Skip to content

feat(deps): update duplicati/duplicati v2.3.0.4_stable_2026-07-09 → v2.4.0.0_stable_2026-09-03 - #3426

Open
truecharts-admin wants to merge 1 commit into
mainfrom
renovate/duplicati-duplicati-2.x
Open

feat(deps): update duplicati/duplicati v2.3.0.4_stable_2026-07-09 → v2.4.0.0_stable_2026-09-03#3426
truecharts-admin wants to merge 1 commit into
mainfrom
renovate/duplicati-duplicati-2.x

Conversation

@truecharts-admin

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change
duplicati/duplicati minor 2.3.0.4_stable_2026-07-092.4.0.0_stable_2026-09-03

Release Notes

duplicati/duplicati (duplicati/duplicati)

v2.4.0.0_stable_2026-09-03

Compare Source

This release is a stable release that supersedes the 2.3.0.4 stable release. It contains all changes from the 2.3.1.0 and 2.3.1.1 beta releases.

Breaking change: Locked-down data folder permissions

This release hardens security around the data folder and is a breaking change for some setups.

For most users, this should not be a problem as the folders should already have the correct permissions.

Duplicati now requires that the data folder has the exact expected permissions, or it will refuse to use it. Previously, Duplicati would silently lock down the folder if it was not already locked.

To opt out of the permission check, you need to either pass --allow-insecure-datafolder, set the environment variable DUPLICATI__ALLOW_INSECURE_DATAFOLDER=true, or place a file named insecure-permissions.txt in the installation folder.

Note that the previous method of placing insecure-permissions.txt in the data folder is no longer supported.

This change also applies to preload.json, such that it will only be loaded if the folder is trusted, or one of the opt-out methods are activated. Additionally, the previous trusted paths /usr/local/share/Duplicati/preload.json and C:\ProgramData\Duplicati\preload.json are no longer supported as they cannot be guaranteed to be locked down.

A preload.json inside the data folder is still supported, provided the folder passes the permission check.

The ConfigureTool has a new secure-datafolder command that can be used to force the correct permissions on the data folder.

For most users this should not cause any problems, as Duplicati has been locking down the folder already, but if you rely on lax folder permissions the setup needs to change. Some Docker setups may not be able to set the permissions and will need to apply DUPLICATI__ALLOW_INSECURE_DATAFOLDER=true in the image to run without the protections.

Sync copy mode

This release adds an often requested feature that enables simple copying of files from source to destination.
Where the regular backups are deduplicated, compressed, encrypted and versioned, the new sync mode will instead simply copy from source to destination.

The copy is currently a one-way sync, where the source is replicated on the destination. Files can be deleted on the destination during sync (use --sync-then-delete), but destination folders will not be deleted.

The option --sync-remote-state is by default set to UseRemoteState which will list the destination and figure out what to upload. The setting UseLocalState uses a local database, similar to how backups work, to keep track of known remote files, and reduce the amount of remote listings done. Finally, the BlindlyUpload setting will just copy everything as-is to the remote.

The sync jobs support remote sources, snapshots, and multiple destinations. If snapshots are enabled, the copy is done from the snapshot, ensuring reliable reads.

Configuration of such a sync job is done the same way as with backup, but using a toggle option in the first step of the UI. Note that backup and sync jobs are not compatible as they use very different storage logic, so it is not possible to change the job mode after creating a job.

CLI mode also supports sync.

Improved Windows installer

This change brings a major update to the Windows installers, which now integrates the ability to run as a service, as well as generate and use TLS (https). The service feature has been present for a while in the WindowsService.exe tool and the TLS certificates were added as part of the Duplicati.CommandLine.ConfigureTool.exe. With this update these things are now integrated into the installer, and exposed as simple checkboxes to toggle the features. Installing the service from a regular user account, will also auto-generate a secure password and configure the TrayIcon to connect to the service (only for the current user).

If you have installed the service manually, do not activate the new checkbox as it only works if there is no pre-existing service. The installer-driven service does not support commandline arguments directly, but instead prefers preload.json files to configure it. The MSI supports the property INSTALL_PRELOAD=true which will cause it to pick up a preload.json file from the same folder the MSI is located in.

The Windows service is now also configured as delay-start service to avoid startup issues on boot.

Live reporting module

This release adds a new live-reporting module that sends the current progress of backups to a user-specified URL. The intention is that this can be used for dashboards that want to show the current progress for backups. By default, the module is not configured and has no impact.

The module supports multiple activity targets and includes metadata in the activity report, as well as a console-provided activity URL.

PAR2 parity / error-correction for remote volumes

This release adds a pluggable parity module that produces error-correction data for remote data volumes, so they can be repaired after bit-rot or corruption on the backend, thanks @​JamBalaya56562.

To enable this, ensure that par2 is installed on the machine and set --parity-module=par2. Setting this will cause additional .par2 files to be uploaded.

Store configuration with backup

This release revives the store-task-config option and makes it enabled by default for encrypted backups. The backup configuration is stored with the backup data, making it easier to restore a configuration later.

For unencrypted backups, no secrets are stored by default. The behavior can be customized with options to store none, self, or all configurations, with or without secrets. The UI has been updated to allow restoring from the destination config. If multiple configurations are found, the user can select one or more backup configurations to restore.

