paramiko's connect had no timeout, so a server that doesn't answer
made the program hang until the OS gave up (about 2 minutes). Give up
after 15 seconds and exit with code 5.
The example config has empty remote_sudo and numeric_ids values, which
made getboolean fail with "Bad configuration file" if the [server]
section was uncommented, and an empty ssh_keyfile was used as the key
path. Treat empty values as false or not set, and show false in the
example config.
The connection was only closed at the end of a backup that ran to
completion, not on early returns (e.g. missing output folder or no
inputs) or exceptions, and a client that failed to log in was left
open. Close it in all cases, and remove the unused _password field.
Old backups were listed with os.listdir, so a stray file or symlink
in the backup folder counted as a backup: depending on its name,
rmtree crashed on it or one backup too many was removed. An
unreadable backup folder also crashed with PermissionError. Count
only directories, and log an error if the folder can't be read.
Old backups on the server were listed with ls, which also lists files
and prints nothing on errors. A stray file made one backup too many
get removed, and an empty or unreadable backup folder was counted as
one backup with an empty name, which made rm -r delete the whole
simple_backup folder. List only directories with find, and don't
remove anything if listing fails.
An empty answer raised IndexError, and running without a terminal
(e.g. from cron) raised EOFError. Treat both as "no", and log why the
connection was aborted.
Remote backup needs both, but if only one was set the program silently
ran a local backup instead, and a missing ssh_user in the config also
dropped ssh_host. Exit with an error (code 6) instead.
The output path was made absolute with os.path.abspath and '~' was
expanded to the local home, so relative paths and '~' pointed to the
wrong folder on the server. Resolve the path on the server instead,
where '~' and relative paths refer to the remote user's home, and
document it.
The rsync command was built as a string and split with shlex.split,
so paths containing quotes broke it, and the key file path in the -e
command was split on spaces. Pass each path as its own argument, and
quote the key file and user name inside the -e command, which rsync
splits itself.
Remote commands were built with f-strings, with paths either unquoted
or in double quotes. Paths with spaces broke ls and find, and $ or
backticks in a path were expanded by the server's shell. Quote every
path with shlex.quote.
rsync's ssh command used StrictHostKeyChecking=no, so it connected
even if the server's host key had changed. Use accept-new instead:
unknown hosts are still added automatically, but a changed key for a
known host makes the connection fail.
The key file given with --keyfile was only passed to rsync's ssh
command when running as root, so as a normal user rsync ignored it
and fell back to the default keys or the agent.
An unknown hostname, a refused connection or an unreachable server
raise OSError (socket.gaierror, NoValidConnectionsError), which
paramiko.SSHException doesn't cover, so the program crashed with a
traceback. Log the error and exit with code 5 instead.
Code 24 (source files vanished during the transfer) already counted as
success when deciding whether to remove old backups, but the program
still exited with 4 and reported errors. Exit with 0 and report the
backup as completed, logging only a warning, so both checks agree.
The remote branch of run() returned None, so the program always exited
with 0, and it decided whether the backup worked by checking that the
backup folder existed on the server, ignoring rsync's return code.
Use the same return code check for local and remote backups.
Unencrypted ed25519 and ECDSA keys crashed with an uncaught
SSHException, and the DSA fallback raised NameError since paramiko 4
removed DSSKey. Load the key with paramiko.PKey.from_path instead,
ask for the passphrase only when the key is encrypted, and log an
error instead of crashing when the key can't be loaded.
Require paramiko >= 3.2 for PKey.from_path.
Use git.shouldnt.work as the clone URL, don't install wheel for
building, as setuptools no longer needs it, list paramiko among the
optional dependencies, and use the correct names of the remote
backup options (--ssh-user, --ssh-host).
With --remove-before-backup, a failed backup leaves only the kept
backups, or none with keep=0. Log an error and send a notification
in that case, and document it in the man page.
