Commit Graph
10370 Commits
Author SHA1 Message Date
Wang Chencheng b93b73bcb0 operations: fix ignored error in rcat probe reads
Return the first non-EOF input error encountered while Rcat probes whether an
upload is small. Previously that error was ignored and the full probe buffer,
including bytes that were never read, could be passed to Put or PutStream.
2026-09-19 10:24:10 +01:00
NytePlus 1b3136702b fs: preserve explicitly supplied backend overview 2026-09-19 10:20:49 +01:00
Kalin Stoyanov 4928459f46 smb: Add workstation field to smb backend 2026-09-19 10:18:29 +01:00
Vasek Sraier d632f8bb51 serve restic: prevent concurrent append-only overwrites
- Reject uploads when object lookup fails for reasons other than "not found".
- Serialize uploads to the same object to prevent races between the
  existence check and the write.
2026-09-19 10:16:32 +01:00
Acts1631 c8d60a67fc compress: fix crash on ranged reads when gzip metadata is corrupted
Gzip metadata is read from the wrapped remote and could contain an
invalid block size or incomplete block index. A range read could then
panic in the seekable gzip reader.

Validate the gzip sidecar invariants before constructing a reader so
malformed remote metadata returns an error instead of crashing rclone.
2026-09-16 17:09:39 +01:00
Nick Craig-Wood a401763cf6 fstest: remove the TestS3MinioEdge test server
The minio/minio:edge image it ran has gone from Docker Hub and there
is no equivalent tag on quay.io, so this test remote can no longer be
started.
2026-09-16 09:17:11 +01:00
Nick Craig-Wood 4cf1da0d4f fstest: make test server start fail fast when docker run fails
The start function was run inside an if condition, where bash ignores
errexit, so a failed docker run was not noticed. The script then
printed its connection details anyway and the test spent 100 seconds
trying to connect before failing with a message that hid the real
error.

Run start in a subshell with errexit on and check its status
explicitly so the failure is reported immediately with docker's
error message.
2026-09-16 09:17:11 +01:00
Nick Craig-Wood e0d846f29e build: fix TestS3Minio by pulling minio from quay.io as it has gone from Docker Hub
The minio/minio repository has been removed from Docker Hub so the
TestS3Minio test server could not be started and every Linux CI run
failed. quay.io/minio/minio still serves the final release so use
that instead.
2026-09-16 09:17:11 +01:00
Nick Craig-Wood 9265e147b9 Add 6 new contributors
- ZRHann
- enkvadrat
- Vladimir Babin
- Eugene
- Kunpeng Xie
- foecmke
2026-09-16 09:17:11 +01:00
KBS 976d05e1dd rc: fix rc API accepting an out of range number and overflowing 64 bits
float64(math.MaxInt64) rounds up to 2^63, so x > math.MaxInt64 in
GetInt64 lets 2^63 through to int64(x), which is out of range.
2026-09-15 16:45:33 +01:00
foecmke b1a10fe17e docs: update --onedrive-hard-delete to mention personal account support 2026-09-15 16:42:32 +01:00
Kunpeng Xie 4f0148db0c accounting: stop averaging when the last check finishes
Release the averaging goroutine when checks outlast transfers, with a regression
test for the completion order.

Assisted-by: OpenAI Codex
2026-09-15 16:40:40 +01:00
tomaszni e85836d4c7 oracleobjectstorage: upload empty streams without multipart
OCI rejects a multipart completion request with no parts. Probe unknown-size
streams through a buffered reader and use a regular upload when the stream is
empty. Peek preserves a non-empty stream for the selected upload path.
2026-09-15 16:38:20 +01:00
Eugene 0cb6ddada9 cmount: ignore com.apple.* xattrs on the macOS FSKit backend 2026-09-15 12:10:22 +01:00
jzunigax2 77ec281072 internxt: fix lookups of files starting with a dot and dropped uploads
Internxt stores a file as a (plainName, type) pair and never derives the
split itself, so it is a convention shared between clients. This backend
split at the final dot, storing and looking up ".bashrc" as an empty name
of type "bashrc", where the web, desktop, Linux and macOS clients all keep
the leading dot in plainName. List rebuilt the full name so such files
appeared, but NewObject looked them up by the split and missed them.
2026-09-15 12:03:23 +01:00
jzunigax2 e441773d24 refactor: streamline file existence checks and metadata retrieval
- Replaced the preUploadCheck function with findFile for better clarity and efficiency in checking file existence.
- Introduced splitNameExt to encapsulate name and extension parsing logic.
- Updated NewObject and Update methods to utilize findFile for improved file metadata handling.
- Enhanced error handling and reduced redundant code in file checks.
2026-09-15 12:03:23 +01:00
tomaszni 934c21de26 oracleobjectstorage: purge objects in batches
Use OCI BatchDeleteObjects to remove up to 1,000 objects per request when
purging. Include directory markers so purging a bucket leaves it empty for
deletion.
2026-09-15 11:58:58 +01:00
tomaszni d81e8d7f54 oracleobjectstorage: encode carriage returns and line feeds
OCI Object Storage rejects NUL, carriage return and line feed in
object names. NUL is already encoded by rclone, while carriage returns
and line feeds need EncodeCrLf so rclone can represent those names
without issuing invalid OCI requests.

