Eidnes | Files touched by this commit (4) | Package updated
Log message:
sysutils/py-borgbackup: add patches to accept py-msgpack up to 1.1.2.

This evidently got lost in the previous update...
This replicates what upstream has already done in 1.4.2rc*.
   2025-10-09 09:58:14 by Thomas Klausner | Files touched by this commit (442)
Log message:
*: remove reference to (removed) Python 3.9