With --remove-before-backup, the last backup was selected for
--link-dest before old backups were removed, so with keep=0 rsync
was given a directory that no longer existed.
With --rsync-options, only -r and -v were kept, so the first backup
failed because the simple_backup directory did not exist yet, and a
missing input made rsync fail. Use these options in any case.
Invalid values (e.g. an empty or non-numeric 'keep') and syntax
errors in the config file raised uncaught exceptions. Catch them
and exit with code 6, including the reason in the error message.
ConfigParser interpolation treats '%' as special, so a path or
pattern containing it crashed the program. Disable interpolation,
which is not used by the config file.
'inputs=/a, /b' was read as '/a' and ' /b', so /b was skipped, and
excluded patterns with spaces around them never matched. Strip
whitespace from each value, and ignore empty exclude entries.
':' is not allowed on FAT/exFAT filesystems, so backups to such
drives failed. Use '%Y-%m-%d_%H-%M-%S' instead; existing backups
with the old format still sort correctly. Document the limitations
of FAT/exFAT in the man page.
The inputs temp file was left behind when no inputs existed, and
both temp files if rsync failed to start. The descriptors returned
by mkstemp were also never closed. Remove the temp files when run()
exits in any way, and write them through the mkstemp descriptors.
Without dbus-python, or without a session bus (e.g. when running
from a timer), each notification printed a traceback. Skip
notifications if dbus is not installed, and log a single warning
if sending one fails. Remove the now unneeded NameError handling
around _notify calls.
warnings.filterwarnings('error') applied to the whole program, so
any warning raised by a library (e.g. a DeprecationWarning) would
crash it. Limit it to the ssh connection (unknown host key) and
the password prompt (no terminal available).
The return annotation of _ssh_connect referenced paramiko, which
Python < 3.14 evaluates at class definition, raising NameError when
paramiko (an optional dependency) is missing. Postpone evaluation
of annotations, and mark the return type as Optional.
The default config path was computed before -u was parsed, so
running as root without sudo/doas used '~None/...' even when the
user was given with -u. Expand '~' only after the user is detected.
User detection only checked SUDO_USER, so with doas the user's
config file was not found unless -u was given. Fall back to
DOAS_USER, as already done for notifications.
If rsync returns an error, the new backup may be incomplete. Keep
the old backups in that case, except for return code 24 (vanished
source files), which is expected when backing up a live system.
rsync reads --files-from entries relative to the source directory
('/'), so relative inputs pointed to the wrong path and were ignored
due to --ignore-missing-args. Convert inputs to absolute paths.
Check that the inputs specified on the command line (i.e. with the
option '-i' or '--input') exist and print a warning when they don't.
If no valid inputs are found, exit.
@@ -20,28 +20,55 @@ The script uses rsync to actually run the backup, so you will have to install it
sudo pacman -Syu rsync
```
Optional dependencies are systemd-python to enable using systemd journal for logging, dbus-python for desktop notifications, and paramiko for remote backup.
## Install
To install the program, first clone the repository:
Install tools required to build and install the package:
Then install the tools required to build the package:
```bash
pip install --upgrade build installer wheel
pip install --upgrade build
```
Then run:
Finally, run:
```bash
cd simple_backup
python -m build --wheel
python -m installer dist/*.whl
python -m pip install dist/*.whl
```
For Arch Linux, a PKGBUILD that automates this process is provided.
For Arch Linux and Arch-based distros, two packages are available in the AUR (aur.archlinux.org):
- **simple_backup** for the release version
- **simple_backup-git** for the git version
After installing, copy simple_backup.conf (if you used the PKGBUILD on Arch, it will be in /etc/simple_backup/) to $HOME/.config/simple_backup and edit is as needed.
## Old backups
The number of old backups to keep can be set with the --keep (or -k) argument (or in the configuration file).
Old backups are only removed if rsync completes successfully, so that they are not deleted when the new backup may be incomplete.