MS365 subsites and shared mailboxes

This release improves the Microsoft 365 backup support with two additions.
Support for backing up SharePoint subsites has been added, making it possible to include sub-sites beneath a site collection in a backup.

The handling of shared mailboxes has also been improved, with better detection and enumeration of shared mailboxes within a tenant.

The license counting has been simplified. A Duplicati license is now required if an MS365 license is assigned, without needing per-user lookups. The same logic applies to both users and sites, and personal sites of users without a license are not counted. Filtering based on classification is still supported.

Full disk backup support (Windows, Linux, MacOS)

This release extends the full disk backup feature to support Linux and MacOS, in addition to Windows.

The Linux support allows backup and restore of entire disks on Linux, including partition tables. The MacOS support adds basic backup and restore of entire disks, including partition tables.

Partition-level backup and restore is now supported, making it possible to select individual partitions as backup sources, or restore a single partition from a full disk backup to a different partition.

Like the Office 365 / Google Workspace backup features, this is a proprietary module (source available).

Full disk backup requires administrative privileges to access the disk directly.
Full disk restore requires administrative privileges and requires that the disk is unmounted and not write-protected.

Desktop notifications on all platforms

Desktop notifications are now supported on all platforms. Windows toast notifications have been implemented with click-to-open support, and native notification support has been added for macOS and Linux (via DBus), thanks @​JamBalaya56562 for the Windows implementation.

Restore reliability improvements

Several issues with the restore process have been fixed. Restores now properly respond to stop/abort requests, file reads and writes can be interrupted, and a critical bug with wrong seek offsets for partial blocks has been fixed, which could cause restores to fail, thanks @​JamBalaya56562.

An index has been added on the restore file table join columns for better restore performance, thanks @​JamBalaya56562.

Misconfigured filter detection

A new warning system detects when filters are configured to unconditionally exclude everything. A post-backup check also warns if no files were examined during backup, which helps catch misconfigurations that would otherwise silently produce empty backups.

New backends

Added support for Drime Cloud as a new storage backend.

Added a new backend for the Spanish provider Movistar, thanks @​redmars27. The backend is marked as "untested" as it can only be used (and tested) by Movistar customers.

Deprecated backends

The previous "SharePoint" and "OneDrive for Business" backends have been marked as deprecated, as Microsoft shut down the API they were calling. The migration step is to use the "SharePoint v2" backend (renamed to just "SharePoint" in this version) which uses the Microsoft Graph API.

Duplicati Storage

This release includes Duplicati Storage which is integrated with the Duplicati console. Once a machine is connected to the console it can use the account's storage allocations with zero configuration required.

SharpAESCrypt v3

Updated the SharpAESCrypt encryption library to support "AES Crypt Stream Format v3", which has a number of improvements over the v2 format.
For this release, the default written format remains v2, but we encourage you to set the environment variable DUPLICATI__AES_VERSION=3 to test the new format.
Note: if you set this version to 3, the new remote volumes cannot be read by Duplicati versions older than 2.3.0.101.

Support for MacOS ACLs

This release adds support for reading MacOS attributes and ACL strings during backup, and restoring them when permission restores are selected.

Support for Windows Alternate Data Streams

This release implements support for reading and writing alternate data streams (ADS) on Windows. This feature is disabled by default and can be enabled with the advanced option --enable-ads-backup. If ADS content is found in the source, this is restored by default but can be disabled with --disable-ads-restore.

Fixed MSSQL backups

Since 2.1 the MSSQL backups would produce errors if attempting to back up an MSSQL server that was running as the default instance, but would work with a named instance. This release fixes the issue and now handles both default- and named instances.

Improved missing source handling

The default behavior when sources are missing has changed. Previously, a missing source would abort the backup. Now, a missing source will only trigger a warning unless the option --abort-if-source-missing is set. The option --allow-missing-source can still be used to suppress warnings entirely. If no sources are found at all, the backup will still abort.

Relative database paths

Database paths are now stored relative to the data folder by default. This makes it simpler to move the data folder as the paths are not stored in full. Existing backups retain their full paths, but manually updating a database path will make it relative if it is within the data folder.

Improved TLS certificate validation

The TLS certificate validation has been improved, and Duplicati now falls back to using the OS-default certificate validator. This should resolve issues with custom certificate chains and improve compatibility with various TLS setups.

Improved source tree and filter accuracy

The source tree now shows the content of remote sources, including Microsoft 365 tenants, Google Workspace subscriptions and full-disk content. Filter evaluation is performed server-side for non-trivial filters, ensuring the same code is used for display and actual backup operations.

Helper entries like "My Documents" are now shown in all picker situations and resolve to the full path. The destination configuration supports browsing the remote file system.

New welcome page and start

The UI will now show a welcome page showing how to connect to the console with an option to continue without.
This can be suppressed with the option --webservice-suppress-welcome-page=true or environment variable DUPLICATI__WEBSERVICE_SUPPRESS_WELCOME_PAGE=true.

If the connection is made from the TrayIcon, the initial dialog asking to set a password is no longer shown, as the intention is to use the TrayIcon to connect.
It is still possible to change the password from the Settings page if needed.

