Releases: graemejross/nextcloud-sync-daemon
Release list
v0.5.0
Onboarding release — the sync engine is unchanged from v0.4.x. Both features came from community requests filed by @narcisgarcia.
New
--init-enable/--init-disable(#35): the daemon registers itself as a systemd service. Run as root it installs a system-scope unit; run as a normal user, a user-scope unit (with aloginctl enable-lingerreminder). The generated unit embeds the binary and config paths and, in system scope, write access to your configured sync directory — no unit editing needed. It validates the config first, refuses to overwrite an existing unit, and--init-disableremoves only what it wrote.--get-app-password [--server URL](#37): obtain a Nextcloud app password without a browser on this machine, via the same Login Flow v2 the desktop client uses. Open the printed URL on any device (your phone works), approve, and the CLI prints the app password to stdout — pipe it straight into your password file. Works with two-factor accounts.
Packages: .deb and .tar.gz for amd64 and arm64.
Full changelog: v0.4.1...v0.5.0
v0.4.1
Same daemon code as v0.4.0 — upgrade to either closes the password-in-process-list exposure fixed there.
Packaging
- Releases now include
.debpackages for amd64 and arm64 (#34). The package installs the binary to/usr/bin, an example config to/etc/nextcloud-sync-daemon/config.yaml.example, and a systemd unit (shipped disabled); it depends onnextcloud-desktop-cmd. First-run steps are in the README's Debian install section. - Corrects the example-config note that still described the pre-v0.4.0 password handling.
Full changelog: v0.4.0...v0.4.1
v0.4.0
Security
nextcloudcmd is no longer given the account password on its command line (#30). Previous releases invoked it with -u USER -p PASSWORD, which any local process could read from /proc/<pid>/cmdline for the duration of every sync. The daemon now writes the credentials to a 0600 .netrc inside a 0700 temporary directory, points the child's HOME there, and invokes nextcloudcmd -n. The temporary directory is removed when the sync returns.
Upgrade recommended for all users. Requires a nextcloudcmd that supports -n/.netrc (all current builds do). Note the daemon now sets HOME for the child process.
Reliability
- Orphaned
nextcloudcmdprocesses are killed when the daemon dies (Pdeathsig=SIGKILL), and a startup flock makes a duplicate daemon instance fail fast with the holder's PID (#27).
Docs
- Example systemd unit cleaned up; journal entries for the #27 hardening and the #28 CRLF-filename investigation.
Full changelog: v0.3.2...v0.4.0
v0.3.2
v0.3.1
v0.3.0
v0.2.1
v0.2.0
Changelog
- 21b8bb1 Add health enhancements, peer notification, and sync test command
- 6cf7193 Clarify that logs go to journal, not files
- f411052 Fix 7 issues from team critical review before announcement
- 64ccc66 Fix download URLs in README — link to releases page, not versioned filenames
- 4492013 Replace ASCII architecture diagram with mermaid
- 562c5ed Restructure README for end-user audience (Closes #14)
- bb58d93 Update journal with Session 3: team review and migration
- 92c0e58 Update journal with Session 4 and README status for v0.2.0
v0.1.1
v0.1.0
Changelog
- 233248f Add CI workflow and goreleaser config (Refs #9)
- fc39820 Add Phase 5 plan and session wrap-up to journal (Refs #9)
- 8945c49 Add design document for Go daemon implementation (Refs #2)
- 32b015a Add development journal documenting build process (Refs #5)
- da22949 Add health endpoint and wire into engine (Refs #9)
- 11955f9 Add project scaffolding — go mod, Makefile, shared types (Refs #4)
- 0187e8f Add systemd integration and example unit file (Refs #9)
- 57fd3ff Fix errcheck lint failures — handle all return values (Refs #9)
- 9e10927 Fix remaining errcheck failures in engine tests (Refs #9)
- 587f8d1 Implement Phase 1: config, sync executor, one-shot CLI (Refs #5)
- 2476563 Implement Phase 2: event loop engine with polling (Refs #6)
- a11d674 Implement Phase 3: filesystem watcher with fsnotify (Refs #7)
- 73565b4 Implement Phase 4: webhook listener for server push events (Refs #8)
- 41c21b2 Initial README and prototype scripts (Fixes #1)
- daaa311 Update README and journal for Phase 5 completion (Closes #9)
- 4fcf534 Update journal and README for Phase 2 completion (Refs #6)
- 9fe3411 Update journal and README for Phase 3 completion (Refs #7)
- 18656cd Update journal and README for Phase 4 completion (Refs #8)
- cdc3f50 Update status to Phase 1 complete (Refs #5)