https://docs.oracle.com/en-us/iaas/Content/Object/Tasks/managingobjects.htm
2026-09-15 11:51:47 +01:00
n4n5 8fafc08dd1 docs: extend librclone instructions for gomobile 2026-09-14 14:45:31 +02:00
Vladimir Babin 3342e34f58 archive: fix crash when creating archive to stdout - fixes #9910
When rclone archive create is run without a destination the archive
should be written to stdout, but ArchiveCreate called
CheckValidDestination on the nil dst and panicked with a nil pointer
dereference. Skip the destination check when there is no destination.

Also remove a leftover debug Printf that wrote to stdout before the
archive data.

Signed-off-by: Vladimir Babin <vovababin@gmail.com>
2026-09-14 10:34:33 +02:00
maximilize 0e19ed565f docs: clarify --password-command quoting for a path with spaces 2026-09-14 07:27:06 +02:00
enkvadrat c2a5884ad9 docs: add padding to footer card
This is mostly visible in dark mode, as a side effect off adding the class,
the background of the card also changed to be dark-gray.
2026-09-14 07:25:31 +02:00
ZRHann 812e693fd7 webdav: fix duplicated listing entries after retried PROPFIND 2026-09-12 12:36:50 +01:00
tomaszni 886bd96d0a oracleobjectstorage: add server-side object moves
Use OCI RenameObject for moves within a bucket, avoiding a server-side copy
followed by source deletion. Cross-bucket moves continue to fall back to copy
and delete.
2026-09-12 12:32:29 +01:00
shauryaandno-hup c3ba184611 docs: fix broken --check-filename self-link in bisync docs
The link pointed at a bare relative path (--check-filename) instead of
the in-page anchor for the ### --check-filename heading further down the
page, so it 404s on the rendered docs site. Point it at #check-filename
(Hugo strips leading dashes when generating header anchors).

---------

Co-authored-by: no-hup <19599684+no-hup@users.noreply.github.com>
2026-09-11 06:16:21 +02:00
Nick Craig-Wood 7b3a4e5144 docs: update sponsors 2026-09-10 16:57:15 +01:00
Nick Craig-Wood b68bbeebb1 Add 9 new contributors
- Vaibhav Mashal
- Murat Topcu
- tomaszni
- eliotee
- Aditya
- Nicholas Velten
- youdie006
- subomi
- Can Arslan
2026-09-10 16:57:15 +01:00
Nick Craig-Wood e7bc3b2483 bin: make update-authors.py add multiple contributors in a single commit
When more than one new contributor is found, list their names in the
commit body rather than making one commit per person.
2026-09-10 16:57:15 +01:00
Can ArslanandCan Arslan 3fe205796a onedrive: allow --onedrive-upload-cutoff up to the documented limit of 250 MiB
Before this --onedrive-upload-cutoff was capped at 4 MiB and made
larger single-part uploads impossible.

Microsoft documents the limit for a single-request upload as "250 MB".
Measured against SharePoint Online the figure is binary and exclusive:
a body of 262143999 bytes is accepted and one of 262144000 is not.
Raise the constant to 250 MiB and record where it comes from.

The default is unchanged (upload_cutoff = -1, always chunk), so this
only affects users who raise the cutoff deliberately.

Co-authored-by: Can Arslan <carslan@viyaenv.com>
2026-09-10 16:17:19 +01:00
KBS c4f4dbf3ec fs: reject sizes too large for SizeSuffix instead of silently disabling the limit 2026-09-10 15:51:51 +01:00
subomi 8c32435bec docs: lshelp: explain that a directory on a bucket-based remote is a key prefix
Listing a bucket without -R shows each prefix as one directory entry, so the
objects under it are not in the output. This is easy to read as a truncated
listing rather than as one level of a hierarchy.

Fixes #9797
2026-09-10 15:46:08 +01:00
dependabot[bot] ef6968730f build: update google.golang.org/grpc to 1.85.0-dev.0.20260825072537-93e31b48545e to fix CVE-2026-84445
A vulnerability exists in gRPC-Go servers configured with
xds.NewGRPCServer() where a crafted request missing both :authority
and Host headers can cause a server panic, resulting in a Denial of
Service (DoS).