Other notable changes

  • AutoTune tool: A new Duplicati.CommandLine.AutoTuneTool / duplicati-autotune tool to help evaluate and optimize performance-related settings.
  • Read-only backend testing: Backends now support read-only context-aware testing, safe for testing restore destinations without risking unintended changes.
  • Remote synchronization improvements: Integrated remote synchronization (3-2-1 backups) into the Main library with quota checks and improved error handling.
  • Multi-version restore: New --restore-all-files option to restore files matching a filter from multiple versions.
  • Performance improvements: ArrayPool-based allocations reduce memory pressure during backups. Faster delete queries for large backups.
  • Post-backup scripts: The RunScript module now supports running scripts when a backup has finished, but before checks and compaction.
  • Database tool commands: Added verify and cleanup commands to the database tool. Added wipe-encryption command for recovering encrypted databases.
  • Slow query monitor: Added tracking of long-running database queries to help diagnose performance issues.
  • Crash dialog: Added a crash dialog window that appears when the application encounters an unhandled exception.
  • Updated LibSecret support for KDE Plasma 5+6, fixing issues with the default collection.
  • More robust server connection: The remote server connection has been hardened with a watchdog that restarts unresponsive connections.
  • Auto-configure database metadata: The --store-metadata-content-in-database option is automatically applied when needed by the source provider.
  • MS365/Google permission testing: Added ability to verify that granted permissions match what is required for backup or restore.

Thanks to contributors

This release is a collaboration effort from the Duplicati community. Thanks to the many contributors who report issues, test new releases, request features, write documentation, maintain translations, and contribute to the codebase.

v2.3.1.1_beta_2026-08-26

Compare Source

2026-08-26 - 2.3.1.1_beta_2026-08-26

This release is a Beta release intended to be used for testing to identify any issues before releasing the next stable version.

Partition level full disk backup and restore

The full disk backup feature now supports selecting individual partitions as backup sources, in addition to entire disks. This makes it more intuitive to back up a specific partition without filtering.

Restore now also supports partition-to-partition restores, so it is possible to restore a single partition from a full disk backup, or restore a partition backup to a different partition.

Desktop notifications on all platforms

Desktop notifications are now supported on all platforms. Windows toast notifications have been implemented (with click-to-open support), and native notification support has been added for macOS and Linux (via DBus), thanks @​JamBalaya56562.

Restore cancellation and reliability improvements

Several issues with the restore process have been fixed. Restores now properly respond to stop/abort requests, file reads and writes can be interrupted, and a critical bug with wrong seek offsets for partial blocks has been fixed, which could cause restores to fail for most files, thanks @​JamBalaya56562.

Misconfigured filter detection

A new warning system detects when filters are configured to unconditionally exclude everything. A post-backup check also warns if no files were examined during backup, which helps catch misconfigurations that would otherwise silently produce empty backups.

More robust server connection

The remote server connection has been hardened against network events that could cause it to drop. A watchdog monitors the connection and restarts it if it has been unresponsive for an extended period.

Improved MS365 license counting

The MS365 license counting logic has been simplified. A Duplicati license is now required if an MS365 license is assigned, without needing per-user lookups. The same logic applies to both users and sites, and personal sites of users without a license are not counted.

Faster delete operations

The database query for deleting old backup versions has been optimized, significantly speeding up the delete operation for large backups.

Fixed index file recreation

An issue where recreated index files could be incomplete has been fixed. The index file recreation now happens after block volumes are fully processed, ensuring all blocklists are included. This fixes the intermittent "Found N faulty index files" verification error.

Security fix for credential leaks

Fixed an issue where credentials embedded in URLs could leak into log messages, but only on malformed URLs, thanks @​JamBalaya56562.

Auto-configure database metadata

When using a source provider that requires database metadata (such as full disk backup), the --store-metadata-content-in-database option is now automatically applied when needed. This can still be overridden manually.

