News
Duplicati 2.4.0.1 is out: a stability and security update
Duplicati 2.4.0.1 is out, a stability-focused patch for 2.4.0.0 with fixes for restores that hang or stop on a single failed file, aborts that wait on stuck reads, and the new sync mode. It also hardens the server login and remote control, and adds a reduced reporting mode for anyone who needs to keep file names and error text off the wire.
Duplicati 2.4.0.1 is now available. It is a patch release for 2.4.0.0 that fixes a number of issues reported since the 2.4.0.0 release, with no new features that change how you work.
The focus is stability. Restore and abort handling have received the most attention, followed by the new sync mode, and the server and remote control have been hardened. If you are running 2.4.0.0, we recommend upgrading.
One usability fix deserves a mention up front: on Windows, selecting files from search and restoring them could end in an empty restore, because search sent the wrong paths to the restore flow. That is fixed in this release.
Security and privacy
The server login is now hardened against weak passwords and has a login throttle. Remote control requests have been locked down and now require per-message keys, and the remote control connection works on NAS devices that use integrated authentication, such as Synology DSM.
Path redaction in logs and reports has been improved, and secrets stored in lists get an additional layer of protection.
For users who need to limit what leaves the machine, this release adds a reduced reporting mode. With --reduced-reporting, reports contain only log message ids, counters and dates, with no message text, error messages or file names. The setting can be enforced from the Duplicati Console for organizations that require it.
Restore and abort fixes
A restore now carries on with the next file when a single file fails, instead of stopping the whole restore. Several causes of restores hanging have been fixed: blocks are released for skipped files, all restore processes are released when a volume cannot be produced, and restore stages are released on every exit path. A missing destination folder is reported before the restore starts rather than partway through.
Aborting is also more reliable. Stopping a backup or other operation no longer waits for a stuck source file read, a stuck backend call, or a block processor that has stopped. Aborting a repair while it is reading the local database no longer discards the database.
Sync mode fixes
Sync mode was introduced in 2.4.0.0 and has received a round of fixes based on the first weeks of real-world use. Folder sync now works on destinations where it previously failed, zero-byte files upload correctly to Google Drive and Google Cloud, case-insensitive remotes are honoured, and duplicate remote listings are handled. Sync metadata and last-run handling have been corrected, and memory use is lower because remote operations are no longer kept in memory.
The standalone synchronization tool has also been fixed to pass the correct arguments to its backends, ignore folder entries in listings, rename through the backend, and count failed deletes and renames in its return code.
Stability, performance and storage providers
The wasted-space calculation used for compacting has been improved, deleting filesets uses less memory, and SQLite memory usage has been reduced further. Database connections are closed when opening or setting up a local database fails, and the server now takes the database lock in a few paths that previously skipped it. Resuming after sleep no longer waits for the suspend handling to finish, and Windows is allowed to sleep again once an operation ends. Tasks and HTTP status reports now surface errors from operations that finished without throwing.
Storage provider fixes in this release:
Google Drive: every copy of a duplicated name is kept, and shared drives report no quota instead of the user's own quota.
Google Workspace: inactive accounts are handled, a root folder is emitted, and the restore scope is fixed.
MS365: large emails restore correctly.
Drime: listings beyond the pagination limit are now complete.
S3: RelAix has been added to the list of providers.
SMB: improved error detection.
Duplicati Storage: error messages from the console are shown.
An unknown destination quota is no longer treated as a full destination, and a manually set quota is kept when the backend quota is disabled.
Windows installer, command line and UI
The Windows MSI now remembers the install location on upgrade, and the path browse button has been fixed. The Windows shell overlay works again. It depends on the folder status service, which is disabled by default and can be enabled from the command line with --webservice-enable-folder-status-service=true.
The command line tools have fixes to listing and searching: the latest version is listed when none is given, search covers sub-folders, file versions can be looked up by full path, and folders given without a trailing separator are handled. Purge and set-locks now stop when the given version or time matches no fileset.
The web UI has a few new features as well:
Purge files directly from the UI.
Check permissions for MS365 and Google Workspace, with a counter dialog for Google Workspace data.
Disable chunking on S3 providers that do not support it.
Reduced reporting can be configured from the UI.
Sync jobs are shown when restoring configurations from remote, and sync operations display more clearly.
The new-backup flow now asks for the source before the destination.
Fixes for folder filters and exclusions, schedule dates, WebDAV path normalization, destination test dialogs, and reconnecting WebSockets and long polls.
The old UI also has fixes for editing local folder and S3 destinations, restore version grouping and selecting a restore root. All translations have been updated; thank you to everyone who contributes translations.
Getting the update
Duplicati 2.4.0.1 is available now from the downloads page and through the built-in updater. The full list of changes is in the release notes.
As always, if you run into a problem, report it on the forum or on GitHub so it can be fixed in the next release.