This update fixes the problem.
2026-09-09 10:38:19 +01:00
youdie006 52ac7e0e18 fs: fix about showing a negative total when a quota reaches the int64 maximum
NewUsageValue exists to clip an oversized quota to the maximum value of an
int64, which is what dc95f36bc added it for when Box raised the Enterprise
space_amount to 1e+18 and started returning it as a float.

For the float64 instantiation the guard misses its own boundary.
float64(math.MaxInt64) is not 2**63-1, it rounds up to 2**63, so a quota of
exactly 2**63 fails the comparison and falls through to the int64 conversion,
which the spec leaves implementation dependent for an unrepresentable value.
On linux/amd64 it wraps:

    Before: rclone about -> Total=-9223372036854775808
    After:  rclone about -> Total=9223372036854775807

A negative total is not just a wrong number. vfs.Statfs documents -1 as "not
known", vfs.fillInMissingSizes branches on total < 0, and serve sftp only
computes its usage percentage when total > 0, so the value is read back as a
missing quota.

The int64 and uint64 instantiations are unaffected, since for them
T(int64(math.MaxInt64)) is exact and clipping MaxInt64 to MaxInt64 is a no-op.
2026-09-09 10:31:29 +01:00
youdie006 5bbc5d5545 fs: make BwTimetable.Set replace the timetable instead of appending to it
Set built the timetable with *x = append(*x, ts), so setting a bandwidth
timetable on a value that already held one kept both schedules. The single-value
branch of the same function has always done *x = BwTimetable{ts}, and the other
multi-token Set methods in this package build into a local and assign at the end.

The visible effect is through the rc API. The "main" options block registered in
fs.RegisterGlobalOptions is the live globalConfig, and options/set reshapes JSON
straight into it, so

  rclone rc options/set --json '{"main": {"BwLimit": "Mon-10:00,1Mi"}}'

added to the running daemon's timetable rather than replacing it, and the older
slot kept winning: LimitAt for a Sunday returned the previous 10Mi. The same
applies to a _config override on a single call, since AddConfig shallow-copies
the global.

Building into a local also stops a failed parse from leaving the previous
timetable partly overwritten, which the existing error cases already expect.
2026-09-09 10:28:44 +01:00
Nicholas Velten e45210765c touch: parse documented timestamp formats 2026-09-09 10:24:48 +01:00
Aditya ea589de941 s3: disable signing Accept-Encoding for Ceph and Linode - fixes #8206
Ceph RGW (and Linode Object Storage, which is Ceph-backed) can break
SigV4 when Accept-Encoding is included in the signature, especially
when a reverse proxy rewrites that header. GCS already sets this quirk;
apply the same default for Ceph and Linode as suggested in #8206.
2026-09-09 10:21:07 +01:00
eliotee 39b487d7f7 s3: add backend link command with signed response header overrides
Fixes #7684.
2026-09-08 17:23:10 +01:00
tomaszni 3eee2c0dd2 oracleobjectstorage: fix SSE-C server-side copies
Set the OCI source SSE-C request headers when using a customer key.
Server-side copies need these headers to decrypt the source object, in
addition to the existing headers that encrypt the destination.
2026-09-08 17:18:00 +01:00
Murat Topcu 89fc14059e selfupdate: fix TestInstallOnLinux panicking when the build is the latest beta
The test asks InstallUpdate to install the latest beta into an
unwritable file and expects an error. When the binary under test
reports exactly the latest beta version (as make quicktest does right
after a beta is published from the same commit), InstallUpdate
correctly decides there is nothing to do and returns nil, and the test
then dereferences the nil error and panics.

Pin fs.Version to a fixed old value for the duration of the test so an
update is always attempted, and use require.Error so a missing error
fails the test instead of crashing it.
2026-09-08 17:16:06 +01:00
phatlc 03783be7a5 fs/config: only run --password-command once when using --daemon
Decrypting the config with --daemon runs --password-command twice, which
means two authentications when the command needs one, such as a hardware
key touch for `pass show`.

SetConfigPassword saves the obscured key to the temp file named by
_RCLONE_CONFIG_KEY_FILE so the daemon process can pick it up, but the
process that wrote it then read and deleted that file itself before
daemonizing. The daemon started with the variable pointing at a file that
was already gone, found no key, and ran the password command again.

Skip acquiring a password when _RCLONE_CONFIG_KEY_FILE is set, as the
PassConfigKeyForDaemonization documentation already describes, and only
consume the key file in a process that has no key of its own. The parent
then leaves the key for the daemon, and the daemon uses it.

