This release includes 3 breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
Affected surfaces
ReleasePort's take
Moderate signalRestic v0.19.0 fixes several bug reports and deprecates the `--repack-small` flag in prune while adding support for restoring UNIX ownership by name.
Why it matters: Bugfixes improve reliability (exit codes, error handling) and a severity‑70 breaking change removes `--repack-small`; consider testing before upgrade.
Summary
AI summaryBroad release touches https://github.com/restic/restic/issues/5280, https://github.com/restic/restic/issues/21820, https://github.com/restic/restic/issues/2034, and https://github.com/restic/restic/issues/4447.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Breaking | High |
Deprecate `--repack-small` option in `prune`. Deprecate `--repack-small` option in `prune`. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Breaking | High |
Prevent `backup` from excluding paths explicitly passed to it. Prevent `backup` from excluding paths explicitly passed to it. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Dependency | Medium |
Require Go 1.25 or newer to build restic. Require Go 1.25 or newer to build restic. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Bugfix | Medium |
Exit with code 3 when some `backup` source paths do not exist. Exit with code 3 when some `backup` source paths do not exist. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Bugfix | Medium |
Return exit code 3 when `forget` fails to remove snapshots. Return exit code 3 when `forget` fails to remove snapshots. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Bugfix | Medium |
Error out when environment variables hold invalid values. Error out when environment variables hold invalid values. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Bugfix | Medium |
Exit with code 130 on SIGINT. Exit with code 130 on SIGINT. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Bugfix | Medium |
Reject impossible `find` time bounds immediately. Reject impossible `find` time bounds immediately. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Bugfix | Medium |
Make `find --pack` list blobs for tree packs. Make `find --pack` list blobs for tree packs. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Other | Medium |
Support restoring ownership by name on UNIX systems. Support restoring ownership by name on UNIX systems. Source: llm_adapter@2026-06-10 Confidence: low |
— |
Full changelog
Changelog for restic 0.19.0 (2026-06-09)
The following sections list the changes in restic 0.19.0 relevant to restic users. The changes are ordered by importance.
Summary
- Fix #2034: Support serving a
restic mountof a Windows system via Samba - Fix #4447: Use mode 0700 for repository directories created over SFTP
- Fix #4467: Exit with code 3 when some
backupsource paths do not exist - Fix #4759: Error out when environment variables hold invalid values
- Fix #5233: Return exit code 3 when failing to remove snapshots
- Fix #5258: Exit with code 130 on SIGINT
- Fix #5280: Reject impossible
findtime bounds immediately - Fix #5280: Make
find --packlist blobs for tree packs - Fix #5354: Allow
rcloneandsftpbackends when running in background - Fix #5427: Correctly restore ACL inheritance state on Windows
- Fix #5477: Password prompt was sometimes not shown for
backup -v - Fix #5487: Mark repository files read-only when using the SFTP backend
- Fix #5586: Correctly handle
snapshots --group-bywith--latest - Fix #5595: Avoid spurious
chmoderrors on certain file backends - Fix #5683: Prevent
backup --stdin-from-commandfrom hanging - Fix #5757: Respect
--userand--hostinkey passwd - Fix #21820: Correct handling of duplicate index entries
- Fix #21820: Correctly handle pack files missing from the index
- Chg #5293: Prune small packfiles more aggressively
- Chg #5767: Prevent excluding paths explicitly passed to
backup - Chg #21791: Update dependencies and require Go 1.25 or newer
- Enh #3326: Limit
checkto snapshots selected by filters - Enh #3572: Support restoring ownership by name on UNIX systems
- Enh #3738: Optional GitHub token for
self-updateAPI requests - Enh #4278: Support include filters in the
rewritecommand - Enh #4728: Support zstd compression levels
fastestandbetter - Enh #4868: Include repository ID in the filesystem name used by
mount - Enh #5175: Add status counters to
copyin verbose text output - Enh #5352: Support excluding cloud-backed files on macOS
- Enh #5383: Reduce progress bar refresh rates to decrease energy usage
- Enh #5424: Enable Windows filesystem privileges before file access
- Enh #5440: Make
--hostoverride environment variableRESTIC_HOST - Enh #5448: Support configuring
niceandionicein the Docker image - Enh #5453: Copy multiple snapshots in batches
- Enh #5523: Add Open Container Initiative labels to release Docker image
- Enh #5531: Reduce Azure storage costs by optimizing uploads
- Enh #5562: Rewrite only changed status lines each frame
- Enh #5588: Show timezone context in
snapshotsoutput - Enh #5610: Reduce
check,copy,diffandstatsmemory usage - Enh #5689: Show more detailed progress for
stats - Enh #5713: Significantly speed up index loading
- Enh #5718: Stricter and earlier validation of the
mountpoint
Details
-
Bugfix #2034: Support serving a
restic mountof a Windows system via SambaA repository mounted using
restic mounton a POSIX system could not use Samba to serve files from backups of Windows systems, while backups of non-Windows systems could be served successfully. This has now been fixed. -
Bugfix #4447: Use mode 0700 for repository directories created over SFTP
When creating a repository over SFTP, restic created the repository directories with the SFTP server's default permissions, often 0755, rather than the 0700 permissions it uses for local repositories.
