Commit Graph
10398 Commits
Author SHA1 Message Date
Nick Craig-Wood ff02636fe4 onedrive: update docs for versions, links and time precision on personal accounts
Testing against OneDrive personal (free) and OneDrive for Business shows

- personal accounts now create versions on setting the modification
  time and can delete them, so --onedrive-no-versions and rclone
  cleanup work there
- --onedrive-link-password works on OneDrive for Business
- personal free accounts can't set a link password or --expire
- --onedrive-link-type embed only works on OneDrive personal
- personal accounts store times with 1s precision, not mS

See #9917
2026-09-22 15:12:29 +01:00
Nick Craig-Wood 7a2d7c766d vfs: fix crash reading the metadata of a file which is being written
With --vfs-metadata-extension set, looking up the metadata file of a
file which was open for write and not yet uploaded caused a nil pointer
panic. Such a file has no object to read the modification time from.

Use the modification time of the VFS node instead, which is valid
whether or not the file has been uploaded.
2026-09-22 15:01:44 +01:00
Nick Craig-Wood ff958c999f operations: fix TestDeleteFatalError, TestDirMoveMoveError and TestDirMoveContext on remotes
TestDeleteFatalError set --max-delete before writing its files, so on
chunker, which deletes while uploading, the setup failed.

TestDirMoveMoveError and TestDirMoveContext test the core DirMove logic
with a wrapping Fs. This fails on remotes without Move (eg s3, memory)
and on those whose objects don't belong to the wrapped Fs (eg archive),
so they now only run on local.
2026-09-22 14:58:12 +01:00
Nick Craig-Wood 1e92520076 iclouddrive: fix potential crash looking up items
findItem read the response status code when the lookup failed, so a
failure with no HTTP response panicked.

Thanks to @manus-pi for finding this problem.
2026-09-22 11:03:16 +01:00
Nick Craig-Wood 35abcadfc7 shade: fix potential crash in directory move
DirMove discarded the error from the destination check and read the
response status code, so a failure with no HTTP response panicked.
Other errors were reported as the destination existing; they are now
returned.

Thanks to @manus-pi for finding this problem.
2026-09-22 11:03:16 +01:00
Nick Craig-Wood e2cd9a5dfb imagekit: fix potential crash in rmdir and purge
Rmdir and Purge read the response status code before checking for an
error, so a failed DeleteFolder call with no HTTP response (a network
error, or purging the root which fails validation) panicked.

Thanks to @manus-pi for finding this problem.
2026-09-22 11:03:16 +01:00
Leon Brocard f21bb97383 s3: add Fastly EU Central 1 region
Fastly Object Storage now provides the eu-central-1 region. Add the
region and endpoint to the configuration choices so users do not need
to enter them manually.

https://community.fastly.com/t/new-fastly-object-storage-capabilities-and-a-new-storage-region/4493
2026-09-22 10:34:03 +01:00
Mattias Michaux 4e7a21bead onedrive: add configurable SharePoint tenant API version 2026-09-21 18:19:15 +01:00
phatlc 556940ea44 serve dlna: log unescaped paths - fixes #7370
The request log printed the escaped URL, so non-ASCII file names showed
up as long runs of %XX escapes. Log the unescaped URL path instead, as
the other serve commands do.
2026-09-21 18:11:07 +01:00
phatlc ebb1cc1221 vfs: fix AddVirtual ignoring isDir
VFS.AddVirtual always added a file entry to the directory cache, even
when called with isDir set, so a virtual directory showed up as a file
and nothing could be added inside it.

See #9310
2026-09-21 18:10:18 +01:00
phatlc b6beea4b27 local: stop --copy-links following symlink loops - fixes #4402
With -L/--copy-links a symlink pointing to one of its parent
directories was followed until the OS gave up with "too many levels
of symbolic links" 40 levels deep. As every looping symlink multiplies
the listing, a small tree with three such symlinks listed millions of
entries.

