Release: 2.3.0.105 (Canary) 2026-06-24

2.3.0.105_canary_2026-06-24

2026-06-24 - 2.3.0.105_canary_2026-06-24

This release is a canary release intended to be used for testing.

Store configuration with backup

This release revives the store-task-config option and makes it enabled by default for encrypted backups. The backup configuration is stored with the backup data, making it easier to restore a configuration later.

For unencrypted backups, no secrets are stored by default. The behavior can be customized with options to store none, self, or all configurations, with or without secrets. The UI has been updated to allow restoring from the destination config. If multiple configurations are found, the user can select one or more backup configurations to restore.

Support for MacOS ACLs

This release adds support for reading MacOS attributes and ACL strings during backup, and restoring them when permission restores are selected.

Support for Windows Alternate Data Streams

This release implements support for reading and writing alternate data streams (ADS) on Windows. This feature is disabled by default and can be enabled with the advanced option --enable-ads-backup. If ADS content is found in the source, this is restored by default but can be disabled with --disable-ads-restore.

Fixed MSSQL backups

Since 2.1 the MSSQL backups would produce errors if attempting to back up an MSSQL server that was running as the default instance, but would work with a named instance. This release fixes the issue and now handles both default- and named instances.

Improved missing source handling

The default behavior when sources are missing has changed. Previously, a missing source would abort the backup. Now, a missing source will only trigger a warning unless the option --abort-if-source-missing is set. The option --allow-missing-source can still be used to suppress warnings entirely. If no sources are found at all, the backup will still abort.

Relative database paths

Database paths are now stored relative to the data folder by default. This makes it simpler to move the data folder as the paths are not stored in full. Existing backups retain their full paths, but manually updating a database path will make it relative if it is within the data folder.

Updated LibSecret support for KDE

The LibSecret support has been updated to work correctly on KDE Plasma 5+6. The default collection alias is now properly resolved, fixing issues where a new collection named default would be created incorrectly.

License flexibility in MS365 and Google Workspace

The way license usage is calculated has been updated. Enumeration is now applied without imposing limitations, but actually reading the items is limited. This allows filtering unwanted items before they count towards usage.

Improved source tree

To make it easier to see what data is included, the source tree will now show the content of remote sources, including Microsoft 365 tenants, Google workspace subscriptions and full-disk content.

Easier filter configuration

Expanding the content will show item inclusion state. Clicking items will toggle them, similar to how regular file select works. This allows selective backup of remote data, such as picking which MS365 mailboxes to include.

For the full-disk selection is now possible to select an entire disk as the source, or select the individual partitions.

Server-side filters

Additionally, the filter evaluation will now be performed server-side if the filters are not “simple filters”. When a non-trivial filter is in the list, the C# code will be asked to evaluate the list and produces the filtered results which are then displayed. This increases the correctness of the displayed filter state because the same code is now used for both display and actual backup operations.

Resolve helper entries

The helper entries, like “My Documents” are now show in all picker situations and resolve to the full path. This makes it possible to use these shortcuts to pick things like log-file location or SSH keyfiles, without having to traverse the full tree to find the locations.

Browse remote destinations

The destination configuration has been updated to include a browse button for finding the remote destination path. Once the connection details are in place, the browse button can be used to navigate the remote file system and select the desired destination folder. This works both for configuring a backup and for picking the restore location.

Detailed list of changes

  • Updated LibSecret support to work correctly on KDE Plasma 6
  • Improved missing source handling, missing sources now warn instead of abort by default
  • Fixed MSSQL default instance handling
  • Fixed incorrect option types for lock mode, now showing as enums in the UI
  • Fixed retry of HTTP messages
  • Fixed ordering issue where filtered paths were accessed before filtering
  • Use relative database paths by default
  • Updated rclone in Docker images to use recent releases
  • Store configuration with backup with flexible options for encrypted and unencrypted backups
  • Added support for MacOS ACLs
  • Added searching in metadata for remote sources
  • Filter paths in reported log data to avoid leaking sensitive information
  • Prevent crash on metadata error during restore
  • Fixed case-insensitive search and exposed the flag in the API
  • Implemented support for ADS on Windows
  • Added auth timeout to Duplicati backend
  • Handle script modified filters correctly
  • Fix minor issues with remote sources
  • Improve license flexibility, allowing filtering before usage limits
  • Added unified interface for remote browsing
  • Always install WindowsService.exe in MSI
  • Add server-side filter evaluation
  • Block path traversal in recovery tool
  • Allow disabling default secret provider
  • Fixed case-change issue with USN on Windows

Updates to ngclient

New Features

  • Added support for restoring from remote config.
  • Added ability to browse for a destination path.
  • Added support for the new destination list API (auto-toggled if server supports it).
  • Added support for browsing MS365 and Google Workspace, so filters can be applied while content is visible.
  • Added support for server-side filters in treeview.
  • Showing shortcuts in pickers as we can now resolve them.
  • Added a debouncer to filter calls.
  • Added error indicator to tree view.

Improvements

  • Clean up target disk layout.
  • Apply extended search only if we are restoring from a destination that needs it.
  • Include server-only options, if any.
  • Better Google Workspace error messages.
  • Fixes to allow listing full disks on Windows.
  • Fixed issue with evaluating globbing.

Upgraded my machines, can confirm the Windows machines all got the service file so they seem to be fine.

