Skip to content

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 11 Aug 20:11
· 10 commits to main since this release
3868f90

Security

nextcloudcmd is no longer given the account password on its command line (#30). Previous releases invoked it with -u USER -p PASSWORD, which any local process could read from /proc/<pid>/cmdline for the duration of every sync. The daemon now writes the credentials to a 0600 .netrc inside a 0700 temporary directory, points the child's HOME there, and invokes nextcloudcmd -n. The temporary directory is removed when the sync returns.

Upgrade recommended for all users. Requires a nextcloudcmd that supports -n/.netrc (all current builds do). Note the daemon now sets HOME for the child process.

Reliability

  • Orphaned nextcloudcmd processes are killed when the daemon dies (Pdeathsig=SIGKILL), and a startup flock makes a duplicate daemon instance fail fast with the holder's PID (#27).

Docs

  • Example systemd unit cleaned up; journal entries for the #27 hardening and the #28 CRLF-filename investigation.

Full changelog: v0.3.2...v0.4.0