When a followed symlink points to a directory, compare it with the
directory being listed and each of its parents using os.SameFile and
if it matches report an error and skip it, the same way as a circular
symlink. A symlink to a sibling directory is still followed. Loops
excluded by the directory filters are skipped quietly as before.
2026-09-21 18:08:05 +01:00
phatlc 3c51b96774 smb: save the user name in the config even if it matches the current user - fixes #9356
The default for --smb-user was the name of the user running rclone
config, and rclone does not write defaults to the config file, so
entering your own user name left it out. A remote made that way then
logged in as whoever ran it later, e.g. root under systemd.

Make the default blank and look up the current user when the remote is
used, as the ftp backend does. Existing configs work as before.
2026-09-21 17:27:57 +01:00
phatlc dc98c216f2 operations: stop --copy-dest replacing files with --immutable
When the source matched a file in --copy-dest, copyDest server-side
copied it over an existing destination which differed, so sync, copy
and copyto with --copy-dest could modify a file --immutable should have
protected.

Leave such a destination for the caller, which rejects it with
ErrorImmutableModified as for any other modified file.
2026-09-21 17:26:51 +01:00
phatlc 575633cf6c operations: make --immutable work with copyto, moveto and single file copy - fixes #4921
--immutable was only enforced by sync, so copyto, moveto, copy and move
of a single file, and the operations/copyfile and operations/movefile rc
calls overwrote a destination which differed from the source.

Fail these with the same ErrorImmutableModified as sync, and reject
--no-check-dest with --immutable as sync does, since without checking
the destination it cannot be protected.
2026-09-21 17:26:51 +01:00
FTCHD 788e252d72 gui: clarify url param in docs 2026-09-21 14:09:21 +01:00
Nick Craig-Wood 7723091be9 rc: reject out of range integer parameters instead of truncating them
This was spotted by CodeQL after this change was merged:

976d05e1d rc: fix rc API accepting an out of range number and overflowing 64 bits
2026-09-21 12:26:31 +01:00
Nick Craig-Wood 1dc2516f08 docs: remove broken SecureBuild links 2026-09-21 12:26:31 +01:00
Nick Craig-Wood 29c9766a5e Add solunolab to contributors 2026-09-21 12:26:31 +01:00
solunolab c4ad609c1d refactor: use slices.Backward to simplify the code (#9501)
Signed-off-by: solunolab <solunolab@outlook.com>
2026-09-21 11:32:43 +01:00
Nick Craig-Wood 1c3e432c3f box, serve s3: fix log messages with bad format strings
The box backend logged an int64 with %q which printed
%!q(int64=123) instead of the sequence ID.

serve s3 passed the message from gofakes3 as the format string, so
any % in it was interpreted as a formatting directive and the message
was mangled.
2026-09-20 14:23:50 +01:00
Nick Craig-Wood 939f82d908 rc: make job/status and job/list require authentication
job/status returns the complete output of the job so it is as
sensitive as the call which started the job, e.g. config/dump started
with _async returns the config file including any secrets. It was
possible to read this without authentication where an authenticated
and an unauthenticated rc server share the same process, e.g. rclone
gui --rc.

An unauthenticated client can't start jobs on a server which needs
authentication, other than with the calls which don't need it, so
this shouldn't affect existing users.
2026-09-20 14:23:50 +01:00
Nick Craig-Wood 4cd6359ae9 log: fix race when adding a log output while logging
Handle read the list of extra outputs without holding the mutex, so
calling AddOutput while logging caused a data race.

This reads the extra outputs once under the mutex.
2026-09-20 14:23:50 +01:00
Nick Craig-Wood dd07bb33ba jobs: fix tests failing and racing when run with -count > 1
TestRcJobList listed the jobs left running in the global job list by
the previous run of the tests, so reset the global job list first.
2026-09-20 14:23:50 +01:00
Nick Craig-Wood 88bd49fab8 operations: don't sleep for a Retry-After error when the transfer is cancelled
The wait to obey a Retry-After error from the server used
time.Sleep() so it carried on sleeping when the context was
cancelled, e.g. by job/stop or --max-duration, and it also slept
after the last try when there was nothing left to retry.

Copying a file also logged the low level retry number counting from
0 rather than 1 as everything else does.
2026-09-20 14:23:50 +01:00
Nick Craig-Wood b82a024de0 operations: fix hang and lost context when moving a directory file by file
When the backend has no DirMove method, operations.DirMove moves the
objects one by one. If one of the moves failed the movers stopped
without receiving the rest of the objects, so DirMove blocked forever
once the channel filled up. This could be seen renaming a directory on
a mount of a backend without DirMove, such as s3.

