Remote commands were built with f-strings, with paths either unquoted
or in double quotes. Paths with spaces broke ls and find, and $ or
backticks in a path were expanded by the server's shell. Quote every
path with shlex.quote.
rsync's ssh command used StrictHostKeyChecking=no, so it connected
even if the server's host key had changed. Use accept-new instead:
unknown hosts are still added automatically, but a changed key for a
known host makes the connection fail.
The key file given with --keyfile was only passed to rsync's ssh
command when running as root, so as a normal user rsync ignored it
and fell back to the default keys or the agent.
An unknown hostname, a refused connection or an unreachable server
raise OSError (socket.gaierror, NoValidConnectionsError), which
paramiko.SSHException doesn't cover, so the program crashed with a
traceback. Log the error and exit with code 5 instead.
Code 24 (source files vanished during the transfer) already counted as
success when deciding whether to remove old backups, but the program
still exited with 4 and reported errors. Exit with 0 and report the
backup as completed, logging only a warning, so both checks agree.
The remote branch of run() returned None, so the program always exited
with 0, and it decided whether the backup worked by checking that the
backup folder existed on the server, ignoring rsync's return code.
Use the same return code check for local and remote backups.
Unencrypted ed25519 and ECDSA keys crashed with an uncaught
SSHException, and the DSA fallback raised NameError since paramiko 4
removed DSSKey. Load the key with paramiko.PKey.from_path instead,
ask for the passphrase only when the key is encrypted, and log an
error instead of crashing when the key can't be loaded.
Require paramiko >= 3.2 for PKey.from_path.
Use git.shouldnt.work as the clone URL, don't install wheel for
building, as setuptools no longer needs it, list paramiko among the
optional dependencies, and use the correct names of the remote
backup options (--ssh-user, --ssh-host).
With --remove-before-backup, a failed backup leaves only the kept
backups, or none with keep=0. Log an error and send a notification
in that case, and document it in the man page.
With --remove-before-backup, the last backup was selected for
--link-dest before old backups were removed, so with keep=0 rsync
was given a directory that no longer existed.
With --rsync-options, only -r and -v were kept, so the first backup
failed because the simple_backup directory did not exist yet, and a
missing input made rsync fail. Use these options in any case.
Invalid values (e.g. an empty or non-numeric 'keep') and syntax
errors in the config file raised uncaught exceptions. Catch them
and exit with code 6, including the reason in the error message.
ConfigParser interpolation treats '%' as special, so a path or
pattern containing it crashed the program. Disable interpolation,
which is not used by the config file.
'inputs=/a, /b' was read as '/a' and ' /b', so /b was skipped, and
excluded patterns with spaces around them never matched. Strip
whitespace from each value, and ignore empty exclude entries.
':' is not allowed on FAT/exFAT filesystems, so backups to such
drives failed. Use '%Y-%m-%d_%H-%M-%S' instead; existing backups
with the old format still sort correctly. Document the limitations
of FAT/exFAT in the man page.
The inputs temp file was left behind when no inputs existed, and
both temp files if rsync failed to start. The descriptors returned
by mkstemp were also never closed. Remove the temp files when run()
exits in any way, and write them through the mkstemp descriptors.
Without dbus-python, or without a session bus (e.g. when running
from a timer), each notification printed a traceback. Skip
notifications if dbus is not installed, and log a single warning
if sending one fails. Remove the now unneeded NameError handling
around _notify calls.
warnings.filterwarnings('error') applied to the whole program, so
any warning raised by a library (e.g. a DeprecationWarning) would
crash it. Limit it to the ssh connection (unknown host key) and
the password prompt (no terminal available).
The return annotation of _ssh_connect referenced paramiko, which
Python < 3.14 evaluates at class definition, raising NameError when
paramiko (an optional dependency) is missing. Postpone evaluation
of annotations, and mark the return type as Optional.
The default config path was computed before -u was parsed, so
running as root without sudo/doas used '~None/...' even when the
user was given with -u. Expand '~' only after the user is detected.
User detection only checked SUDO_USER, so with doas the user's
config file was not found unless -u was given. Fall back to
DOAS_USER, as already done for notifications.
If rsync returns an error, the new backup may be incomplete. Keep
the old backups in that case, except for return code 24 (vanished
source files), which is expected when backing up a live system.
rsync reads --files-from entries relative to the source directory
('/'), so relative inputs pointed to the wrong path and were ignored
due to --ignore-missing-args. Convert inputs to absolute paths.