More of the security work from the past week, plus two requested features.
Security
- Borg updates are verified before they are installed. The server checks each download against the SHA-256 digest GitHub publishes for it, and against the Borg project's signature where the release has one. Nothing is run before it passes. Server-hosted builds need a valid signature from the BBS release key. Updating to borg 1.4.1 or older is refused, because GitHub publishes no digest for those releases.
- Remote SSH host settings are checked again before every use, not only when saved. A host saved before that check existed is set aside, with a warning in the log, until it is edited and saved. The agent also refuses a repository address whose SSH user or host is not valid.
- The MongoDB password no longer appears in the process list on the client. mongodump and mongorestore read it from a private file (MongoDB Database Tools 100.3 and newer), and mongosh gets it from its environment.
- SSO redirect addresses come from the configured server address, never from the request.
New
- Archive delete shows progress (#527). The job page shows borg's progress while a delete runs. Warnings appear in the activity log as they happen, and the amount of data removed is logged at the end.
- Dry runs keep their full file list (#414). The job page has a download of every included and excluded path, kept for a day, with a button to delete it sooner. The result also shows the size of what would be backed up, before compression and deduplication.
Fixes
- Archive downloads larger than about 500 MB were cut off part way.
- Retrying a failed archive delete failed with "No archive name specified".
- The activity log, dashboard notifications and emails showed internal job names such as
s3_syncinstead of "Offsite sync" (#524). - Archive delete, archive lock, compact and repair on a read-only repository copy are refused straight away, instead of being accepted and failing when the job starts.
Agent updated to 2.98.6.