Detailed list of changes

  • Added partition-level full disk backup and partition-to-partition restore support
  • Added Windows toast notifications with click-to-open, thanks @​JamBalaya56562
  • Added macOS native notifications
  • Added Linux DBus notifications
  • Added detection and warning for misconfigured filters that exclude everything
  • Added watchdog for more robust console connection handling
  • Added automatic database metadata configuration for source providers that need it
  • Added index on restore file table join columns for better restore performance, thanks @​JamBalaya56562
  • Added sync command to CLI help output
  • Simplified MS365 license counting to check license assignment without per-user lookups
  • Improved MS365 user/site listing with alphabetical sorting and fewer API calls
  • Improved HyperV and MSSQL enumeration to handle errors gracefully
  • Improved pagination for backend listing results
  • Fixed wrong seek offset in restore when copying verified local blocks, which could break restores, thanks @​JamBalaya56562
  • Fixed restore not responding to stop/abort requests, thanks @​JamBalaya56562
  • Fixed restore cancellation not interrupting file reads and writes, thanks @​JamBalaya56562
  • Fixed local files being incorrectly marked as broken when a shutdown interrupted writes, thanks @​JamBalaya56562
  • Fixed requested shutdown being reported as a failure instead of a user-initiated stop, thanks @​JamBalaya56562
  • Fixed index file recreation producing incomplete index files
  • Fixed similarly named paths being incorrectly excluded from backup sources
  • Fixed quota errors being reported during read-only operations like restore, thanks @​JamBalaya56562
  • Fixed stale query statistics causing slow backups, thanks @​JamBalaya56562
  • Fixed backend statistics reporting unset timestamps in JSON output, thanks @​JamBalaya56562
  • Fixed legacy symlink folder restore using wrong path, thanks @​JamBalaya56562
  • Fixed slow query monitoring not tracking database queries, thanks @​JamBalaya56562
  • Fixed credentials leaking through URL sanitizer on malformed URLs, thanks @​JamBalaya56562
  • Fixed destination connection test failing on missing probe file, thanks @​JamBalaya56562
  • Fixed invalid update check interval being silently ignored, thanks @​JamBalaya56562
  • Fixed Google credentials not being read as service accounts, thanks @​JamBalaya56562
  • Fixed SharpAESCrypt version inconsistency across projects, thanks @​JamBalaya56562
  • Fixed Linux notifier using obsolete DBus API, thanks @​JamBalaya56562
  • Fixed Microsoft.Extensions packages left at older versions, thanks @​JamBalaya56562
  • Fixed SecretProvider package version alignment, thanks @​JamBalaya56562
  • Fixed Box folder lookup failing when folder name already exists, thanks @​JamBalaya56562
  • Fixed Box backend ignoring the requested path in entry lookups, thanks @​JamBalaya56562
  • Fixed IDrive e2 backend GetEntryAsync returning null for all paths, thanks @​JamBalaya56562
  • Fixed pCloud uploads not checking HTTP response status, thanks @​JamBalaya56562
  • Fixed Tahoe-LAFS deletes not checking response status, thanks @​JamBalaya56562
  • Fixed Filejump error handler infinite recursion causing stack overflow, thanks @​JamBalaya56562
  • Fixed Filen downloads not checking response status before decrypting, thanks @​JamBalaya56562
  • Fixed full disk provider not initializing when listing folders
  • Updated all NuGet packages to latest versions
  • Updated SSH.NET dependency
  • Updated all translations, thanks to all translators
  • Updated licenses project with missing packages

Changes in ngclient

  • Added support for choosing sort order in the file tree
  • Added support for partition-level full disk backup and restore in the UI
  • Added warning if filters appear to exclude everything
  • Added load-more pagination for file browsing
  • Added prefill of restore options from configured settings, thanks @​JamBalaya56562
  • Added option to allow encryption changes for imported backups, thanks @​JamBalaya56562
  • Improved schedule summary with templates, reducing translation burden, thanks @​JamBalaya56562
  • Improved MS365 tenant counter display
  • Disabled menu options that do not apply to sync jobs
  • Fixed Chinese locale selection, thanks @​JamBalaya56562 and @​scambra
  • Fixed source filter highlighting, thanks @​JamBalaya56562
  • Fixed commandline output auto-scrolling, thanks @​JamBalaya56562
  • Fixed remote source selection copy, thanks @​JamBalaya56562
  • Fixed destination editor identity preservation, thanks @​JamBalaya56562
  • Fixed usage statistics compatibility across UIs, thanks @​JamBalaya56562
  • Fixed absolute assets path ignoring X-Forwarded-Prefix header, thanks @​scambra
  • Updated all translations, thanks to all translators

v2.3.1.0_beta_2026-07-28

Compare Source

This release is a Beta release intended to be used for testing to identify any issues before releasing the next stable version.

Breaking change: Locked-down data folder permissions

This release hardens security around the data folder and is a breaking change for some setups.

Duplicati now requires that the data folder has the exact expected permissions, or it will refuse to use it. Previously, Duplicati would silently lock down the folder if it was not already locked.

To opt out of the permission check, you need to either pass --allow-insecure-datafolder, set the environment variable DUPLICATI__ALLOW_INSECURE_DATAFOLDER=true, or place a file name insecure-permissions.txt in the installation folder.

Note that the previous method of placing insecure-permissions.txt in the data folder is no longer supported.

This change also applies to preload.json, such that it will only be loaded if the folder is trusted, or one of the opt-out methods are activated. Additionally, the previous trusted paths /usr/local/share/Duplicati/preload.json and C:\ProgramData\Duplicati\preload.json are no longer supported as they cannot be guaranteed to be locked down.

A preload.json inside the data folder is still supported, provided the folder passes the permission check.

The ConfigureTool has a new secure-datafolder command that can be used to force the correct permissions on the data folder.

For most users this should not cause any problems, as Duplicati has been locking down the folder already, but if you rely on lax folder permissions the setup needs to change. Some Docker setups may not be able to set the permissions and will need to apply DUPLICATI__ALLOW_INSECURE_DATAFOLDER=true in the image to run without the protections.

Sync copy mode

This release adds a often requested feature that enables simple copying of files from source to destination.
Where the regular backups are deduplicated, compressed, encrypted and versioned, the new sync mode will instead simply copy from source to destination.

The copy is currently a one-way sync, where the source is replicated on the destination. Files can be deleted on the destination during sync (use --sync-then-delete), but destination folders will not be deleted.

