This release includes breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryCLI now accepts multiple sources like cp -r and adds Linux/macOS sparse-file support.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
CLI accepts multiple sources via command line (cp -r style). CLI accepts multiple sources via command line (cp -r style). Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Feature | Medium |
Sparse-file detection and copy with SEEK_DATA/SEEK_HOLE on Linux/macOS. Sparse-file detection and copy with SEEK_DATA/SEEK_HOLE on Linux/macOS. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Feature | Medium |
`--use-sudo` flag auto-elevates process under sudo. `--use-sudo` flag auto-elevates process under sudo. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Feature | Medium |
Tamper-resistant audit log written as immutable JSONL when running under sudo. Tamper-resistant audit log written as immutable JSONL when running under sudo. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
SSH rekey timeout no longer terminates long transfers during bulk copy. SSH rekey timeout no longer terminates long transfers during bulk copy. Source: llm_adapter@2026-05-21 Confidence: high |
— |
Full changelog
v3.1.0 — 2026-05-16
Big release built around bulk-backup workflows for VM-image / Longhorn-style
sources: multi-source command lines, sparse-file awareness, sudo
auto-elevation, and a tamper-resistant audit trail. Plus one
long-standing SSH reliability fix.
New Features
-
Multiple sources on the command line (cp -r style) — The CLI now
accepts one or more sources followed by a destination:fast-copy /var/lib/longhorn/replicas/pvc-* /mnt/backup_pvcThe shell can glob-expand into N source paths (files or directories);
each one is copied as its own subtree under the destination, preserving
its basename. Previously this errored with
unrecognized arguments: …because only one positional source was
allowed. Existing single-sourcefast-copy SRC DSTinvocations are
unaffected. -
Sparse-file support (Linux/macOS) — VM disk images, Longhorn
volume-head-*.imgreplicas, and other sparse files are now detected
automatically (st_blocks * 512 < st_size) and copied with
SEEK_DATA/SEEK_HOLEso unallocated holes never hit the wire or
the destination disk. The Phase 3 space check uses the allocated
byte count on sparse-capable destinations, so a 2.3 TB sparse tree
holding 12 GB of real data no longer rejects a 900 GB destination.
The scan output reports the sparse summary up front, e.g.:Sparse: 346 sparse files — 2.3 TB logical, 12.2 GB on disk Data to write: 12.2 GB (after sparse holes skipped 2.2 TB)Falls back to dense copy on Windows and on filesystems that don't
support holes (FAT32, exFAT); the resulting file is still
byte-identical to the source. -
--use-sudoself-elevation — Saves typingsudo python fast_copy.py …for the common case where the source or destination
needs root (Longhorn replicas, container volumes, system paths).
fast-copy re-execs itself undersudoand lets sudo prompt for the
password on the terminal as usual. Linux/macOS only. -
Tamper-resistant audit log under sudo — When running under sudo
(detected viaSUDO_USER), fast-copy writes a hidden
.fast_copy_audit.jsonlto the destination directory, one JSON
record per run. Each record captures the original (pre-elevation)
username, the full command, source/destination, the per-file copy
list, and run summary. After each write the file ischattr +i
(immutable) so even root cannot edit or delete it without first
runningchattr -i. The next sudo run clears the flag, appends its
record, and re-immutables. Degrades gracefully (writes the record
unprotected, with a warning) on filesystems without immutable
support — tmpfs, FAT32, NFS.
Reliability Fixes
- SSH rekey timeout no longer kills long transfers — Paramiko's
default periodic SSH re-key (after ~1 GB transferred) could time out
mid-transfer on slow or busy servers and tear down the session with
Key-exchange timed out waiting for key negotiation. We now raise
the rekey thresholds high enough that re-key effectively never fires
during a single bulk transfer, eliminating the failure mode reported
on multi-GB Longhorn → SFTP backups.
Upgrade notes
- No breaking changes. Existing single-source CLI invocations and
the existing--log-filebehavior are unchanged. - New flag:
--use-sudo. The audit log only writes when the
process is actually running under sudo, regardless of how root was
reached. - Audit file management: to inspect,
sudo cat <dst>/.fast_copy_audit.jsonl(reads work on immutable files). To
remove entirely,sudo chattr -i <path> && sudo rm <path>. - Sparse copy scope: the wire format for SSH transfers is still
dense — sparse-aware copy applies to local→local destinations only.
Remote backup of sparse files materializes the holes as zeros on the
remote, same as before.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Fast_copy new release with new features
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]