Fixes #7341
2026-09-08 17:13:23 +01:00
Vaibhav Mashal 2c4bc66e45 docker: make container user UID and GID configurable via build ARGs - fixes #9839 2026-09-08 17:09:05 +01:00
phatlc 9ac29e3b35 serve docker: fix volume path being lost when the plugin restarts
applyOptions consumes the "path" option into vol.Path rather than leaving
it in vol.Options, but restoreState rebuilt the options with only fs and
type. The explicit path was therefore dropped when the plugin restarted,
and since fsString is rebuilt from those options the volume was remounted
at the root of the remote instead of at its subpath.

Before this change a volume created with type + path lost its path
completely, and one created with remote + path silently fell back to the
path of the connection string. With a backend whose credentials are
scoped to the subpath the restored mount then failed every operation
rather than serving the wrong directory.

Feed the persisted path back like fs and type, so applyOptions applies
the same precedence on restore that it applies when the volume is
first created.

Fixes #9853
2026-09-08 17:05:23 +01:00
phatlc b549554c31 dropbox: match shared-folder and received-file names case-insensitively - fixes #9706
The Dropbox backend advertises CaseInsensitive: true, but the two
shared-mode lookup helpers compared names with an exact, case-sensitive
==, so a shared folder or received file named "Project" could not be
found when requested as "project". Use strings.EqualFold in both
findSharedFolder and findSharedFile to honour the advertised
case-insensitivity.

Fixes #9706
2026-09-08 16:57:43 +01:00
phatlc ac7cfcc848 dropbox: fix shared folder mount for roots nested more than one level deep
In shared_folders mode NewFs derived the shared folder name with
path.Dir(f.root), which returns the parent path rather than the first
path component. For a root like "SharedFolder/subdir/deeper" this yielded
"SharedFolder/subdir", which findSharedFolder cannot match, so NewFs
failed with ErrorDirNotFound. Use the first path component of the root,
as the shared_folders option documents, so deeply nested roots mount.

Fixes #9705
2026-09-08 16:55:15 +01:00
Sanjay Kanth A 13084df67c yandex: add app_folder option to support cloud_api:disk.app_folder OAuth scope - Fixes #9848 2026-09-08 16:40:17 +01:00
ferrumclaudepilgrim 2cec6065d3 local: make out of space errors fatal during multi-thread transfers 2026-09-08 16:35:36 +01:00
ferrumclaudepilgrim 7bfc9ca648 local: clarify what --local-fatal-if-no-space catches
The flag applies to out of space errors while writing and while creating
files or directories, not only while writing. Describe those operations
without naming ENOSPC, which is a Unix error that Windows never reports, so
the help is accurate on every platform.
2026-09-08 16:35:36 +01:00
ferrumclaudepilgrim e724790620 vfs/vfscache: fix hang when the cache cleaner is disabled
KickCleaner sets the out of space flag, kicks the cleaner and then waits for
that flag to clear. Only the cleaner clears it, and the cleaner returns
immediately when the cache poll interval is not positive, so when it is
disabled nothing ever reads the kick or clears the flag and the caller waits
forever.

It now returns straight away in that case, under the same condition the
cleaner itself uses to decide it is disabled. Callers already retry a bounded
number of times and then report the error, which is the right outcome when
nothing is going to free space.
2026-09-08 16:35:36 +01:00
ferrumclaudepilgrim ca41db095b fserrors: fix out of space detection on Windows - fixes #8011
IsErrNoSpace compared against syscall.ENOSPC. Go defines that constant on
Windows as a value in its application reserved range which no Windows API
returns, so the comparison could never be true there. A full disk on Windows
reports ERROR_DISK_FULL or ERROR_HANDLE_DISK_FULL instead.

Preallocation failures were still caught, because those return a separate
sentinel, but a disk that is already full fails at the directory creation or
at the open long before preallocation is reached. That is the case reported.

The errors are now held in a list which platform specific files add to in
their init, which is the shape retriable_errors already uses in this package,
and the comparison itself is unchanged. Windows appends the two codes that
lib/file already recognises when preallocation fails. Every other platform
keeps exactly the behaviour it had.

This also reaches the VFS cache, which uses the same helper and has no
preallocation path of its own, so its out of space handling has been inert
on Windows.
2026-09-08 16:35:36 +01:00
Sanjay Kanth A c875d89033 docs: drive: document Branding step needed to publish own client_id
Google now requires an app homepage URL and privacy policy URL to be
set on the OAuth consent screen's "Branding" page before the "PUBLISH
APP" button becomes clickable, even for a personal single-user app.
The existing instructions jumped straight to publishing in step 9
without mentioning this, leaving the button greyed out with no
explanation of why.

Fixes #9854
2026-09-08 10:51:05 +01:00