The option --sync-remote-state is by default set to UseRemoteState which will list the destination and figure out what to upload. The setting UseLocalState uses a local database, similar to how backups work, to keep track of known remote files, and reduce the amount of remote listings done. Finally, the BlindlyUpload setting will just copy everything as-is to the remote.

The sync jobs support remote sources, snapshots, and multiple destinations. If snapshots are enabled, the copy is done from the snapshot, ensuring reliable reads.

Configuration of such a sync job is done the same way as with backup, but using a toggle option in the first step of the UI. Note that backup and sync jobs are not compatible as they use very different storage logic, so it is not possible to change the job mode after creating a job.

CLI mode also supports sync.

Improved Windows installer

This change brings a major update to the Windows installers, which now integrates the ability to run as a service, as well as generate and use TLS (https). The service feature has been present for a while in the WindowsService.exe tool and the TLS certificates were added as part of the Duplicati.CommandLine.ConfigureTool.exe. With this update these things are now integrated into the installer, and exposed as simple checkboxes to toggle the features. Installing the service from a regular user account, will also auto-generate a secure password and configure the TrayIcon to connect to the service (only for the current user).

If you have installed the service manually, do not activate the new checkbox as it only works if there is no pre-existing service. The installer-driven service does not support commandline arguments directly, but instead prefers preload.json files to configure it. The MSI supports the property INSTALL_PRELOAD=true which will cause it to pick up a preload.json file from the same folder the MSI is located in.

The Windows service is now also configured as delay-start service to avoid startup issues on boot.

Live reporting module

This release adds a new live-reporting module that sends the current progress of backups to a user-specified URL. The intention is that this can be used for dashboards that want to show the current progress for backups. By default, the module is not configured and has no impact.

PAR2 parity / error-correction for remote volumes

This release adds a pluggable parity module that produces error-correction data for remote data volumes, so they can be repaired after bit-rot or corruption on the backend, thanks @​JamBalaya56562.

To enable this, ensure that par2 is installed on the machine and set --parity-module=par2. Setting this will cause additional .par2 files to be uploaded.

Store configuration with backup

This release revives the store-task-config option and makes it enabled by default for encrypted backups. The backup configuration is stored with the backup data, making it easier to restore a configuration later.

For unencrypted backups, no secrets are stored by default. The behavior can be customized with options to store none, self, or all configurations, with or without secrets. The UI has been updated to allow restoring from the destination config. If multiple configurations are found, the user can select one or more backup configurations to restore.

MS365 subsites and shared mailboxes

This release improves the Microsoft 365 backup support with two additions.
Support for backing up SharePoint subsites has been added, making it possible
to include sub-sites beneath a site collection in a backup.

The handling of shared mailboxes has also been improved, with better detection
and enumeration of shared mailboxes within a tenant.

The license counter now excludes shared mailboxes without a license, and supports
top-level filtering of users/sites/groups based on classification.

Full disk backup support (Windows, Linux, MacOS)

This release extends the full disk backup feature to support Linux and MacOS.

The Linux support allows backup and restore of entire disks on Linux, including partition tables. The MacOS support adds basic backup and restore of entire disks, including partition tables.

Like the Office 365 / Google Workspace backup features, this is a proprietary module (source available) that requires a license to use in production.

Full disk backup requires administrative privileges to access the disk directly.
Full disk restore requires administrative privileges and requires that the disk is unmounted and not write-protected.

Read-only testing of backends

Backends now support read-only context-aware testing, which allows testing connections safely without risking unintended changes to the storage. The read-only testing is applied when testing a restore destination or a remote source, such that no files are attempted written to the remote storage.

New backends

Added support for Drime Cloud as a new storage backend.

Added a new backend for the Spanish provider Movistar, thanks @​redmars27. The backend is marked as "untested" as it can only be used (and tested) by Movistar customers.

Deprecated backends

The previous "SharePoint" and "OneDrive for Business" backends have been marked as deprecated, as Microsoft shut down the API they were calling. The migration step is to use the "SharePoint v2" backend (renamed to just "SharePoint" in this version) which uses the Microsoft Graph API.

FAT32 and NTFS support for full disk backup

Added FAT32 and NTFS file system support for the full disk backup feature, including boot sector parser, table reader, streams, and directory walker. This features makes it more efficient to do full-disk backups.

To enable this feature, add the advanced option --diskimage-filesystem-parsed=true and the backups will attempt to parse the disk, and if it is one of the supported formats, it will only read the relevant sectors.

Remote synchronization improvements

Integrated remote synchronization feature (aka 3-2-1 backups) from a separate module into the Main library for better integration, with improved error handling, progress tracking, and reliability.

Added destination space quota checks to the remote synchronization runner, helping prevent failures due to insufficient destination space.
An option to disable quota checks (quota-disable) has also been added for scenarios where quota information is not available or reliable.

Duplicati Storage

This release also includes the Duplicati Storage which is integrated with the Duplicati console. Once a machine is connected to the console it can use the accounts storage allocations with zero configuration required.