Restic now creates these directories with 0700 permissions.
-
Bugfix #4467: Exit with code 3 when some
backupsource paths do not existRestic used to exit with code 0 when a top-level backup source path was missing, and exited with code 3 only when a child path under an existing source did not exist. Scripts that relied on the exit code could therefore treat an incomplete backup as success.
Restic now exits with code 3 when any backup source path does not exist.
-
Bugfix #4759: Error out when environment variables hold invalid values
If the environment variables
RESTIC_COMPRESSION,RESTIC_PACK_SIZE, orRESTIC_READ_CONCURRENCYcould not be parsed, restic used to ignore them. Restic now fails with an error unless the same setting is overridden on the command line. -
Bugfix #5233: Return exit code 3 when failing to remove snapshots
Previously, the
forgetcommand returned exit code 0 when it failed to remove one or more snapshots. This was misleading to scripts.The
forgetcommand now instead returns exit code 3 when failing to remove one or more snapshots. -
Bugfix #5258: Exit with code 130 on SIGINT
Restic used to return exit code 1 on SIGINT. It now returns 130, the usual convention for a process stopped by Ctrl-C.
-
Bugfix #5280: Reject impossible
findtime bounds immediatelyThe
findcommand now fails with an error when both--oldestand--newestare set and--oldestis later than--newest. -
Bugfix #5280: Make
find --packlist blobs for tree packsThe
find --pack <tree-pack>command now also reports blobs for packs that only contain tree blobs. -
Bugfix #5354: Allow
rcloneandsftpbackends when running in backgroundPreviously, starting restic in the background could result in unexpected behavior when using the
rcloneorsftpbackends. For example,restic -r rclone:./example --insecure-no-password init &could cause the callingbashshell to exit unexpectedly.This has now been fixed.
-
Bugfix #5427: Correctly restore ACL inheritance state on Windows
Since security descriptor backups were added in restic 0.17.0, Access Control Entry inheritance was not restored correctly on Windows; restored permissions were always marked as explicit (not inherited) even when they were inherited from a parent folder.
The inheritance flags are now correctly applied when restoring the security descriptor, preserving the original permission structure.
-
Bugfix #5477: Password prompt was sometimes not shown for
backup -vThe repository password prompt could be hidden when running the
backup -vcommand. This has now been fixed. -
Bugfix #5487: Mark repository files read-only when using the SFTP backend
Files created through the SFTP backend previously stayed writable. New files now get read-only permissions where the server supports
chmod. -
Bugfix #5586: Correctly handle
snapshots --group-bywith--latestFor the
snapshotscommand,--latestdid not interact correctly with a non-default--group-byvalue. This combination now behaves as intended. -
Bugfix #5595: Avoid spurious
chmoderrors on certain file backendsOn filesystems that do not support
chmod(for example CIFS or FUSE-mounted WebDAV), restic since version 0.18.0 failed to remove stale locks, throwing the errorchmod ...: operation not supported. This has now been fixed. -
Bugfix #5683: Prevent
backup --stdin-from-commandfrom hangingWhen using
--stdin-from-command, thebackupcommand could hang until manually cancelled if the backup stopped before all subprocess output was consumed, for example after a failed upload to the repository. This has now been fixed. -
Bugfix #5757: Respect
--userand--hostinkey passwdThe
key passwdcommand previously ignored the--userand--hostoptions and always stored the new key with the current user and host name. These options are now honored. -
Bugfix #21820: Correct handling of duplicate index entries
Before restic 0.10.0, a bug could, in very rare cases, split information about a pack file across multiple index files.
