rust-proxmox-backup (4.2.5-1) trixie; urgency=medium * backup: harden the handling of client supplied backup manifests: - only accept archive names that are plain file names carrying a server side type extension. A crafted name in a manifest could previously make a sync job read or write outside of the snapshot directory, running as the unprivileged 'backup' user. Reaching this needed a manifest from a configured sync remote or from a client that already had backup access to the datastore. - keep an uploaded manifest in memory and only persist it on backup finish, checking that every archive it lists was really uploaded during that session and that the checksums match the ones computed server side. A client uploading a manifest that references archives it did not upload now gets an error on finish instead of such a snapshot being created. * fix #7878: sync: push: reuse the manifest of a previous snapshot on a non-encrypting push if the source snapshot was encrypted with a matching key, restoring chunk reuse and thus avoiding needlessly long sync runs. * sync: push: keep the sign-only crypt mode of a source archive instead of reducing it to unencrypted when pushing without server side encryption. * subscription: reject a subscription key issued for a different architecture than the host, as arm64 keys carry an explicit marker, so a wrong key fails fast instead of only erroring during the online check. * update to proxmox-upgrade-checks 1.1, which accepts the 7.0 kernel, tells a bookworm backport apart from a trixie build and fixes the dkms check. * docs: clarify in the backup protocol description that the manifest is uploaded by the client and only persisted on backup finish. -- Proxmox Support Team Wed, 05 Aug 2026 18:25:37 +0200 rust-proxmox-backup (4.2.4-1) trixie; urgency=medium * docs: document the debug symbol repository * datastore: fix wrong local path used for S3 bad chunk handling during garbage collection * refactor file creation/mode/ownership helpers to proxmox-product-config crate * fix #7642: avoid expensive user lookups on file locking by caching the backup user/group ID * depend on proxmox-enterprise-support-keyring, and track its version in the package version API endpoint * fix #5748: docs: add `catalog.pcat1` format specification * docs: system requirements: document we recommend local storage * S3: fix #6841: allow configuring request rate limits by updating to proxmox-s3-client 1.4.1. these rate limits are split into active and passive methods, allowing separate handling of POST/PUT/DELETE and GET/HEAD request limits. * S3: config: allow editing the use-node-config flag that controls whether requests S3 endpoints honor the node's proxy settings or not * sync: push: gracefully handle previous manifest signature mismatches, which can happen when enabling or disabling push-encryption on an already synced backup group -- Proxmox Support Team Wed, 29 Jul 2026 15:08:15 +0200 rust-proxmox-backup (4.2.3-1) trixie; urgency=medium * css: remove x-grid-row-loading class, replace it with non-blurry SVG variant from proxmox-widget-toolkit * pbs-client: add backoff log throttle, to ensure progress and similar output appears quickly initially, but does not create overly long logs * client: report progress during restore * api: journal: adopt proxmox-syslog-api and stream the output, making the implementation consistent with the one from Proxmox Datacenter Manager * ui: enable the structured journal view and per-service logs, including colored output and filtering capabilities * ui: always use arrays for 'delete' property, instead of manually converting * fix #5971: tape: don't warn on custom MAM attribute write failures * fix #7175: api: time: use timedatectl instead of /etc/timezone * fix #7187: report: add ethtool output for physical interfaces * prune jobs: schedule jobs that do not prune anything, but warn during their execution. such jobs allow testing scheduling options, but make no sense for production use. * fix #6691: allow search by comment in datastore content, make search case-insensitive and correctly reset content view after empty searches * ui: datastore: disable various action tooltips for actions which cannot be triggered * ldap: escape the user-provided user name when using it in the LDAP search filter that looks up the user DN. * ldap sync: log which user properties change when synchronizing an existing user, instead of only reporting that the user was updated. * api schema/section config: add support for declaring deprecated property aliases, to allow renaming properties without showing the old name in the documentation * rest server: accept deprecated property aliases in JSON request bodies by rewriting them to the canonical name before verification and dispatch, like the CLI and query-string handling already do. * fix #7690: fs: replace_file: close the temporary file before renaming or unlinking it, fixing the replacement on WORM file systems and avoiding leftover .fuse_hidden files on FUSE mounts. * fs: make_tmp_file: append the temporary suffix instead of replacing the file extension, keeping the original file name intact for easier debugging of leftover temporary files. -- Proxmox Support Team Tue, 14 Jul 2026 12:54:15 +0200 rust-proxmox-backup (4.2.2-1) trixie; urgency=medium