SharpAESCrypt v3

Updated the SharpAESCrypt encryption library to support "AES Crypt Stream Format v3", which has a number of improvements over the v2 format.
For this release, the default written format remains v2, but we encourage you to set the environment variable DUPLICATI__AES_VERSION=3 to test the new format.
Note: if you set this version to 3, the new remote volumes cannot be read by Duplicati versions older than (2.3.0.101).

Support for MacOS ACLs

This release adds support for reading MacOS attributes and ACL strings during backup, and restoring them when permission restores are selected.

Support for Windows Alternate Data Streams

This release implements support for reading and writing alternate data streams (ADS) on Windows. This feature is disabled by default and can be enabled with the advanced option --enable-ads-backup. If ADS content is found in the source, this is restored by default but can be disabled with --disable-ads-restore.

Fixed MSSQL backups

Since 2.1 the MSSQL backups would produce errors if attempting to back up an MSSQL server that was running as the default instance, but would work with a named instance. This release fixes the issue and now handles both default- and named instances.

Improved missing source handling

The default behavior when sources are missing has changed. Previously, a missing source would abort the backup. Now, a missing source will only trigger a warning unless the option --abort-if-source-missing is set. The option --allow-missing-source can still be used to suppress warnings entirely. If no sources are found at all, the backup will still abort.

Relative database paths

Database paths are now stored relative to the data folder by default. This makes it simpler to move the data folder as the paths are not stored in full. Existing backups retain their full paths, but manually updating a database path will make it relative if it is within the data folder.

Updated LibSecret support for KDE

The LibSecret support has been updated to work correctly on KDE Plasma 5+6. The default collection alias is now properly resolved, fixing issues where a new collection named default would be created incorrectly.

Improved source tree

To make it easier to see what data is included, the source tree will now show the content of remote sources, including Microsoft 365 tenants, Google workspace subscriptions and full-disk content.

Improved filter accuracy in the UI

The filter evaluation will now be performed server-side if the filters are not "simple filters". When a non-trivial filter is in the list, the C# code will be asked to evaluate the list and produces the filtered results which are then displayed. This increases the correctness of the displayed filter state because the same code is now used for both display and actual backup operations.

Resolve shortcut entries

The helper entries, like "My Documents" are now shown in all picker situations and resolve to the full path. This makes it possible to use these shortcuts to pick things like log-file location or SSH keyfiles, without having to traverse the full tree to find the locations.

Browse remote destinations

The destination configuration has been updated to include a browse button for finding the remote destination path. Once the connection details are in place, the browse button can be used to navigate the remote file system and select the desired destination folder. This works both for configuring a backup and for picking the restore location.

New welcome page and start

The UI will now show a welcome page showing how to connect to the console with an option to continue without.
This can be suppressed with the option --webservice-suppress-welcome-page=true or environment variable DUPLICATI__SUPPRESS_WELCOME_PAGE=true.

If the connection is made from the TrayIcon, the initial dialog asking to set a password is no longer shown, as the intention is to use the TrayIcon to connect.
It is still possible to change the password from the Settings page if needed.

Crash dialog

Added a crash dialog window that appears when the application encounters an unhandled exception.

Thanks to contributors

This release is once again a collaboration effort from the Duplicati community. Thanks to the many contributors who reports issues, test new releases, requests features, write documentation, maintain translations, and contribute to the codebase.

v2.3.0.110_canary_2026-08-25

Compare Source

This release is a canary release intended to be used for testing.

Database update to version 20

This release updates the local database schema to version 20. The update adds a label column to the fileset table and is applied automatically on first use. After the update, the database can no longer be opened by earlier versions of Duplicati. If you need to downgrade, the bundled database tool (duplicati-database-tool) can downgrade the database back to version 19; downgrading removes the labels, but otherwise causes no data loss.

Labels on backup versions

Backup versions can now carry an optional text label. Labels have no functional purpose, but they help mark and distinguish versions, for example when backups are hand-curated instead of running on a schedule. The CLI and UI supports setting and showing labels.

Partition-level backup and restore

It is now possible to select a single disk partition as the backup source, instead of selecting the full disk and filtering the unwanted partitions. Restores are likewise more flexible: in addition to disk-to-disk restores, a single partition can now be restored into a partition on another disk, creating the partition as needed.

This also fixes a bug where a failing priority file would leave the restore stuck until it was cancelled, and a number of issues with enumerating and filtering disks and partitions, in particular on Windows.

Automatic metadata storage for sources that need it

Backups using a source provider that relies on database metadata, such as the disk image provider, previously required the user to set --store-metadata-content-in-database=true manually. The setting is now applied automatically when the source needs it, and can still be overridden by setting the option explicitly.

QNAP packages

This release adds native QNAP package support. Similar to the Synology package, it integrates with the QNAP OS, uses the built-in authentication, and only allows access for administrators.

Stricter Google Cloud Storage credentials

Google Cloud Storage credentials are now read as service account credentials, which is what the options are documented to take. Other credential types, such as stored user credentials or external account configurations, are now refused. If you authenticate to Google Cloud Storage, or the Google Cloud secret provider, with anything other than a service account key, you need to switch to a service account key.