Since restic 0.17.0, any operation that rewrites the index (like
pruneorrepair packs) could lose part of that information, resulting in errors in latercheckorpruneruns. This can be fixed by runningrepair packs, and only repositories using repository format version 1 might be affected.Split pack index entries are no longer lost during index rewrites. The
checkcommand now reports these cases as errors that can be fixed using therepair packscommand. On older restic versions, runningrepair indextwice also fixes the problem. -
Bugfix #21820: Correctly handle pack files missing from the index
The
repair packscommand was unable to salvage blobs from a pack file if the pack file was not contained in the index or the index entry was incomplete.The command now uses information from both the index and the pack file header.
-
Change #5293: Prune small packfiles more aggressively
The
prunecommand now repacks more small packfiles by default. The option--repack-smallis no longer needed and has been marked as deprecated. The--repack-smaller-thanoption can still be used to further control repacking of small pack files. -
Change #5767: Prevent excluding paths explicitly passed to
backupWhen e.g.
restic backup --exclude-if-present .git /home/user/datawas run and/home/user/.gitexisted, restic excluded thedatadirectory from the snapshot. The same applied to--exclude-cachesor--one-file-system.Similarly,
restic backup --exclude-larger-than 1M large-file.binproduced an empty snapshot when the file was larger than one megabyte.The
backupcommand now tracks which files and directories were specified on the command line and does not apply excludes to those paths. Content inside a backed-up directory is still filtered by excludes as before. -
Change #21791: Update dependencies and require Go 1.25 or newer
Dependencies have been updated. Building restic now requires Go 1.25 or newer. The Windows build with Go 1.26 was also fixed.
-
Enhancement #3326: Limit
checkto snapshots selected by filtersThe
checkcommand can now restrict pack verification to snapshots chosen with the usual snapshot filters (--tag,--host,--path, or explicit snapshot IDs on the command line). -
Enhancement #3572: Support restoring ownership by name on UNIX systems
The
restorecommand used to restore file ownership on UNIX systems by UID and GID. It now supports restoring ownership by user and group name with--ownership-by-name, so that snapshots can be restored on systems where numeric IDs do not match those on the backup host.Note: POSIX ACLs are still restored by numeric value; this change does not add ACL-by-name support.
-
Enhancement #3738: Optional GitHub token for
self-updateAPI requestsThe
self-updatecommand used only unauthenticated GitHub API requests when checking for releases. Shared IP addresses could hit the GitHub rate limit, resulting in a 403 Forbidden error and preventing updates.Unauthenticated requests remain the default, but authenticated requests are now possible. Set the environment variable
GITHUB_ACCESS_TOKENto a GitHub personal access token to avoid rate-limit failures. -
Enhancement #4278: Support include filters in the
rewritecommandThe
rewritecommand now accepts the same include filter options as therestorecommand (--include,--include-file,--iinclude,--iinclude-file, and short-i). Include and exclude filter options are mutually exclusive. -
Enhancement #4728: Support zstd compression levels
fastestandbetterRestic now supports the zstd compression modes
fastestandbetter. Set the environment variableRESTIC_COMPRESSIONtofastestorbetter, or pass the same values with the--compressionoption. -
Enhancement #4868: Include repository ID in the filesystem name used by
mountThe filesystem exposed by the
mountcommand now includes the repository ID in its name. The ID is printed when opening a repository or can be read withrestic cat config.$ df ./test-mount/ Filesystem 1K-blocks Used Available Use% Mounted on restic:d3b07384d1 0 0 0 - /mnt/my-restic-repo -
Enhancement #5175: Add status counters to
copyin verbose text outputThe
copycommand now prints additional counters in text mode when--verboseis set: blobs to copy, their on-disk size, and the number of pack files read from the source repository. -
Enhancement #5352: Support excluding cloud-backed files on macOS
Previously, restic treated cloud-backed files (such as files stored on iCloud) like normal local files, forcing a full download of placeholders and other "meant to be cloud only" content during backups.