The moves were also done with context.Background() instead of the
caller's context, so they didn't have the caller's config, couldn't
be cancelled and weren't counted in the caller's stats.
2026-09-20 14:23:50 +01:00
Nick Craig-Wood caa341878f operations: fix hang when deleting files and a fatal error occurs
When a fatal error such as --max-delete being reached stopped the
deletions, the deleters returned without receiving the rest of the
objects, so whatever was sending them blocked forever once the
channel filled up.

For example "rclone delete --max-delete 1" on a directory with more
files than --checkers hung instead of returning the error.

The deleters now keep receiving objects without deleting them after a
fatal error.
2026-09-20 14:23:50 +01:00
Nick Craig-Wood db5beead16 Add 4 new contributors
- Vasek Sraier
- Kalin Stoyanov
- NytePlus
- Jeremy Schoemaker
2026-09-20 11:14:24 +01:00
Jeremy Schoemaker b5f83bdbf2 rc: fix large numeric parameters being rejected on 32 bit builds
Params.GetInt64 parsed string parameters with strconv.ParseInt(x, 10, 0).
A bitSize of 0 means int, which is 32 bits on 386, arm, mips and mipsle,
so any value outside the int32 range was rejected as out of range even
though it fits in the int64 the method returns.

Parameters reach the rc API as strings on the paths that matter here: the
rc server puts every URL query and form value into Params as a string, and
rclone rc turns each key=value argument into a string. So on a 32 bit build
operations/getfile could not be given an offset, count, head or tail beyond
2 GiB, and debug/set-soft-memory-limit could not be given a limit beyond
2 GiB, while the same commands worked on a 64 bit build.

Parse with a bitSize of 64 to match the declared return type. This is the
string half of the range checking that was added to the float64 branch of
the same function in 976d05e1.
2026-09-20 10:11:03 +01:00
Wang Chencheng b93b73bcb0 operations: fix ignored error in rcat probe reads
Return the first non-EOF input error encountered while Rcat probes whether an
upload is small. Previously that error was ignored and the full probe buffer,
including bytes that were never read, could be passed to Put or PutStream.
2026-09-19 10:24:10 +01:00
NytePlus 1b3136702b fs: preserve explicitly supplied backend overview 2026-09-19 10:20:49 +01:00
Kalin Stoyanov 4928459f46 smb: Add workstation field to smb backend 2026-09-19 10:18:29 +01:00
Vasek Sraier d632f8bb51 serve restic: prevent concurrent append-only overwrites
- Reject uploads when object lookup fails for reasons other than "not found".
- Serialize uploads to the same object to prevent races between the
  existence check and the write.
2026-09-19 10:16:32 +01:00
Acts1631 c8d60a67fc compress: fix crash on ranged reads when gzip metadata is corrupted
Gzip metadata is read from the wrapped remote and could contain an
invalid block size or incomplete block index. A range read could then
panic in the seekable gzip reader.

Validate the gzip sidecar invariants before constructing a reader so
malformed remote metadata returns an error instead of crashing rclone.
2026-09-16 17:09:39 +01:00
Nick Craig-Wood a401763cf6 fstest: remove the TestS3MinioEdge test server
The minio/minio:edge image it ran has gone from Docker Hub and there
is no equivalent tag on quay.io, so this test remote can no longer be
started.
2026-09-16 09:17:11 +01:00
Nick Craig-Wood 4cf1da0d4f fstest: make test server start fail fast when docker run fails
The start function was run inside an if condition, where bash ignores
errexit, so a failed docker run was not noticed. The script then
printed its connection details anyway and the test spent 100 seconds
trying to connect before failing with a message that hid the real
error.