Detailed list of changes

  • Updated all localizations, thanks to all translators
  • Added labels to backup versions, with CLI, API, and UI support
  • Added partition-level backup and partition-to-partition restore
  • Fixed disk image provider not initializing when listing drives, and improved disk enumeration and filter handling on Windows
  • Automatically enabled --store-metadata-content-in-database when the source provider requires it
  • Added native QNAP package support
  • Added a watchdog that restarts a stale remote management connection, and fixed issues that could drop the connection
  • Google Cloud Storage credentials are now read strictly as service accounts, thanks @​JamBalaya56562
  • Fixed WebDAV destinations with a + in the path reporting uploaded files as missing, thanks @​JamBalaya56562
  • Fixed Windows file:// target URLs with a query string being misparsed
  • Stopped reporting quota errors on read-only operations such as restore, thanks @​JamBalaya56562
  • Fixed stale SQLite query statistics causing extremely slow fileset and consistency queries on growing databases, thanks @​JamBalaya56562
  • Sped up cleanup after deleting a backup version by avoiding a full table scan
  • Fixed a similarly named file and folder in the source causing the folder to be omitted, and allowed explicitly including a file inside an excluded folder
  • Fixed backend statistics reporting a bogus zero timestamp in the operation log, thanks @​JamBalaya56562
  • Fixed Linux desktop notifications using an unsupported signal API, thanks @​JamBalaya56562
  • Fixed a restore with failing priority files getting stuck instead of failing
  • Aligned SharpAESCrypt, AWSSDK.Core, Azure.Core, and Microsoft.Extensions package versions across the solution, thanks @​JamBalaya56562

Updates to ngclient

  • Added settings to control sorting of tree views
  • Added support for editing version labels
  • Disabled menu options that do not apply to sync jobs
  • Fixed the destination editor mixing up connection state when a destination is removed, thanks @​JamBalaya56562
  • Allowed changing encryption settings for imported backups, thanks @​JamBalaya56562
  • Fixed the usage statistics setting not matching the format used by the legacy UI and server settings, thanks @​JamBalaya56562
  • Added a plain-language summary to the custom schedule editor, thanks @​JamBalaya56562
  • Added support for browsing disks and partitions and for restoring disk images and partitions
  • Fixed Chinese locale selection, thanks @​JamBalaya56562
  • Fixed absolute asset paths ignoring the path prefix when running behind a reverse proxy, thanks @​scambra
  • Updated all translations, thanks to all translators

v2.3.0.109_canary_2026-08-14

Compare Source

This release is a canary release intended to be used for testing.

Native desktop notifications

This release adds native desktop notifications on all supported desktop platforms. Backup results and other tray-icon notifications are now shown as real operating-system notifications instead of only appearing inside the UI.

On Windows, notifications are shown as Windows toast notifications with click-to-open support, thanks @​JamBalaya56562. On macOS, notifications are shown via the native notification center. On Linux, notifications are sent over DBus and integrate with the desktop environment's notification daemon.

Native environment variable syntax on Linux and macOS

Paths and filters now support the native $VAR and ${VAR} environment variable syntax on Linux and macOS, most notably $HOME, thanks @​JamBalaya56562. Previously only the Windows-style %VAR% syntax was expanded, so the native forms were silently left unexpanded on non-Windows systems.

The expansion is additive: %VAR% keeps working everywhere, and an undefined variable is left as-is. If you previously worked around this with literal $ characters in paths or filters, those entries will now be expanded.

Restore improvements and fixes

Several restore issues have been fixed in this release, thanks @​JamBalaya56562. Restore now honors stop requests promptly: an abort interrupts in-progress file reads and writes, where it previously could keep running for minutes after the request. An aborted restore no longer reports errors, blames the backup, or leaks temporary files, and files that a shutdown interrupted are no longer listed as broken. A requested shutdown is in general no longer reported as a failure. Two bugs that could corrupt restored data were fixed: a wrong seek offset when copying verified local blocks, and an incorrect buffer copy when merging a hash fragment. Restore now also preserves the selected folder and applies configured default options (such as --restore-permissions) when the restore request does not explicitly specify them. On the legacy restore engine, restoring a directory symlink no longer creates a real folder in its place.

Stricter validation of settings

This release adds validation in places that previously failed silently, which may surface new warnings or errors after upgrading:

  • Misconfigured filters are now detected and reported with a warning, instead of silently matching nothing.
  • An unusable update check interval is now rejected instead of being ignored.
  • An invalid webservice timezone now fails instead of being silently reset.

