v2.0.1 - Security fix
database-backup v2.0.1 - Security fix
A patch release that hardens the root → uid 1000 privilege-drop boundary. No configuration or behavior changes - upgrading is a drop-in image update.
Security fix
On startup dbbackup runs briefly as root to install the database clients, then re-owns the /backups volume to uid 1000 before dropping privileges. That re-own step walked the volume with os.Chown, which follows symlinks. Because the volume is writable by the unprivileged backup user, a symlink planted there had its target re-owned to uid 1000 by root - an arbitrary-chown-as-root primitive that could be used to escalate back to root inside the container after a restart.
The fix switches the walk to os.Lchown, which re-owns the link itself and never dereferences its target. Regular files and directories - every real dump and job directory - are re-owned exactly as before, so migrated deployments keep working unchanged.
Impact: local privilege escalation confined to the backup container. Exploitation requires an attacker to already have code execution as the unprivileged uid-1000 user (for example through a compromised database server the tool connects to). This is a defense-in-depth fix for the privilege-drop boundary; there is no remote or unauthenticated exposure. v1 (bash-based) is not affected - this code only exists in the v2 Go rewrite.
Upgrading
Drop-in: pull the new image. The latest, 2, and 2.0 tags now point to v2.0.1.
docker compose pull && docker compose up -dFull changelog: v2.0.0...v2.0.1