Run start in a subshell with errexit on and check its status
explicitly so the failure is reported immediately with docker's
error message.
2026-09-16 09:17:11 +01:00
Nick Craig-Wood e0d846f29e build: fix TestS3Minio by pulling minio from quay.io as it has gone from Docker Hub
The minio/minio repository has been removed from Docker Hub so the
TestS3Minio test server could not be started and every Linux CI run
failed. quay.io/minio/minio still serves the final release so use
that instead.
2026-09-16 09:17:11 +01:00
Nick Craig-Wood 9265e147b9 Add 6 new contributors
- ZRHann
- enkvadrat
- Vladimir Babin
- Eugene
- Kunpeng Xie
- foecmke
2026-09-16 09:17:11 +01:00
KBS 976d05e1dd rc: fix rc API accepting an out of range number and overflowing 64 bits
float64(math.MaxInt64) rounds up to 2^63, so x > math.MaxInt64 in
GetInt64 lets 2^63 through to int64(x), which is out of range.
2026-09-15 16:45:33 +01:00
foecmke b1a10fe17e docs: update --onedrive-hard-delete to mention personal account support 2026-09-15 16:42:32 +01:00
Kunpeng Xie 4f0148db0c accounting: stop averaging when the last check finishes
Release the averaging goroutine when checks outlast transfers, with a regression
test for the completion order.

Assisted-by: OpenAI Codex
2026-09-15 16:40:40 +01:00
tomaszni e85836d4c7 oracleobjectstorage: upload empty streams without multipart
OCI rejects a multipart completion request with no parts. Probe unknown-size
streams through a buffered reader and use a regular upload when the stream is
empty. Peek preserves a non-empty stream for the selected upload path.
2026-09-15 16:38:20 +01:00
Eugene 0cb6ddada9 cmount: ignore com.apple.* xattrs on the macOS FSKit backend 2026-09-15 12:10:22 +01:00
jzunigax2 77ec281072 internxt: fix lookups of files starting with a dot and dropped uploads
Internxt stores a file as a (plainName, type) pair and never derives the
split itself, so it is a convention shared between clients. This backend
split at the final dot, storing and looking up ".bashrc" as an empty name
of type "bashrc", where the web, desktop, Linux and macOS clients all keep
the leading dot in plainName. List rebuilt the full name so such files
appeared, but NewObject looked them up by the split and missed them.
2026-09-15 12:03:23 +01:00
jzunigax2 e441773d24 refactor: streamline file existence checks and metadata retrieval
- Replaced the preUploadCheck function with findFile for better clarity and efficiency in checking file existence.
- Introduced splitNameExt to encapsulate name and extension parsing logic.
- Updated NewObject and Update methods to utilize findFile for improved file metadata handling.
- Enhanced error handling and reduced redundant code in file checks.
2026-09-15 12:03:23 +01:00
tomaszni 934c21de26 oracleobjectstorage: purge objects in batches
Use OCI BatchDeleteObjects to remove up to 1,000 objects per request when
purging. Include directory markers so purging a bucket leaves it empty for
deletion.
2026-09-15 11:58:58 +01:00
tomaszni d81e8d7f54 oracleobjectstorage: encode carriage returns and line feeds
OCI Object Storage rejects NUL, carriage return and line feed in
object names. NUL is already encoded by rclone, while carriage returns
and line feeds need EncodeCrLf so rclone can represent those names
without issuing invalid OCI requests.

https://docs.oracle.com/en-us/iaas/Content/Object/Tasks/managingobjects.htm
2026-09-15 11:51:47 +01:00
n4n5 8fafc08dd1 docs: extend librclone instructions for gomobile 2026-09-14 14:45:31 +02:00
Vladimir Babin 3342e34f58 archive: fix crash when creating archive to stdout - fixes #9910
When rclone archive create is run without a destination the archive
should be written to stdout, but ArchiveCreate called
CheckValidDestination on the nil dst and panicked with a nil pointer
dereference. Skip the destination check when there is no destination.

Also remove a leftover debug Printf that wrote to stdout before the
archive data.

Signed-off-by: Vladimir Babin <vovababin@gmail.com>
2026-09-14 10:34:33 +02:00
maximilize 0e19ed565f docs: clarify --password-command quoting for a path with spaces 2026-09-14 07:27:06 +02:00
enkvadrat c2a5884ad9 docs: add padding to footer card
This is mostly visible in dark mode, as a side effect off adding the class,
the background of the card also changed to be dark-gray.
2026-09-14 07:25:31 +02:00