rust-proxmox-backup (4.2.5-1) trixie; urgency=medium

  * backup: harden the handling of client supplied backup manifests:
    - only accept archive names that are plain file names carrying a server
      side type extension. A crafted name in a manifest could previously make
      a sync job read or write outside of the snapshot directory, running as
      the unprivileged 'backup' user. Reaching this needed a manifest from a
      configured sync remote or from a client that already had backup access
      to the datastore.
    - keep an uploaded manifest in memory and only persist it on backup
      finish, checking that every archive it lists was really uploaded during
      that session and that the checksums match the ones computed server
      side. A client uploading a manifest that references archives it did not
      upload now gets an error on finish instead of such a snapshot being
      created.

  * fix #7878: sync: push: reuse the manifest of a previous snapshot on a
    non-encrypting push if the source snapshot was encrypted with a matching
    key, restoring chunk reuse and thus avoiding needlessly long sync runs.

  * sync: push: keep the sign-only crypt mode of a source archive instead of
    reducing it to unencrypted when pushing without server side encryption.

  * subscription: reject a subscription key issued for a different
    architecture than the host, as arm64 keys carry an explicit marker, so a
    wrong key fails fast instead of only erroring during the online check.

  * update to proxmox-upgrade-checks 1.1, which accepts the 7.0 kernel, tells
    a bookworm backport apart from a trixie build and fixes the dkms check.

  * docs: clarify in the backup protocol description that the manifest is
    uploaded by the client and only persisted on backup finish.

 -- Proxmox Support Team <support@proxmox.com>  Wed, 05 Aug 2026 18:25:37 +0200

rust-proxmox-backup (4.2.4-1) trixie; urgency=medium

  * docs: document the debug symbol repository

  * datastore: fix wrong local path used for S3 bad chunk handling during
    garbage collection

  * refactor file creation/mode/ownership helpers to proxmox-product-config
    crate

  * fix #7642: avoid expensive user lookups on file locking by caching the
    backup user/group ID

  * depend on proxmox-enterprise-support-keyring, and track its version in the
    package version API endpoint

  * fix #5748: docs: add `catalog.pcat1` format specification

  * docs: system requirements: document we recommend local storage

  * S3: fix #6841: allow configuring request rate limits by updating to
    proxmox-s3-client 1.4.1. these rate limits are split into active and
    passive methods, allowing separate handling of POST/PUT/DELETE and GET/HEAD
    request limits.

  * S3: config: allow editing the use-node-config flag that controls whether
    requests S3 endpoints honor the node's proxy settings or not

  * sync: push: gracefully handle previous manifest signature mismatches, which
    can happen when enabling or disabling push-encryption on an already synced
    backup group

 -- Proxmox Support Team <support@proxmox.com>  Wed, 29 Jul 2026 15:08:15 +0200

rust-proxmox-backup (4.2.3-1) trixie; urgency=medium

  * css: remove x-grid-row-loading class, replace it with non-blurry SVG
    variant from proxmox-widget-toolkit

  * pbs-client: add backoff log throttle, to ensure progress and similar output
    appears quickly initially, but does not create overly long logs

  * client: report progress during restore

  * api: journal: adopt proxmox-syslog-api and stream the output, making the
    implementation consistent with the one from Proxmox Datacenter Manager

  * ui: enable the structured journal view and per-service logs, including
    colored output and filtering capabilities

  * ui: always use arrays for 'delete' property, instead of manually converting

  * fix #5971: tape: don't warn on custom MAM attribute write failures

  * fix #7175: api: time: use timedatectl instead of /etc/timezone

  * fix #7187: report: add ethtool output for physical interfaces

  * prune jobs: schedule jobs that do not prune anything, but warn during their
    execution. such jobs allow testing scheduling options, but make no sense
    for production use.

  * fix #6691: allow search by comment in datastore content, make search
    case-insensitive and correctly reset content view after empty searches

  * ui: datastore: disable various action tooltips for actions which cannot be
    triggered

  * ldap: escape the user-provided user name when using it in the LDAP search
    filter that looks up the user DN.

  * ldap sync: log which user properties change when synchronizing an existing
    user, instead of only reporting that the user was updated.

  * api schema/section config: add support for declaring deprecated property
    aliases, to allow renaming properties without showing the old name in the
    documentation

  * rest server: accept deprecated property aliases in JSON request bodies by
    rewriting them to the canonical name before verification and dispatch, like
    the CLI and query-string handling already do.

  * fix #7690: fs: replace_file: close the temporary file before renaming or
    unlinking it, fixing the replacement on WORM file systems and avoiding
    leftover .fuse_hidden files on FUSE mounts.

  * fs: make_tmp_file: append the temporary suffix instead of replacing the
    file extension, keeping the original file name intact for easier
    debugging of leftover temporary files.

 -- Proxmox Support Team <support@proxmox.com>  Tue, 14 Jul 2026 12:54:15 +0200

rust-proxmox-backup (4.2.2-1) trixie; urgency=medium
