Skip to content

Releases: graemejross/nextcloud-sync-daemon

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 11 Aug 21:23
64eb6c8

Onboarding release — the sync engine is unchanged from v0.4.x. Both features came from community requests filed by @narcisgarcia.

New

  • --init-enable / --init-disable (#35): the daemon registers itself as a systemd service. Run as root it installs a system-scope unit; run as a normal user, a user-scope unit (with a loginctl enable-linger reminder). The generated unit embeds the binary and config paths and, in system scope, write access to your configured sync directory — no unit editing needed. It validates the config first, refuses to overwrite an existing unit, and --init-disable removes only what it wrote.
  • --get-app-password [--server URL] (#37): obtain a Nextcloud app password without a browser on this machine, via the same Login Flow v2 the desktop client uses. Open the printed URL on any device (your phone works), approve, and the CLI prints the app password to stdout — pipe it straight into your password file. Works with two-factor accounts.

Packages: .deb and .tar.gz for amd64 and arm64.

Full changelog: v0.4.1...v0.5.0

v0.4.1

Choose a tag to compare

@github-actions github-actions released this 11 Aug 21:08
d6128a5

Same daemon code as v0.4.0 — upgrade to either closes the password-in-process-list exposure fixed there.

Packaging

  • Releases now include .deb packages for amd64 and arm64 (#34). The package installs the binary to /usr/bin, an example config to /etc/nextcloud-sync-daemon/config.yaml.example, and a systemd unit (shipped disabled); it depends on nextcloud-desktop-cmd. First-run steps are in the README's Debian install section.
  • Corrects the example-config note that still described the pre-v0.4.0 password handling.

Full changelog: v0.4.0...v0.4.1

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 11 Aug 20:11
3868f90

Security

nextcloudcmd is no longer given the account password on its command line (#30). Previous releases invoked it with -u USER -p PASSWORD, which any local process could read from /proc/<pid>/cmdline for the duration of every sync. The daemon now writes the credentials to a 0600 .netrc inside a 0700 temporary directory, points the child's HOME there, and invokes nextcloudcmd -n. The temporary directory is removed when the sync returns.

Upgrade recommended for all users. Requires a nextcloudcmd that supports -n/.netrc (all current builds do). Note the daemon now sets HOME for the child process.

Reliability

  • Orphaned nextcloudcmd processes are killed when the daemon dies (Pdeathsig=SIGKILL), and a startup flock makes a duplicate daemon instance fail fast with the holder's PID (#27).

Docs

  • Example systemd unit cleaned up; journal entries for the #27 hardening and the #28 CRLF-filename investigation.

Full changelog: v0.3.2...v0.4.0

v0.3.2

Choose a tag to compare

@github-actions github-actions released this 17 Mar 15:07

Changelog

  • e2bd096 Fix errcheck lint warnings in notifypush tests (Refs #24)

v0.3.1

Choose a tag to compare

@github-actions github-actions released this 17 Mar 15:02

Changelog

  • b29feb9 Migrate websocket library from nhooyr.io to coder/websocket (Fixes #24)

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 17 Mar 15:01

Changelog

  • def50fc Add notify_push WebSocket event source for NAT-friendly server push (Fixes #24)
  • 8ad8e09 Update README and journal for notify_push support (Refs #24)

v0.2.1

Choose a tag to compare

@github-actions github-actions released this 17 Mar 11:45

Changelog

  • b863cb0 Reduce log noise: deduplicate sync complete, demote expected warnings (Fixes #21)
  • 750fc6c Skip FindConfigPath tests when system config exists (Fixes #20)

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 17 Mar 08:06

Changelog

  • 21b8bb1 Add health enhancements, peer notification, and sync test command
  • 6cf7193 Clarify that logs go to journal, not files
  • f411052 Fix 7 issues from team critical review before announcement
  • 64ccc66 Fix download URLs in README — link to releases page, not versioned filenames
  • 4492013 Replace ASCII architecture diagram with mermaid
  • 562c5ed Restructure README for end-user audience (Closes #14)
  • bb58d93 Update journal with Session 3: team review and migration
  • 92c0e58 Update journal with Session 4 and README status for v0.2.0

v0.1.1

Choose a tag to compare

@github-actions github-actions released this 16 Mar 17:29

Changelog

  • 2fb2597 Security hardening: rate limiting, password file perms, process visibility (Refs #10, #11, #12, #13)

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 16 Mar 14:51

Changelog

  • 233248f Add CI workflow and goreleaser config (Refs #9)
  • fc39820 Add Phase 5 plan and session wrap-up to journal (Refs #9)
  • 8945c49 Add design document for Go daemon implementation (Refs #2)
  • 32b015a Add development journal documenting build process (Refs #5)
  • da22949 Add health endpoint and wire into engine (Refs #9)
  • 11955f9 Add project scaffolding — go mod, Makefile, shared types (Refs #4)
  • 0187e8f Add systemd integration and example unit file (Refs #9)
  • 57fd3ff Fix errcheck lint failures — handle all return values (Refs #9)
  • 9e10927 Fix remaining errcheck failures in engine tests (Refs #9)
  • 587f8d1 Implement Phase 1: config, sync executor, one-shot CLI (Refs #5)
  • 2476563 Implement Phase 2: event loop engine with polling (Refs #6)
  • a11d674 Implement Phase 3: filesystem watcher with fsnotify (Refs #7)
  • 73565b4 Implement Phase 4: webhook listener for server push events (Refs #8)
  • 41c21b2 Initial README and prototype scripts (Fixes #1)
  • daaa311 Update README and journal for Phase 5 completion (Closes #9)
  • 4fcf534 Update journal and README for Phase 2 completion (Refs #6)
  • 9fe3411 Update journal and README for Phase 3 completion (Refs #7)
  • 18656cd Update journal and README for Phase 4 completion (Refs #8)
  • cdc3f50 Update status to Phase 1 complete (Refs #5)