The one issue I still have as reported with .104 is one Windows server I’m still unable to rebuild the database after using deleting+repair:

2026-06-24 21:21:55 +02 - [Error-Duplicati.Library.Main.Controller-FailedOperation]: The operation Repair has failed
UserInformationException: Some zero-length metadata entries could not be repaired.

One of my Windows 11 machines is not allowing external connections to the UI, locally it’s fine - I checked the firewall rules and they are still present, but I see the following logged in the event viewer:

Refusing to process TLS certs registry command: acl-mismatch (DACL is not protected from inheritance (SE_DACL_PROTECTED flag missing)); actual 'D:AI(A;CIID;KR;;;BU)(A;CIID;KA;;;BA)(A;CIID;KA;;;SY)(A;CIIOID;KA;;;CO)(A;CIID;KR;;;AC)(A;CIID;KR;;;S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681)'
Refusing to consume init password: acl-mismatch (DACL is not protected from inheritance (SE_DACL_PROTECTED flag missing)); actual 'D:AI(A;CIID;KR;;;BU)(A;CIID;KA;;;BA)(A;CIID;KA;;;SY)(A;CIIOID;KA;;;CO)(A;CIID;KR;;;AC)(A;CIID;KR;;;S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681)'
Refusing to consume reset password: acl-mismatch (DACL is not protected from inheritance (SE_DACL_PROTECTED flag missing)); actual 'D:AI(A;CIID;KR;;;BU)(A;CIID;KA;;;BA)(A;CIID;KA;;;SY)(A;CIIOID;KA;;;CO)(A;CIID;KR;;;AC)(A;CIID;KR;;;S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681)'

The service is started like this:

"C:\Program Files\Duplicati 2\Duplicati.WindowsService.exe" /localuser --webservice-password=[redacted] --webservice-sslcertificatefile=C:\ProgramData\Duplicati\nelson.pfx --webservice-sslcertificatepassword=[redacted] --disable-db-encryption --server-datafolder=C:\ProgramData\Duplicati

For the past couple of months, my backups on Windows haven’t been working due to the use of running files (VSS). After finding information here that the libraries had been changed and that version 104 Canary seemed to offer a solution—using Duplicati as a Windows service—I decided to install it.

To my surprise, it won’t install.

My theory is that I already have a Duplicati-server.sqlite file with my own security password, which makes it incompatible. On a machine without this file (or any trace of Duplicati), the installation worked, and the service was created without problems. The UI shows a clean start.

So, I think either I’m doing something very wrong, or the system doesn’t work on machines that already have data.

Just in case it helps.

These are all related to the new service install feature.
To support various service configuration options, the installer will write certain values into HKLM\SOFTWARE\DuplicatiTeam\Duplicati\Service.

But to avoid insecure setups, this key must be locked down with appropriate ACLs.
For this reason, the WindowsService is very picky about the correct permissions, and the messages you report are all from a failed check on the permissions.

There is no functionality of this failure, as any tool that needs to use it will reset the permissions. But having the keys in an insecure state could potentially let an attacker reset the password (other things needs to fall into place as well).

What is not clear to me is how the key got to be that way in the first place? The installer explicitly creates this key and locks it down. Can you give some best-effort description of what you have done, so I can try to replicate it and figure out if there is some scenario where the ACLs are not applied correctly? (I assume you did not create the key yourself).

Hi @ciltocruz, welcome to the forum.

Yes, that sounds like a correct theory. If the encryption key is not present, the service will crash and this would give an error like you describe.

To better understand your setup, can you give me some background?

  • What version was installed before?
  • Did you run it as a Service before (configured with Duplicati.WindowsService.exe)?
  • Did you apply a database encryption passphrase? With what method?

The installer is not super flexible in terms of configuration. It will just do a plain setup with no commandline arguments. So if you were previously relying on that (i.e., passing --settings-encryption-key) this will fail if you are using the new “Install service” feature.

There are three ways to fix this (maybe more :smiley: ):

  1. Don’t check the “Install service” during install
    This will allow you to manually handle the service configuration as with previous versions.

  2. Use preload.json to configure the instance.
    This will allow you to set the commandline options that would be wiped by the “Install service” option.

  3. Decrypt the database first, then install.
    This will make the database unencrypted, and then when the service starts, it will use a random generated key (stored in Windows Credential Manager) to encrypt the database.

To decrypt the database, start Duplicati once with --disable-db-encryption, then exit it. If you are managing the service via Duplicati.WindowsService.exe you need to do the uninstall/install roundtrip to include the additional argument.

Thanks for your reply, @kenkendk. Unfortunately, I can no longer test what you suggested.

I opted for the simpler, though perhaps more tedious, approach.

In my old Duplicati (stable version), I exported my backup configurations.

I uninstalled Duplicati Stable.

I installed a fresh Canary (105). The service was created without issue, and I imported my configurations and UI options. I adjusted the backup database paths and verified everything.

I had to change several things because it previously used %HOME%, and now, as it’s a service, %HOME% is different path.

But it’s up and running now, and it seems to be working. I no longer have VSS errors, and my backups work even when there are “files in use.”

The only thing that’s puzzling me is that everything works fine, but the path indicator is grayed out, as if it’s not connected.

image

Damn, I forgot to update this as I was spending more time trying to fix the other back that still won’t work Release: 2.3.0.105 (Canary) 2026-06-24 - #2 by Taomyn

I fixed the problem by changing the Windows firewall as it was not using the correct the .exe i.e. it was allowing Duplicati.Service.exe instead of Duplicati.WindowsService.exe

I have another Win 11 machine to check later so I’ll see if it has the same issue.