The
backupcommand now supports--exclude-cloud-files(previously only available on Windows) to skip those files on supported macOS versions. From Sonoma (macOS 14.0) onward the option can prevent unwanted downloads. Older macOS versions will still download the files during a backup run. -
Enhancement #5383: Reduce progress bar refresh rates to decrease energy usage
Progress bars were previously updated at 60 frames per second, which could cause high CPU or GPU usage in some terminal emulators.
The refresh rate is now 10 FPS to conserve energy. For some terminal emulators, the lower rate is also necessary to allow selecting text in the terminal.
-
Enhancement #5424: Enable Windows filesystem privileges before file access
Restic used to enable some Windows filesystem privileges only while reading or writing security descriptors. Extended attributes could therefore be read before enabling the backup privilege, possibly resulting in missed data or errors.
Restic now enables the relevant filesystem privileges before any file access.
-
Enhancement #5440: Make
--hostoverride environment variableRESTIC_HOSTPreviously, when the environment variable
RESTIC_HOSTwas set, snapshot listings and other operations were always filtered to that host.Passing
--hostas an empty string (--host=""or--host=) now overridesRESTIC_HOSTand shows snapshots from all hosts.The same override applies to other commands that support snapshot filters, including
snapshots,forget,find,stats,copy,tag,repair snapshots,rewrite,mount,restore,dump, andls. -
Enhancement #5448: Support configuring
niceandionicein the Docker imageThe container entrypoint now reads optional scheduling hints from the environment:
-
The environment variable
NICEsets the process nice value (seeman nice). -
The environment variable
IONICE_CLASSselects the I/O scheduling class (seeman ionice). Real-time classes need theSYS_NICEcapability added to the container. -
The environment variable
IONICE_PRIORITYsets the priority withinIONICE_CLASSand has no effect unlessIONICE_CLASSis set; it defaults to4(neutral priority).
For further details, please see: https://restic.readthedocs.io/en/stable/020_installation.html#docker-container
-
-
Enhancement #5453: Copy multiple snapshots in batches
The
copycommand used to copy snapshots one at a time, even when doing so produced pack files smaller than the target pack size. This led to many small files when copying small incremental snapshots.The
copycommand now copies multiple snapshots together so that small pack files are avoided where possible. -
Enhancement #5523: Add Open Container Initiative labels to release Docker image
The release Docker image now includes OCI-style image annotation labels, which helps external tooling identify the image.
-
Enhancement #5531: Reduce Azure storage costs by optimizing uploads
Restic previously used Azure PutBlock and PutBlockList for every upload, which cost two storage transactions per file and roughly doubled transaction charges for repositories with many pack files.
Files up to 256 MiB now use PutBlob, requiring only a single transaction per file and cutting typical transaction costs by about half. Larger blobs still use block uploads as required by Azure.
-
Enhancement #5562: Rewrite only changed status lines each frame
The status bar rewrote every line on each frame whenever any content changed, which made selecting text impossible in some terminal emulators even when most lines were unchanged.
Now only lines that actually change are rewritten on each update.
-
Enhancement #5588: Show timezone context in
snapshotsoutputThe
snapshotscommand now prints which timezone is used for displayed timestamps. Snapshots may have been created in different timezones but are shown in the local timezone, so a footer line (for example, timestamps shown in CET) clarifies the display context when comparing snapshots from several sources. -
Enhancement #5610: Reduce
check,copy,diffandstatsmemory usageThe
check,copy,diffandstatscommands now use less memory when handling large snapshots. -
Enhancement #5689: Show more detailed progress for
statsThe
statscommand used to show progress only while loading the index. During the scan it printed onlyscanning...with no further updates. It now reports how many snapshots, files, and blobs have been processed so far. -
Enhancement #5713: Significantly speed up index loading
Loading the index for a large repository is now significantly faster. Also, the
mountcommand now loads the index once at startup and then only loads new index files as they appear. It also loads snapshots before printing that the repository is being served. -
Enhancement #5718: Stricter and earlier validation of the
mountpointThe
mountcommand previously accepted invalid mount points, resulting in an error after loading the repository. The specified mount point must now refer to a directory that the current user can access and write to, and this check is performed before opening the repository.
Breaking Changes
- Change #5293: the `--repack-small` option is deprecated because pruning now repacks small packfiles by default.
- Change #5767: `backup` no longer applies excludes to paths explicitly passed on the command line, altering previous exclude‑behavior.
- Change #21791: building restic now requires Go 1.25 or newer.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]