The only rsync error that is ignored is return code 24 (source files vanished during the transfer), which is common when backing up a live system.
## Remote backup
> **Warning**
> This feature is experimental
It's possible to use a remote server as destination for the backup. Just use the --ssh-user and --ssh-host arguments (or set them in the configuration file).
For this to work, rsync must be installed on the server too.
### Server authentication
The best way to handle the authentication is to have an ssh agent running on your system, otherwise if a passphrase is necessary to unlock the ssh key, it will be necessary to enter it more than once.
If needed, it's possible to specify the ssh key location with the --keyfile argument or in the configuration file.
To be able to connect to the user's ssh agent when running simple_backup with sudo, make sure to preserve the SSH_AUTH_SOCK environment variable. For example:
Options \-r, \-v, \-\-ignore\-missing\-args and \-\-mkpath are used in any case. Note that options must be specified without dash (\-), for example:
.P
.EX
simple_backup \-\-rsync\-options a l p
.EE
.P
Check
.BRrsync(1)
for details about the options.
.RE
.TP
.B\-\-remote\-sudo
Run rsync on the remote server with sudo. This is needed if you want to preserve the owner of the files/folders to be copied (rsync \-\-owner option). For this to work the user used to login to the server obviously need to be allowed to use sudo. In addition, the user need to be able to run rsync with sudo without a password. To do this, /etc/sudoers on the server need to be edited adding a line like this one:
.RS
.P
<username> ALL=NOPASSWD:<path/to/rsync>
.P
To be able to remove old backups generated with \-\-remote\-sudo (see \-\-keep option), also
.BRrm(1)
needs to be allowed to run without password in the same way.
.RE
.TP
.B\-\-numeric\-ids
Use rsync \-\-numeric\-ids option. This causes rsync to use numeric uid/gid instead of trying to map uid/gid names from the local machine to the server.
.SHCONFIGURATION
An example configuration file is provided at \(aq/usr/share/doc/simple_backup/simple_backup.conf\(aq.
Copy it to the default location ($HOME/.config/simple_backup) and edit it as needed.
.SHREMOTEBACKUP
It is possible to choose a directory on a remote server as destination for the backup. The files
are copied by rsync through SSH. Server hostname and username must be specified, either in the
configuration file, or on the command line (\(aq\-\-ssh\-host\(aq and \(aq\-\-ssh\-user\(aq options).
.P
The output directory is a path on the server. A leading \(aq~\(aq and relative paths refer to the
home directory of the user on the server. On the command line, quote \(aq~\(aq so that the local
shell doesn\(aqt expand it, for example:
.P
.EX
simple_backup \-\-ssh\-host server \-\-ssh\-user user \-o \(aq~/backups\(aq
.EE
.SSAUTHENTICATION
For authentication, it is possible to use SSH key or password.
.P
When using SSH key, the best way to connect to the server is to have an SSH agent running.
Otherwise, if the SSH key is encrypted, it will be necessary to enter the passphrase more
than once. It is possible to specify the SSH key to use with the option \(aq\-\-keyfile\(aq,
if necessary.
.P
When running
.Bsimple_backup
with
.Bsudo,
in order to connect to the user\(aqs SSH agent it is necessary to preserve the \(aqSSH_AUTH_SOCK\(aq environment variable, for example:
# Files and directories to backup. Multiple items can be separated using a comma (','). It is possible to use wildcards (i.e. '*' to match multiple characters and '~' for the user's home directory).
inputs=/home/user
# Output directory. For remote backups, this is a path on the server ('~' and relative paths refer to the home directory on the server).
backup_dir=/media/Backup
# Files, directories and patterns to exclude from the backup. Multiple items can be separated using a comma.
exclude=*.bak
# Number of old backups (i.e. excluding the one that's being created) to keep (use -1 to keep all)
keep=-1
# Uncomment the following section to enable backup to remote server through ssh
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.