Detailed list of changes

  • Let an abort interrupt the restore's file reads and writes, so a restore stops promptly, thanks @​JamBalaya56562
  • Stopped listing files interrupted by a shutdown as broken during restore, thanks @​JamBalaya56562
  • Stopped reporting a requested shutdown as a failure, thanks @​JamBalaya56562
  • Fixed the legacy restore engine creating a real folder in place of a directory symlink, thanks @​JamBalaya56562
  • Ran all main database queries through the slow-query monitor, so --long-database-query-threshold now warns about hanging queries, thanks @​JamBalaya56562
  • Added native desktop notifications: Windows toast notifications with click-to-open, macOS notifications, and Linux DBus notifications, thanks @​JamBalaya56562
  • Added support for native $VAR/${VAR} environment variable syntax in paths and filters on Linux and macOS, thanks @​JamBalaya56562
  • Made restore honor stop requests; aborted restores no longer report errors, blame the backup, or leak temp files, thanks @​JamBalaya56562
  • Fixed wrong seek offset when copying verified local blocks during restore, thanks @​JamBalaya56562
  • Fixed incorrect buffer copy when merging a hash fragment during restore, thanks @​JamBalaya56562
  • Preserved the selected folder during restore, thanks @​JamBalaya56562
  • Let configured default options apply when restore options are not specified, thanks @​JamBalaya56562
  • Prevented credentials from leaking through URL sanitizing on malformed URLs, thanks @​JamBalaya56562
  • Fixed corrupted target URL for local paths containing @, thanks @​JamBalaya56562
  • Matched backend URL schemes without regard to case, thanks @​JamBalaya56562
  • Fixed decoding of %uXXXX unicode escapes in URLs, thanks @​JamBalaya56562
  • Kept repeated path components in alternate update URLs, thanks @​JamBalaya56562
  • Parsed SSH, SMB, FTP, XMPP, pCloud, Tahoe-LAFS, and OAuth login URLs with the standard URI parser, thanks @​JamBalaya56562
  • Renamed the internal URL parser to RelaxedUri
  • Removed unused parts of the relaxed URL parser and documented its constraints, thanks @​JamBalaya56562
  • Re-created missing index files after the block volumes are processed, thanks @​JamBalaya56562
  • Recomputed the next scheduled run when weekdays or interval change, thanks @​JamBalaya56562
  • Fixed logout not awaiting invalidation and not clearing the refresh cookie, thanks @​JamBalaya56562
  • Improved console connection reconnect handling and allowed concurrent message processing
  • Guarded Hyper-V and MSSQL enumeration against errors
  • Simplified MS365 seat counting and improved site classification
  • Fixed MS365 user listing classification and return results sorted
  • Fixed pagination when listing backend destination folders
  • Treated an existing folder as success when auto-creating a destination, thanks @​JamBalaya56562
  • Made the connection test accept a missing probe file, thanks @​JamBalaya56562
  • Fixed Box folder resolution when the folder name is already in use, thanks @​JamBalaya56562
  • Fixed Box lookups ignoring the requested path, thanks @​JamBalaya56562
  • Fixed IDrive e2 reporting existing entries as missing, thanks @​JamBalaya56562
  • Reported the server error when a multipart upload fails, thanks @​JamBalaya56562
  • Observed read timeout on chunked uploads to Google and Dropbox, thanks @​JamBalaya56562
  • Checked response status before decrypting a Filen download, thanks @​JamBalaya56562
  • Checked response status before treating a pCloud upload as done, thanks @​JamBalaya56562
  • Checked response status when deleting a Tahoe-LAFS file, thanks @​JamBalaya56562
  • Fixed Filejump error handler calling itself indefinitely, thanks @​JamBalaya56562
  • Made BackendTester cleanup accept an already deleted file, thanks @​JamBalaya56562
  • Added detection of misconfigured filters with a warning
  • Rejected unusable update check intervals instead of ignoring them, thanks @​JamBalaya56562
  • Failed on an invalid webservice timezone instead of silently resetting it, thanks @​JamBalaya56562
  • Updated the help text for the sync command
  • Relaxed data folder permission checks for debug builds
  • Synced Japanese and Chinese README files with the English version, thanks @​JamBalaya56562
  • Updated all packages to latest versions
  • Updated SSH.NET and BouncyCastle dependencies
  • Updated js-yaml, fast-uri, and postcss dependencies
  • Updated the licenses project

Updates to ngclient

  • Fixed commandline autoscrolling, thanks @​JamBalaya56562
  • Fixed source filter highlighting, thanks @​JamBalaya56562
  • Prefill restore settings from configured backup settings, thanks @​JamBalaya56562
  • Updated Google Workspace icon
  • Fixed pagination in source tree
  • Database query timeout is now a "short time" type
  • Added a visual warning if filters are "exclude all"
  • Use -filename* as the default new filter to avoid having exclude all as the default
  • Updated all translations, thanks all translators

v2.3.0.108_canary_2026-07-20

Compare Source

This release is a canary release intended to be used for testing.

If no major faults are found, this release is intended to be the basis of the next beta release.

MS365 subsites and shared mailboxes

This release improves the Microsoft 365 backup support with two additions.
Support for backing up SharePoint subsites has been added, making it possible
to include sub-sites beneath a site collection in a backup.

The handling of shared mailboxes has also been improved, with better detection
and enumeration of shared mailboxes within a tenant.

The license counter now excludes shared mailboxes without a license, and supports
top-level filtering of users/sites/groups based on classification.

An extra information button is added to the source page that shows a summary
of what content was found in the MS365 tenant.

Case-insensitive remote filename matching

A new option has been added to perform case-insensitive matching of remote
filenames. This helps with backends that do not preserve filename casing, and
prevents issues where files cannot be found because of case differences.

Improved filter parsing

The filter parsing logic has been improved to handle more edge cases and
produce more predictable results when


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@Crow-Control Crow-Control left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved automated PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants