rclone/rclone
54.7
Weak · 24 September 2026
218.1k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is rclone, a command-line utility for synchronizing and transferring data between a vast array of cloud storage providers and local filesystems. It provides a unified interface for managing files across diverse backends, including object storage, enterprise shares, and decentralized networks, while offering advanced features like encryption, compression, and union mounting. The tool supports both interactive CLI usage and programmatic control via a remote API, enabling complex workflows such as two-way synchronization, archival management, and media serving.
How it got here
2012–2018 — CLI expansion and backend modernization
129 changes.
This period focused on significantly expanding the rclone command-line interface with numerous new commands for file management, checksumming, and remote control, while refactoring the core architecture to support modular configuration and improved testing. Concurrently, the project modernized its backend ecosystem by rewriting critical storage drivers like S3 and SFTP, adding support for new providers such as Backblaze B2 and Jottacloud, and introducing advanced features like FUSE mounting and parallel uploads.
2019–2021 — serve infrastructure and new backends
77 changes.
This period focused on expanding rclone's serving capabilities with new DLNA, SFTP, and Docker plugin commands, alongside a programmable authentication proxy. It also introduced a wide array of new cloud storage backends, including Google Photos, Mail.ru, and Seafile, while establishing foundational library packages for memory management, caching, and plugin support.
2022–2026 — backend expansion and archive tooling
55 changes.
This period focused on significantly expanding the project's storage capabilities by integrating numerous new backends, including Storj, Akamai, Oracle, SMB, and various cloud providers. It also introduced comprehensive archive management features, allowing users to create, list, and extract remote archives with robust security hardening against path traversal attacks. Additionally, the work included infrastructure improvements such as generic multipart upload libraries, NFS serving commands, and a new embedded web GUI.
Features
Add 'about' command to display remote quota information
A new 'about' command has been added to retrieve and display quota usage details (such as total, used, free, and trashed space) from supported remotes. The command supports a '--json' flag for machine-readable output and a '--full' flag to display raw byte counts instead of human-readable sizes. This feature is available starting from version v1.41 and relies on the backend's About feature implementation.
cmd/about · high confidence
Add --rmdirs flag to delete command
The delete command now supports the --rmdirs flag, which allows users to remove empty directories left behind after deleting files. By default, delete only removes files and preserves the directory structure; with this flag, it will also clean up any resulting empty directories.
cmd/delete · high confidence
Add 1Fichier backend support
Introduces a new backend for the 1Fichier cloud storage service, enabling users to mount and manage files stored on 1Fichier. This implementation supports core operations including file uploads, downloads, directory listing, and file moves/copies. It also handles specific 1Fichier features such as password-protected shared folders and files, optional CDN-based downloads, and custom rate-limiting (pacing) to manage the service's strict API limits. Error handling includes specific retries for flood detection and IP lock errors.
backend/fichier · high confidence
Add Akamai NetStorage backend
Users can now connect to Akamai NetStorage as a new remote type. The backend supports HTTP and HTTPS protocols, authenticates via account name and secret key, and provides standard file operations including upload, download, and listing. It also includes custom backend commands for checking disk usage (du) and creating symbolic links (symlink).
backend/netstorage · high confidence
Add Citrix Sharefile API type definitions
Introduces the Go struct definitions for the Citrix Sharefile API in the new \backend/sharefile/api/types.go\ file. This includes models for listing items, handling uploads (including resumable and threaded uploads), and managing item metadata, enabling the backend to interact with the Sharefile service.
backend/sharefile/api · high confidence
Add Citrix Sharefile backend
Users can now mount and transfer files to Citrix Sharefile object storage. The new backend supports OAuth 2.0 authentication, chunked uploads for large files, and configurable root folder access (Personal, Favorites, Shared, etc.). It includes timezone data handling and respects standard rclone features like pacer-based rate limiting and upload cutoff thresholds.
backend/sharefile · high confidence
Add DOI filesystem backend for Zenodo, Dataverse, and Invenio
Introduces a new read-only 'doi' backend that allows users to mount and browse datasets identified by Digital Object Identifiers (DOIs). The backend automatically resolves DOIs via the standard doi.org API and supports three provider types: Zenodo, Dataverse, and InvenioRDM. Users can configure a specific DOI and optionally force a provider (or use auto-detection) to access file listings, metadata (size, modification time, MD5, content type), and file contents from these research data repositories.
backend/doi · high confidence
Add Drime API type definitions
Added the \types.go\ file in the \backend/drime/api\ package, which defines the Go structs for the Drime backend API. These types cover core entities such as \User\, \Item\, and \Permissions\, as well as request and response structures for operations like file uploads (\MultiPartCreateRequest\), folder creation, and item updates. This provides the necessary data models for interacting with the Drime service.
backend/drime/api, backend/yandex/api · high confidence
Add Drime object storage backend
Users can now connect to the Drime object storage system using the new 'drime' backend. This implementation supports standard operations such as listing, uploading, downloading, and deleting files, with configuration options for API access tokens, workspace IDs, and chunked upload settings. The backend includes integration tests to verify functionality.
backend/drime · high confidence
Add Dropbox content-hash implementation
Introduces a new \dbhash\ package that implements the Dropbox content-hash algorithm (a block-based SHA-256 variant) as described in the Dropbox API reference. This allows the Dropbox backend to compute the specific checksums required for content identification and synchronization. The change includes the core implementation and a comprehensive test suite verifying correctness across various data sizes and chunking strategies.
backend/dropbox/dbhash · high confidence
Add Enterprise File Fabric backend
Users can now mount and sync files with Storage Made Easy's Enterprise File Fabric storage system. This new backend supports configuration via URL, permanent authentication tokens, and session tokens, and includes features like directory caching and exponential backoff for API calls.
backend/filefabric · high confidence
Add FileLu cloud storage backend
Rclone now supports FileLu as a new remote storage backend. This addition enables users to mount and manage FileLu cloud storage, supporting standard operations such as listing directories, creating folders, and deleting files. The backend handles file uploads with automatic chunking for large files (configurable via upload\_cutoff and chunk\_size options) and supports range downloads for efficient retrieval. It also provides usage statistics (About) and integrates with Rclone's standard encoding and retry mechanisms.
(repo-wide) · high confidence
Add Files.com backend support
Users can now connect to Files.com object storage via a new 'filescom' backend. This addition introduces support for authenticating via site subdomain, username/password, or API key, and registers the remote within the rclone filesystem interface. The implementation leverages the official Files.com Go SDK to handle file and folder operations, including MD5 and CRC32 hash support, and includes integration tests to verify functionality.
backend/filescom · high confidence
Add Google Photos API type definitions
The backend now includes the Go type definitions required to interact with the Google Photos API. This change introduces structs for managing albums, media items (photos and videos), and search filters, enabling the application to list albums, retrieve media details, and perform filtered searches within Google Photos.
backend/googlephotos/api · high confidence
Add HDFS (Hadoop Distributed File System) backend
Users can now access Hadoop Distributed File System storage via a new 'hdfs' remote. This implementation supports connecting to a list of NameNodes, authenticating via username or Kerberos (with configurable data transfer protection), and performing standard file operations such as uploading, downloading, listing, and deleting files. The backend includes retry logic for replication-in-progress errors during uploads and handles modification times with second-precision truncation.
backend/hdfs · high confidence
Add HTTP CONNECT and SOCKS5 proxy support with memory safety fixes
Users can now connect via HTTP CONNECT proxies (including those requiring authentication) and SOCKS5 proxies. The HTTP CONNECT implementation includes a fix for a potential out-of-memory vulnerability by limiting the size of the proxy response headers read, ensuring that malicious proxies cannot cause unbounded memory usage.
lib/proxy · high confidence
Add HiDrive hierarchical hashing implementation
The backend now includes a dedicated package for the HiDrive hashing algorithm, which combines SHA-1 hashes hierarchically to produce a single top-level hash. This implementation follows the HiDrive synchronization specification (v3.3), handling block-wise processing, position-embedded checksums, and binary serialization for state persistence. Tests verify the correctness of the hierarchical aggregation against documented examples.
backend/hidrive/hidrivehash · high confidence
Add Huawei Drive API type definitions
Added the \backend/huaweidrive/api/types.go\ file, which defines the Go structs and constants required to interact with the Huawei Drive API. This includes data models for user information, file metadata, permissions, and folder structures, as well as request/response types for operations like creating folders, updating files, and handling uploads. These types enable the backend to serialize and deserialize Huawei Drive API responses and requests.
backend/huaweidrive/api · high confidence
Add Huawei Drive backend support
This change introduces a new Huawei Drive backend for rclone, enabling users to mount and manage files stored on Huawei Drive. The implementation supports OAuth2 authentication, chunked and resumable uploads (with configurable chunk sizes and cutoffs), file listing, metadata handling (including SHA256 hashes and timestamps), and filename encoding to comply with Huawei Drive's strict character restrictions. Integration tests are included to verify upload and listing functionality.
backend/huaweidrive · high confidence
Add ImageKit backend client library
Introduce a new client library for the ImageKit API in the backend/imagekit/client package. This addition provides the foundational HTTP client, authentication handling (using private/public keys), and methods for managing media assets, including uploading files, listing and searching files and folders, creating/deleting/moving folders, and generating signed URLs for secure access.
backend/imagekit/client · high confidence
Add ImageKit.io backend
Users can now mount and manage files on ImageKit.io as a remote storage backend. This new integration supports configuration via endpoint, public/private keys, and options for signed URLs and file versioning. It exposes system metadata such as modification time, creation time, dimensions, and AI-generated tags, and includes built-in rate-limiting and retry logic for reliable API interactions.
backend/imagekit · high confidence
Add Internet Archive backend
Users can now store and retrieve files using the Internet Archive service via a new 'internetarchive' remote type. This backend connects to the Internet Archive S3-compatible API (IAS3) and supports configuration of access keys, custom endpoints, and item-level metadata. It includes options to control the derive process for uploaded files, disable checksum verification to speed up large uploads, and wait for archive processing tasks to complete.
backend/internetarchive · high confidence
Add Jottacloud backend
Introduces a new Jottacloud backend, enabling users to mount and manage Jottacloud storage (including whitelabel variants like Elgiganten, MediaMarkt, and Telia) via rclone. The implementation supports standard and traditional OAuth authentication, device and mountpoint selection, metadata handling (birth time, modification time), file versioning controls, trash management, and resumable uploads.
(repo-wide) · high confidence
Add Mail.ru Cloud backend
Users can now connect to Mail.ru Cloud storage using the new 'mailru' backend. This implementation supports OAuth authentication (requiring an app password), file hashing via a custom Mailru-specific hash type, and a 'speedup' feature that allows uploading files by hash to leverage server-side deduplication for common content. The backend includes configuration options for managing upload speedup thresholds, file patterns, and error handling behaviors.
backend/mailru · high confidence
Add Mail.ru backend implementation
Introduces a new backend for Mail.ru cloud storage, including the API package with binary protocol helpers (BinReader/BinWriter), protocol constants, and JSON response structures for authentication, file operations, and directory listings.
backend/mailru/api · high confidence
Add Mail.ru hash (mrhash) implementation
The backend now includes a new \mrhash\ package that implements the Mail.ru checksum algorithm, which is a modified SHA1 variant. For files 20 bytes or smaller, the hash is the data padded with zero bytes; for larger files, it is a SHA1 sum of the data concatenated with its length. This addition is accompanied by comprehensive tests covering various data sizes and chunking scenarios to ensure correctness.
backend/mailru/mrhash · high confidence
Add Mega.nz remote backend
Introduces a new Mega.nz remote backend, allowing users to mount and manage files stored on Mega. The implementation supports two-factor authentication (2FA) via a dedicated configuration option, allows forcing HTTPS connections to avoid ISP throttling, and provides a 'hard\_delete' flag to permanently remove files instead of moving them to trash. It also includes internal tests to verify that deleted files disappear immediately from listings rather than lingering as 'ghost' entries.
backend/mega · high confidence
Add Microsoft Azure Files backend
A new backend for Microsoft Azure Files has been added, allowing users to mount and manage Azure File Shares. The implementation supports authentication via connection strings, account keys, SAS URLs, and OAuth (client assertion), and includes configuration options for share name, chunk size, upload concurrency, and file encoding.
backend/azurefiles · high confidence
Add Proton Drive backend
Users can now mount and manage files on Proton Drive using the new 'protondrive' backend. This implementation supports two-password authentication (login and mailbox passwords), two-factor authentication via OTP codes or secret keys, and includes configuration options for caching, draft handling, and app versioning. The backend integrates with rclone's standard transport and error handling, allowing for seamless file transfers and synchronization with Proton Drive.
backend/protondrive · high confidence
Add Put.io backend
A new backend for Put.io has been added, enabling users to mount and manage their Put.io cloud storage with rclone. The implementation supports standard file operations including uploading, downloading, directory listing, and moving files, along with OAuth2 authentication. It includes specific handling for rate limits and transient errors such as TRASH\_LOCK\_TIMEOUT, and respects file modification times.
backend/putio · high confidence
Add Quatrix backend support
Introduces a new backend for the Quatrix by Maytech object storage system, enabling users to mount and interact with Quatrix storage via rclone. The implementation includes full file operations (upload, download, move, copy, delete), support for chunked uploads with dynamic memory management to optimize transfer speeds, and configuration options such as skipping project folders and hard deletes. It also handles server-side conflict resolution by overwriting files during moves and ensures correct modification times are preserved.
(repo-wide) · high confidence
Add QuickXorHash implementation for OneDrive
The OneDrive backend now includes a native implementation of the QuickXorHash algorithm, a non-cryptographic hash function used by Microsoft OneDrive for Business. This addition enables the backend to correctly compute file hashes required for OneDrive operations, addressing previous limitations on 32-bit architectures and improving overall hashing performance.
backend/onedrive/quickxorhash · high confidence
Add SMB (CIFS) backend with Kerberos authentication and connection pooling
Users can now mount SMB/CIFS shares using the new 'smb' backend. This feature introduces a connection pooling mechanism to improve performance and reliability, along with support for Kerberos authentication (including configurable credential caches and Service Principal Names) and NTLM authentication with optional workstation names. The backend handles connection lifecycle management, including proper cleanup on setup failures and efficient reuse of connections for operations like uploads and metadata updates.
backend/smb · high confidence
Add Sia decentralized cloud backend
Users can now mount and manage files on the Sia decentralized cloud storage network. This new backend connects to a local siad daemon (defaulting to http://127.0.0.1:9980) using an API password and supports standard file operations like uploading, downloading, and directory listing. It includes configuration options for the API URL, user agent, and path encoding, and integrates with rclone's standard testing framework for integration verification.
backend/sia · high confidence
Add Uloz.to backend
Adds a new backend for the Uloz.to file hosting service, enabling users to mount and interact with their Uloz.to storage via rclone. The implementation includes full support for file operations, directory caching, and configuration options such as app tokens, username/password authentication, and root folder slugs. It also implements the About interface to report storage usage and includes integration tests to verify functionality.
backend/ulozto · high confidence
Add cat command with file content filtering and separation options
A new \cat\ command has been added to rclone, allowing users to concatenate and output file contents to stdout. This command supports filtering output with \--head\, \--tail\, \--offset\, and \--count\ flags to select specific character ranges, and includes a \--separator\ option to insert custom delimiters between multiple files. The \--discard\ flag is also available to suppress output entirely.
cmd/cat · high confidence
Add copyto command for renaming files during copy
A new \copyto\ command is introduced, allowing users to copy a single file to a destination with a different name (effectively copying and renaming in one step) or copy a directory structure. The command skips identical files based on size, modification time, or MD5SUM and does not delete existing destination files. It supports logger flags to store sync results and includes real-time progress statistics via the \-P\/\--progress\ flag.
cmd/copyto · high confidence
Add dedicated md5sum and sha1sum commands with stdin support
New standalone commands \rclone md5sum\ and \rclone sha1sum\ are now available, providing a convenient interface for generating MD5 and SHA-1 checksums respectively. These commands mirror the output format of their standard Unix counterparts and support hashing data received via standard input (stdin) when no remote path is specified or a hyphen is passed. They also inherit the \--download\ flag, allowing users to force local hashing for remotes that do not natively support these algorithms.
cmd/md5sum, cmd/sha1sum · high confidence
Add deletefile command to remove individual files
A new \deletefile\ command has been added, allowing users to remove a single file from a remote. Unlike the existing \delete\ command, this command cannot remove directories and ignores include/exclude filters; if the specified file exists, it will always be removed. The command returns an error if the target is a directory or does not exist.
cmd/deletefile · high confidence
Add disk usage measurement library
A new \lib/diskusage\ package has been introduced to provide cross-platform disk space monitoring. It exposes a \New\ function that returns total, free, and available disk bytes for a given directory, utilizing platform-specific system calls (such as \statfs\ on Unix-like systems and \GetDiskFreeSpaceEx\ on Windows) while gracefully handling unsupported platforms with a dedicated error.
lib/diskusage · high confidence
Add hidden 'reveal' command to unmask obscured passwords
A new 'reveal' command has been added to the CLI, allowing users to unmask passwords that were previously obscured in the rclone configuration file. The command takes a single obscured password argument and prints the plain-text version to the standard output. This command is marked as hidden and was introduced in version v1.43.
cmd/reveal · high confidence
Add histogram test command for filename character analysis
A new 'rclone test histogram' command has been added to the test suite. When run against a remote path, it generates a JSON histogram of the characters used in filenames. This tool is intended for developers to analyze filename distributions, particularly for optimizing filename compression, and does not expose any identifying information about the files.
cmd/test/histogram · high confidence
Add iCloud Drive and Photos backend
Introduces a new \iclouddrive\ backend that provides access to both iCloud Drive and iCloud Photos. The implementation supports authentication via Apple ID with 2FA (SMS and push), session persistence, and service selection (Drive vs. Photos) during configuration. For iCloud Photos, it offers read-only access to libraries and smart albums, exposing metadata such as image dimensions, favorite status, and addition time. The backend handles path sanitization, Unicode normalization for filenames, and includes integration tests to verify functionality.
backend/iclouddrive · high confidence
Add key-value database library
A new key-value database library (lib/kv) is introduced, providing a persistent storage backend using bbolt for caching and state management. The implementation includes a thread-safe API for starting, querying, and stopping database instances, with support for concurrent access and graceful shutdown. The library is available on supported operating systems (excluding plan9 and js) and includes unit tests to verify concurrency safety and lifecycle management.
lib/kv · high confidence
Add lib/mmap package for anonymous memory map allocation
The new lib/mmap package provides a cross-platform API for allocating and freeing large blocks of memory using anonymous memory maps. It exposes Alloc and Free functions (along with MustAlloc and MustFree variants) that utilize OS-specific mechanisms—Unix mmap, Windows VirtualAlloc, or fallback heap allocation for unsupported platforms like Plan 9 and WebAssembly—enabling efficient memory management for applications requiring direct memory access.
lib/mmap · high confidence
Add moveto command for moving files with a new destination name
A new \moveto\ command has been added, allowing users to move a file or directory to a destination with a specific name, effectively enabling rename operations during the move. When the source is a file, it moves it to the specified destination path; when the source is a directory, it behaves identically to the existing \move\ command. The command supports logger flags to store sync results and includes documentation recommending the use of \--dry-run\ or \--interactive\ flags to prevent data loss.
cmd/moveto · high confidence
Add native Oracle Cloud Infrastructure Object Storage backend
This change introduces a new \oracleobjectstorage\ backend (prefix \oos\) for Rclone, enabling direct interaction with OCI Object Storage. The implementation supports multiple authentication methods including user principals, instance principals, resource principals, workload identity (for OKE), and no-auth for public buckets. Key features include server-side copy and move operations, multipart upload with configurable concurrency and chunk sizes, and a \backend restore\ command to restore objects from Archive storage. It also supports Bring Your Own Key (BYOK) encryption via SSE-C and KMS, automatic decompression of gzip-encoded downloads, and storage tier management (Standard, Infrequent Access, Archive).
backend/oracleobjectstorage · high confidence
Add obscure command for encrypting passwords
A new \rclone obscure\ command has been added to generate encrypted (obscured) passwords for use in the rclone configuration file. This command accepts a password as an argument or via standard input (using \-\), encrypting the input and outputting it in base64 format to prevent accidental exposure of credentials in the config file. This feature was introduced in version v1.36.
cmd/obscure · high confidence
Add premiumize.me API type definitions
Introduced the Go type definitions for the premiumize.me API integration, including structures for API responses, file/folder items, breadcrumbs, and account information. This provides the foundational data models required for the new backend support.
backend/premiumizeme/api · high confidence
Add premiumize.me backend
Users can now connect to the premiumize.me object storage system via a new 'premiumizeme' backend. This implementation supports OAuth 2.0 authentication, allows configuration of an API key as an alternative, and includes directory caching for improved performance. The backend integrates with the standard rclone encoding options to handle file name characters correctly.
backend/premiumizeme · high confidence
Add rcat command for streaming uploads from stdin
A new \rcat\ command has been added, allowing users to copy data from standard input (stdin) directly to a file on a remote storage backend. This enables streaming uploads via pipes (e.g., \echo "hello" \| rclone rcat remote:path\). The command includes a \--size\ flag to preallocate the remote file in advance, which improves efficiency for remotes that do not support native streaming uploads. Note that because the data is streamed and not cached locally, standard retry mechanisms do not apply to the entire transfer, though multipart chunk retries may be supported by the backend.
cmd/rcat · high confidence
Add rmdirs command with --leave-root option
A new \rmdirs\ command has been added to recursively remove empty directories under a specified path, helping to tidy up remote storage structures left behind by file deletions. The command includes a \--leave-root\ flag that prevents the removal of the root directory itself if it becomes empty, offering more control over the cleanup process.
cmd/rmdirs · high confidence
Add runtime detection for Go race detector status
The library now exposes a package-level constant to indicate whether the Go race detector is active at runtime. This is implemented via two new files, \israce.go\ and \norace.go\, which use build constraints (\//go:build race\ and \//go:build !race\) to set the \Enabled\ constant to \true\ or \false\ respectively, allowing other parts of the application to conditionally adjust behavior based on the presence of the race detector.
lib/israce · high confidence
Add runtime/debug helpers for GC and memory limit configuration
The lib/debug package now exposes SetGCPercent and SetMemoryLimit functions that wrap the corresponding runtime/debug APIs, allowing users to programmatically adjust garbage collection percentages and set soft memory limits directly from the application.
lib/debug · high confidence
Add settier command to change storage class/tier
A new \settier\ command has been added, allowing users to change the storage class or tier of objects on supported cloud remotes (such as AWS S3, Azure Blob, and Google Cloud Storage). The command requires a target tier and a remote path, and it checks for remote support before attempting the operation via the \operations.SetTier\ function.
cmd/settier · high confidence
Add size command with JSON output support
The new \size\ command allows users to calculate the total size and object count for a remote path. It outputs results in a human-readable format by default, including both human-readable and raw numbers, and now supports a \--json\ flag to format the output as JSON for easier parsing. The command also warns users if some objects have unknown sizes, which may lead to underestimated totals.
cmd/size · high confidence
Add support for loading out-of-tree storage plugins
Users can now extend rclone by loading custom storage backends as dynamic libraries on Linux and macOS. By setting the RCLONE\_PLUGIN\_PATH environment variable to a directory containing shared objects named librcloneplugin\_NAME.so, rclone will automatically discover and load these plugins at startup, allowing for custom backend implementations without modifying the core source code.
lib/plugin · high confidence
Add systemd notification utilities for service lifecycle management
The lib/systemd package now provides utilities to communicate with the systemd service manager, allowing commands to properly signal their readiness and stopping states. This includes a Notify function that sends a READY notification upon initialization and a STOPPING notification when the service exits, ensuring correct integration with systemd's service monitoring. Additionally, an UpdateStatus function is available to report custom status strings to systemd.
lib/systemd · high confidence
Add systemd socket activation support with platform-specific implementations
The lib/sdactivation package now provides a wrapper around the coreos/go-systemd library to support systemd socket activation. It introduces two platform-specific files: sdactivation\_unix.go implements the actual activation logic using go-systemd for non-Windows/Plan9 systems, while sdactivation\_stub.go provides empty stub implementations for Windows and Plan9 to ensure the package builds on those platforms despite go-systemd's lack of support there. This allows the application to utilize systemd socket activation where available while maintaining build compatibility on other operating systems.
lib/sdactivation · high confidence
Add touch command to set or create file modification times
A new \touch\ command has been added, allowing users to create new files or update the modification time of existing files on a remote. The command supports setting specific timestamps via the \--timestamp\ flag (accepting formats like \YYYY-MM-DD\, \YYYY-MM-DDTHH:MM:SS\, and nanosecond precision), with an optional \--localtime\ flag to interpret timestamps in local time rather than UTC. It also includes a \--recursive\ (\-R\) flag to update times for all files within a directory tree, a \--no-create\ (\-C\) flag to prevent creating new files if they do not exist, and support for setting metadata on newly created files via \--metadata-set\.
cmd/touch · high confidence
Add uloz.to backend API type definitions
Introduces the Go type definitions for the new uloz.to backend integration, mapping JSON API responses for files, folders, and uploads to structured Go types.
backend/ulozto/api · high confidence
Added drive letter validation utility
A new \fs/driveletter\ package has been introduced to determine if a given string represents a valid Windows drive letter. On Windows systems, the \IsDriveLetter\ function checks if the input is a single alphabetic character; on non-Windows platforms, it consistently returns false, ensuring cross-platform compatibility without errors.
fs/driveletter · high confidence
Authorize command now supports custom HTML templates
The authorize command has been refactored into its own package and now includes a new --template flag that allows users to provide a custom Go template for generating HTML responses during the authorization flow. This change also updates the command's help text to clearly display required arguments and links to remote setup documentation, while ensuring the command works correctly in headless environments by respecting the --auth-no-open-browser flag.
cmd/authorize · high confidence
Backend overview now exposes tier information
The backend overview feature now includes a 'tier' field in its configuration data, allowing users to see the support tier (e.g., Tier 1) for each backend. This change introduces the \GetBackendConfig\ function to parse backend YAML files and includes tests verifying that tier data is correctly loaded for backends like S3 and memory.
backend/overview · high confidence
Enhanced version command with dependency listing and online version checking
The \version\ command now supports two new flags: \--check\ and \--deps\. Using \--check\ performs an online comparison against the latest release and beta versions available on rclone.org, displaying upgrade URLs if a newer version is found. The \--deps\ flag prints detailed build information, including the Go version, main package details, binary path, and a list of all Go dependencies with their versions. The command output also now explicitly displays the OS version, kernel version, bitness, and build tags.
cmd/version · high confidence
Environment variables now set default values for command-line flags
Flags can now be configured via environment variables, which serve as the default value for the corresponding command-line flag. This allows users to set persistent defaults through the environment while still overriding them on the command line. The implementation supports standard flags as well as string array flags (parsed as CSV lists) and integrates with the existing flag grouping system for help documentation.
fs/config/flags · high confidence
Expanded rclone config command with new subcommands for remote and file management
The \rclone config\ command now includes a comprehensive set of new subcommands to manage configuration files and remotes more precisely. Users can now view configuration paths (\paths\), ensure the config file exists (\touch\), display the config file or specific remote settings (\show\, \redacted\), and dump the config as JSON (\dump\). Remote management has been enhanced with commands to create (\create\), update (\update\), delete (\delete\), and unset options (\unset\) for remotes, as well as reconnect, disconnect, and view user info for active sessions. Additionally, new capabilities include listing available providers and options (\providers\), generating connection strings (\string\), managing config encryption (\encryption\), and setting obscured passwords (\password\).
cmd/config · high confidence
Experimental Apache Arrow blob listing for Azure Blob Storage
The \backend/azureblob/arrowlist\ package introduces an experimental feature that allows Azure Blob Storage container listings to be fetched using the Apache Arrow IPC format instead of the traditional XML. This new capability provides a \Client\ and pager interface (\NewListBlobsHierarchyPager\) that requests Arrow responses via the \UseArrowFormat\ option, parsing the binary stream into standard blob item structures. The implementation includes custom authentication policies for token and shared-key credentials to support the Arrow requests, and automatically falls back to XML parsing if the service does not return Arrow data, unless the \EndBefore\ filter is set (which requires Arrow to guarantee correct range limiting).
backend/azureblob, backend/azureblob/arrowlist · high confidence
Experimental browser integration via WebAssembly
Adds an experimental interface for using the rclone remote control (rc) API directly in web browsers. This change introduces a new \fs/rc/js\ directory containing Go source code (\main.go\) that compiles to WebAssembly, exposing the \rc\ function to JavaScript. It includes a loader script (\loader.js\) to initialize the WASM module, a test HTML page, and a local development server (\serve.go\), allowing developers to call rclone methods like \core/version\ or \operations/mkdir\ from client-side code.
fs/rc/js · high confidence
Generic multipart upload library added to lib/multipart
A new generic multipart upload implementation has been added in lib/multipart, allowing backends to offload the complexity of parallel chunked uploads. This library handles concurrent reading from the source, memory pooling, progress accounting, and error cleanup (aborting uploads on failure). It also includes validation to ensure the uploaded data size matches the source object's declared size, preventing truncated objects if the source ends early.
lib/multipart · high confidence
Google Cloud Storage backend introduces directory markers and requester-pays support
The Google Cloud Storage backend now supports directory markers, allowing empty directories to be preserved and synced correctly by treating them as explicit objects rather than implicit constructs. Additionally, the backend adds support for Google Cloud's Requester Pays feature, enabling users to access buckets where the requester, not the bucket owner, bears the storage costs. These changes improve compatibility with GCS-specific features and ensure accurate directory structure synchronization.
backend/googlecloudstorage · high confidence
Initial HiDrive API integration layer
Added the foundational API client components for the new HiDrive backend, including type definitions for HiDrive objects (files, directories, symlinks) and query parameter helpers for constructing API requests. This enables the application to interact with the HiDrive storage service.
backend/hidrive/api · high confidence
Initial QingStor backend support
Users can now mount and transfer files to QingStor object storage. This new backend supports standard operations like listing, uploading, and downloading, with configurable options for authentication (including environment variables), endpoint/zone selection, and multipart upload tuning (chunk size, concurrency, and cutoff). It also includes cleanup logic to remove pending multipart uploads and handles error propagation for failed uploads.
backend/qingstor · high confidence
Initial implementation of the Backblaze B2 backend
This change introduces the new \b2\ backend, enabling rclone to interact with the Backblaze B2 object storage system. The implementation supports chunked uploads for large files, server-side encryption (SSE-C), and configurable upload concurrency. It also includes features for managing file versions, lifecycle rules, and link sharing, along with specific handling for application keys and custom download URLs.
backend/b2 · high confidence
Introduce 'rclone gitannex' subcommand for git-annex integration
Rclone now includes a new 'gitannex' subcommand that implements the git-annex external special remote protocol, allowing git-annex to store and retrieve content directly from rclone-managed remotes. This feature introduces configuration options for specifying the target remote name (with synonyms like 'target'), a content prefix directory, and storage layout modes (such as 'nodir', 'lower', 'directory', 'mixed', and 'frankencase'). The implementation supports the protocol version 1 and includes validation for remote names and backend paths, enabling users to configure git-annex remotes that leverage rclone's backend capabilities.
cmd/gitannex · high confidence
Introduce --name-transform for file and directory name manipulation
The new \lib/transform\ library adds the \--name-transform\ flag, allowing users to apply a wide range of transformations to file and directory names during operations like \convmv\. Supported transformations include prefixing, suffixing, trimming, regex-based replacement, Base64 encoding/decoding, case conversion, ASCII stripping, URL encoding, Unicode normalization (NFC/NFD/NFKC/NFKD), character mapping, and truncation by characters or bytes. Users can scope these changes to files, directories, or the entire path using tags like \file,\, \dir,\, or \all,\.
lib/transform · high confidence
Introduce B2 API type definitions and timestamp handling
The backend/b2/api package now includes a dedicated types.go file defining the Go structs for Backblaze B2 API responses, including Error, Bucket, LifecycleRule, ServerSideEncryption, File, and StorageAPI. This change introduces a custom Timestamp type that correctly marshals and unmarshals B2's millisecond-based epoch timestamps, and adds helper functions for versioned filename handling. A corresponding test file validates the JSON serialization and equality checks for these timestamp types.
backend/b2/api · high confidence
Introduce ChunkedReader for parallel and chunked file reading
Added the \fs/chunkedreader\ package, which provides a \ChunkedReader\ interface and implementation for reading remote objects in chunks. This new component supports both sequential reading with adaptive chunk sizing and parallel multi-stream reading to improve performance. It includes a public API (\New\) to instantiate the reader, along with comprehensive test coverage for both sequential and parallel modes.
fs/chunkedreader · high confidence
Introduce FTP server with secure, session-bound authentication
Adds a new \rclone serve ftp\ command that exposes a remote filesystem over the FTP protocol, configurable via flags for listen address, passive port ranges, TLS certificates, and basic username/password authentication. The implementation uses the \goftp.io/server/v2\ library and includes a critical security fix for the auth-proxy mode: credentials are now bound to individual FTP sessions rather than shared by username, preventing one user from hijacking another's session when they share the same login name. The feature also includes an RC interface for remote control and is disabled on Plan 9 due to compilation constraints.
cmd/serve/ftp · high confidence
Introduce Google Photos backend with virtual directory structure and album management
This change adds a new Google Photos backend that presents the Google Photos library as a virtual file system. It implements a structured directory layout including \media\ (organized by year, month, and day), \album\ and \shared-album\ views, an \upload\ directory for new files, and a \feature\ directory (e.g., favorites). The backend handles album creation and deduplication, supports batched uploads, and enforces Google's OAuth scope requirements. It also includes configuration warnings about the shared client ID and policy changes regarding downloading photos not uploaded by rclone.
backend/googlephotos · high confidence
Introduce HTTP backend for accessing remote file systems
Adds a new HTTP backend that treats HTML pages served from an endpoint as directory listings, allowing users to browse and access files hosted on web servers. The implementation supports configuration of custom HTTP headers, options to disable HEAD requests for performance, handling of directories without trailing slashes, and URL metacharacter escaping controls. It also exposes HTTP metadata (such as Content-Type and Cache-Control) as object metadata and includes comprehensive internal tests with sample HTML directory listings from various web servers.
backend/http · high confidence
Introduce Jottacloud backend with API type definitions and time handling
Adds a new Jottacloud backend implementation, starting with the API layer in \backend/jottacloud/api\. This includes type definitions for authentication (LoginToken, WellKnown, TokenJSON), file operations (AllocateFileRequest/Response, UploadResponse), device registration, and customer info. It also introduces custom time types (\JottaTime\ for legacy API formats and \Rfc3339Time\ for newer APIs) to handle XML marshaling/unmarshaling correctly, along with tests to ensure empty modification times are handled as zero values.
backend/jottacloud/api · high confidence
Introduce Linux-specific FUSE mount implementation
Adds a new FUSE-based mount command for Linux, implementing the filesystem interface via \bazil.org/fuse/fs\ to expose rclone remotes as local directories. This change introduces platform-specific source files (\dir.go\, \file.go\, \fs.go\, \handle.go\, \mount.go\) that handle directory operations, file I/O, attribute management, and mount options, while providing a stub for unsupported platforms to ensure buildability.
cmd/mount · high confidence
Introduce Storj decentralized object storage backend
Added a new backend for Storj (formerly Tardigrade) decentralized cloud storage, allowing users to mount and manage files stored on the Storj network. The implementation supports authentication via existing access grants or by creating new ones from satellite address, API key, and passphrase, and implements core filesystem operations including listing, uploading, downloading, moving, copying, and purging objects.
backend/storj · high confidence
Introduce \`rclone serve sftp\` command to serve remotes over SFTP
Adds a new \serve sftp\ command that allows users to expose an rclone remote via the SFTP protocol. The implementation includes a full SSH server with password and authorized-keys authentication, support for the \--stdio\ flag for use with OpenSSH's \command=\ restriction, and the \--auth-proxy\ option for external authentication. It supports multiple host key types (RSA, ECDSA, Ed25519) and implements SFTP extensions for checksums (md5sum, sha1sum, crc32, sha256, blake3, xxh128) and disk usage reporting (statvfs), ensuring compatibility with standard SFTP clients and the rclone sftp backend.
cmd/serve/sftp · high confidence
Introduce asynchronous read-ahead reader for improved I/O performance
A new \asyncreader\ package has been added to the \fs\ directory, providing an asynchronous reader that performs read-ahead from an input stream independently of the consumer. This component uses a buffer pool to manage memory and exposes an \io.Reader\ interface, allowing downstream operations to benefit from parallelized I/O. The implementation includes comprehensive tests covering various buffer sizes, read patterns, and error conditions to ensure reliability.
fs/asyncreader · high confidence
Introduce chunker backend to split large files into smaller chunks
A new 'chunker' backend is added, allowing users to transparently split large files into smaller chunks on a remote storage. This feature is useful for overcoming file size limits or improving upload reliability on remotes that do not support large files natively. The implementation includes configuration options for chunk size, naming formats, and metadata handling, along with comprehensive tests to ensure correct behavior.
backend/chunker · high confidence
Introduce cmount: a new FUSE mounting backend for Windows and macOS
A new mounting implementation, cmount, is added for Windows and macOS (and other platforms with cgo support), replacing the previous platform-specific mount mechanisms. This new backend uses the cgofuse library to provide FUSE mounting capabilities, enabling features such as symlink support, case-insensitive mount options, and improved error handling for missing dependencies like WinFsp. It also introduces specific behaviors for Windows, including automatic drive letter assignment, network share path detection, and proper handling of volume names, while maintaining compatibility with existing mount options and VFS caching modes.
cmd/cmount · high confidence
Introduce copyurl command for direct URL-to-remote transfers
A new \copyurl\ command is added, allowing users to download content from a URL and copy it directly to a remote destination without temporary storage. The command supports several options: \--auto-filename\ to derive the destination name from the URL, \--header-filename\ to use the Content-Disposition header, \--print-filename\ to output the resulting name, \--no-clobber\ to skip existing files, and \--stdout\ to write output to standard output. Additionally, the \--urls\ flag enables processing a CSV file of multiple URLs with optional filenames, executing copies in parallel.
cmd/copyurl · high confidence
Introduce custom JSON types for File Fabric API compatibility
Added \types.go\ to the File Fabric API backend, defining custom Go types (\Time\, \Int\, \String\) that handle specific JSON serialization and deserialization requirements of the File Fabric API, such as parsing quoted integers and specific UTC time formats.
backend/filefabric/api · high confidence
Introduce experimental S3 server command
Adds the \serve s3\ command, which exposes a remote path as an S3-compatible endpoint using the \gofakes3\ library. This feature supports Signature Version 4 authentication, streaming multipart uploads to the backend, atomic object writes via temporary files, and path traversal protection to ensure clients cannot access files outside the designated bucket namespace.
cmd/serve/s3 · high confidence
Introduce generic lib/batcher for upload batching
A new generic batcher library (lib/batcher) has been added, providing a reusable component for batching uploads in sync, async, or off modes. This library is now used by the Dropbox backend, replacing the previous backend-specific implementation. It supports configurable batch sizes, timeouts, and includes a deprecated batch\_commit\_timeout option that is no longer used.
lib/batcher · high confidence
Introduce in-memory object storage backend with discard mode
Users can now use an in-memory backend (\:memory:\) for object storage operations, which stores data in RAM rather than on disk. This backend includes a \discard\ option that allows uploads to proceed without actually saving file contents, enabling fast performance testing by calculating MD5 sums while skipping data persistence. The implementation includes internal tests to verify stability, specifically addressing potential deadlocks during purge operations.
backend/memory · high confidence
Introduce librclone: embeddable C library and language bindings for rclone
Users can now integrate rclone's remote control (RC) API directly into external applications via a new C library (librclone) and official bindings for Python, PHP, and Go (gomobile). This change adds the core C interface, allowing C/C++ programs to initialize rclone, execute RPC commands (such as file operations and configuration management), and handle results, along with memory management utilities like RcloneFreeString. The diff also includes a C test program, Python and PHP wrapper modules with test scripts, and a Go mobile shim, enabling developers to embed rclone functionality into non-Go applications without running the CLI binary.
librclone · high confidence
Introduce lsjson command for JSON-formatted directory listings
Adds the new \lsjson\ command, which lists directories and objects in a specified path and outputs the results as a JSON array. The command supports various options to customize the output, including \--recursive\ for nested listings, \--hash\ to include file hashes, \--no-modtime\ and \--no-mimetype\ to skip specific metadata reads for performance, \--encrypted\ to show encrypted names, \--original\ to display underlying object IDs, \--files-only\ and \--dirs-only\ to filter the output type, \--metadata\ to include additional metadata, \--hash-type\ to specify hash algorithms, and \--stat\ to return information for a single item instead of a list. The output format includes fields such as Hashes, ID, OrigID, IsBucket, IsDir, MimeType, ModTime, Name, Encrypted, EncryptedPath, Path, Size, and Tier, with the exact set of properties depending on the remote backend and flags used.
cmd/lsjson · high confidence
Introduce mount2 FUSE implementation using go-fuse
A new FUSE-based mounting system (mount2) is added for Linux and macOS (amd64), implemented via the go-fuse/v2 library. This new mount command provides a modern alternative to the existing mount mechanism, featuring support for direct I/O, symlink handling, and stable inode reporting to improve NFS compatibility. It includes specific fixes for common issues such as empty directory listings, non-zero Seekdir offsets, and missing . and .. entries, while also disabling extended attributes by default to ensure broader compatibility.
cmd/mount2 · high confidence
Introduce ncdu command for remote filesystem exploration
Adds the \ncdu\ command, providing a text-based user interface for exploring remote filesystems. This new feature allows users to navigate directory structures, view file sizes, and manage files interactively, similar to the local \ncdu\ tool but operating over rclone remotes. The implementation uses the tcell library for the terminal UI and supports features such as sorting by size, name, or modification time, visual selection, and deletion of files and directories.
cmd/ncdu · high confidence
Introduce new cache backend with Plex integration and background uploads
The cache backend has been rewritten to support caching existing remotes with a new architecture using bbolt for persistent metadata and go-cache for transient chunk storage. Key user-facing changes include the ability to integrate with Plex servers via WebSocket notifications to optimize read workers during playback, support for background uploading of files written to a temporary path, and improved handling of concurrent map writes. The backend now exposes remote control (rc) functions for cache management and stats, and includes specific options for Plex authentication and certificate validation.
backend/cache · high confidence
Introduce pcloud backend with OpenWriterAt and SHA256 support
The pcloud backend is now available, providing access to Pcloud storage. This implementation adds support for SHA256 checksums and implements the OpenWriterAt feature, enabling efficient large file uploads and resumable writes. The backend also includes configuration options for specifying the API hostname (supporting both US and EU regions) and root folder ID.
backend/pcloud · high confidence
Introduce programmable auth proxy for serve commands
Added a new \cmd/serve/proxy\ package that enables dynamic, per-user backend configuration via an external program. Users can now supply an \--auth-proxy\ command to rclone serve (S3, SFTP, etc.), which receives authentication details (passwords, public keys, or S3 access keys) and client IP addresses via JSON on STDIN. The proxy program returns a backend type and configuration (including root, obscured secrets, and S3 secret keys) on STDOUT, allowing rclone to create and cache VFS instances on the fly. This replaces static authorized keys with a flexible, scriptable authentication layer that supports password, public-key, and S3 access-key authentication, with caching based on user credentials and client IP.
cmd/serve/proxy · high confidence
Introduce rclone archive command with file-system abstraction and byte-counting utilities
This change adds the \cmd/archive/files\ package, which provides the core file-system abstractions (\fs.FileInfo\, \fs.File\) and metadata handling (mode, UID, GID, timestamps) required for the new \rclone archive\ command to create and read archive files. It also introduces a \CountWriter\ utility that safely tracks the total bytes written, supporting accurate transfer accounting during archive operations.
cmd/archive/files · high confidence
Introduce remote control client command
Adds the \rclone rc\ command, allowing users to interact with a running rclone remote control server. Users can now send commands via HTTP or Unix sockets, authenticate with \--user\ and \--pass\, and pass structured inputs using \--opt\ and \--arg\ flags or JSON via \--json\. The command also supports a \--loopback\ mode for testing without a separate server process.
cmd/rc · high confidence
Introduce secure random string and password generation utilities
The lib/random package now provides dedicated functions for generating random strings and passwords. The String function creates test-friendly random strings using crypto/rand, while the Password function generates cryptographically strong, memorable passwords from a base64 URL-safe alphabet, allowing users to specify security strength in bits. This replaces previous implementations that may have relied on less secure random sources.
lib/random · high confidence
Introduces centralized flag registration for the Remote Control server
The new \fs/rc/rcflags\ package provides a standardized way to register Remote Control command-line flags. By exposing an \AddFlags\ function, it allows various rclone commands to easily integrate RC options (such as authentication, CORS, and serving settings) into their flag sets using a consistent \rc-\ prefix, ensuring that RC configuration is available across different entry points.
fs/rc/rcflags · high confidence
Introduces command-line flag registration for the auth proxy
A new \proxyflags\ package has been added to the \cmd/serve/proxy\ directory, providing an \AddFlags\ function that registers non-file-system-specific command-line flags for the auth proxy feature. This change establishes the infrastructure for exposing proxy configuration options to users via the CLI, leveraging the existing \proxy.OptionsInfo\ and \flags.AddFlagsFromOptions\ utilities.
cmd/serve/proxy/proxyflags · high confidence
Introduction of the lib/dircache package for directory ID caching
The new lib/dircache package provides a thread-safe cache for mapping directory paths to their unique IDs and vice versa. It introduces a DirCacher interface that backends implement to handle low-level directory operations, allowing the cache to manage lookups, creation, and invalidation (via methods like FlushDir and SetRootIDAlias) without duplicating logic across individual storage drivers.
lib/dircache · high confidence
Local backend: new --local-fatal-if-no-space flag and disk-full error handling
The local backend now supports a new --local-fatal-if-no-space flag. When enabled, disk-full errors (ENOSPC on Unix, ERROR\_DISK\_FULL on Windows) encountered during file writes or transfers are treated as fatal errors, causing the operation to stop immediately rather than continuing or failing silently. This addresses issue \#8011 and ensures that users are explicitly notified of storage exhaustion during multi-thread transfers. The implementation includes platform-specific error detection and corresponding test coverage for both Unix and Windows environments.
backend/local · high confidence
Move command gains options to manage empty source directories
The move command now supports two new flags: --delete-empty-src-dirs, which removes empty directories left behind in the source after files are moved, and --create-empty-src-dirs, which recreates the source directory structure at the destination. These options allow users to fully control the directory hierarchy resulting from a move operation.
cmd/move · high confidence
New 'backend' command for direct backend-specific operations
A new \rclone backend\ command has been added, allowing users to run backend-specific commands (such as \stats\, \cleanup\, or \features\) directly from the CLI. This command supports passing options via the \-o\ flag and includes a \--json\ flag to force JSON output for any result type, ensuring consistent machine-readable output. It also provides help and feature discovery for supported backends, with hints to check the underlying remote if a command is not found on an overlay.
cmd/backend · high confidence
New 'link' command for generating public sharing links
A new 'link' command has been added to allow users to create, retrieve, or remove public links for files and folders on supported remotes. The command accepts an optional --expire flag to set an expiration time for the link (defaulting to 100 years if not specified) and an --unlink flag to remove an existing public link. This feature is available from version v1.41 onwards, though backend support for expiration and unlinking may vary.
cmd/link · high confidence
New 'rclone archive list' command to inspect archive contents
A new 'rclone archive list' command has been added (introduced in v1.72) that allows users to list the contents of archive files stored on remote storage. The command auto-detects the archive format and supports filtering options such as --long (to show size and modification time), --plain (for simple file names), --files-only, and --dirs-only. It integrates with existing rclone filtering and accounting mechanisms to provide detailed or script-friendly output of archive entries.
cmd/archive/list · high confidence
New 'tree' command for hierarchical remote listings
A new \tree\ command has been added to list the contents of a remote file system in a hierarchical, tree-like structure, similar to the Unix \tree\ utility. This command supports various formatting options including sorting by name, version, size, or modification time, displaying file sizes and modification times, controlling indentation, and outputting to a file. It integrates with existing rclone filtering options and provides a visual representation of directory structures for easier navigation.
cmd/tree · high confidence
New DLNA media server command
A new \serve dlna\ command has been added, allowing you to expose your remote storage as a DLNA media server for devices like Smart TVs, consoles, and media players. The server automatically discovers media files and associates external subtitle files (such as .srt or .idx/.sub) located in the same directory or in a \Subs\ subdirectory. It includes compatibility fixes for specific clients, such as removing file extensions from titles to prevent duplication on Samsung TVs, correcting XML quote escaping, and ensuring proper SOAP response argument ordering. The server supports configurable network interfaces and announcement intervals, and requires Go 1.21 or later.
cmd/serve/dlna · high confidence
New DirTree type for in-memory filesystem hierarchies
The \fs/dirtree\ package now provides a \DirTree\ type that allows building and managing filesystem hierarchies in memory. This new component supports adding files and directories, automatically creating parent directory entries, sorting entries, and pruning specific directories from the tree structure. Tests have been added to verify the correctness of these operations.
fs/dirtree · high confidence
New Docker volume plugin and sample server configurations
Users can now deploy rclone as a Docker volume plugin, with new files in contrib/docker-plugin/managed providing the Dockerfile, plugin configuration, and systemd unit/socket files to manage the service. Additionally, sample Docker Compose manifests have been added for running DLNA and WebDAV servers, simplifying the setup of these specific rclone serve modes.
contrib · high confidence
New Internxt Drive backend for Rclone
Adds a new backend for Internxt Drive, enabling users to mount and sync their Internxt storage with Rclone. The implementation includes full authentication handling (email/password login, 2FA support, and automatic JWT token refresh with re-login fallback), support for multi-part uploads with configurable chunk sizes and concurrency, and robust error handling for rate limits and file size limits. It also addresses specific file lookup issues, such as correctly handling dotfiles and files with extensions stored in different formats by the service.
backend/internxt · high confidence
New JWT-based authentication utility for service accounts
The new lib/jwtutil package provides functionality to obtain access tokens via JWT authentication, allowing users to configure rclone for service accounts using RSA-signed JWTs. This utility handles token generation, signing, and the subsequent HTTP request to exchange the JWT for an OAuth2 access token, storing the result in the configuration.
lib/jwtutil · high confidence
New PikPak backend with link validity validation
A new backend for the PikPak cloud storage service has been added, including API type definitions and a test suite. The implementation introduces a validity check for media download links, ensuring they are not expired before use, which helps prevent unnecessary retries and improves upload reliability.
backend/pikpak/api · high confidence
New PikPak backend with optimized multipart uploads
A new backend for the PikPak cloud storage service has been added, enabling users to mount and interact with their PikPak files via rclone. The implementation features a custom multipart upload mechanism that bypasses the standard AWS S3 manager, utilizing pooled memory buffers and configurable chunk sizes to improve performance and reliability. It also includes specific handling for file name collisions, integrity checks during upload, and optimized hash calculations (GCID) to ensure data consistency.
backend/pikpak · high confidence
New Seafile backend
Added a new backend for the Seafile storage system, enabling users to mount and manage Seafile libraries via rclone. The implementation supports standard file operations (upload, download, delete, rename, move) and includes configuration options for two-factor authentication (2FA), encrypted library keys, and automatic library creation. It handles API version detection (v2.0 vs v2.1), manages authentication token renewal for encrypted libraries, and implements rate limiting via a pacer.
backend/seafile · high confidence
New VFS module with directory and file handle abstractions
The VFS layer has been refactored into a new modular structure, introducing dedicated \Dir\ and \File\ types to represent directory and file nodes respectively. This change adds \DirHandle\ and \FileHandle\ abstractions to manage open directory and file streams, implementing standard \os.FileInfo\ and \io\ interfaces for compatibility. The new module includes a cross-platform error system (\vfs/errors.go\) mapping internal states to standard OS errors (e.g., \ENOENT\, \EBADF\), and provides remote control (rc) commands (\vfs/refresh\, \vfs/forget\) to manage the directory cache. Comprehensive test suites (\dir\_test.go\, \file\_test.go\, \dir\_handle\_test.go\) and a generated test matrix (\open\_test.go\) ensure correct behavior for all file opening flag combinations.
vfs · high confidence
New Zoho Workdrive backend implementation
Added a new backend implementation for Zoho Workdrive to support file synchronization with the Zoho platform. This change introduces the core API types and data structures required to interact with Zoho Workdrive, including support for private spaces, cursor-based listing for improved performance, and a large file upload API to handle larger files and avoid throttling. It also fixes missing URL encoding of filenames during uploads.
backend/zoho/api · high confidence
New Zoho Workdrive backend with rate-limiting and private space support
Added a new backend for Zoho Workdrive, enabling users to mount and manage files in Zoho's cloud storage. The implementation includes support for private workspaces, configurable rate limiting (via --zoho-tpslimit and --zoho-tpslimit-burst) to handle API throttling, and optimized folder listing with per-folder limiters to prevent hitting Zoho's request caps. It also features improved error handling for 429 rate-limit responses (honoring Retry-After headers), support for Japan and China regions, and fixes for large file uploads and downloads.
backend/zoho · high confidence
New \`rclone serve docker\` command to expose remotes as Docker volume plugins
Adds a new \serve docker\ subcommand that implements the Docker Volume Plugin API, allowing Docker to use rclone-managed cloud remotes as persistent storage volumes. The command starts an HTTP server (listening on a Unix socket by default or a configurable TCP address) that handles Docker's volume lifecycle requests (Create, Mount, Unmount, Remove, etc.). It supports parsing mount and VFS options passed by Docker, persists volume state to a JSON file to survive plugin restarts, and includes security measures such as rejecting volume names that escape the configured base directory and warning about the risks of socket access.
cmd/serve/docker · high confidence
New \`serve nfs\` command to expose remotes as NFS mounts
A new \serve nfs\ command is introduced, allowing users to serve any rclone remote over the NFSv3 protocol. This is particularly useful for mounting remotes on macOS where FUSE is difficult to install. The implementation includes a file handle cache with three modes: \memory\ (default, volatile), \disk\ (persistent on disk), and \symlink\ (Linux-only, high-performance using kernel file handles). The server supports mounting subpaths of the remote, ensures handle stability across root and subpath mounts, and advertises AUTH\_UNIX to support BSD NFS clients. It runs on the loopback interface by default for security and requires VFS caching for write operations.
cmd/serve/nfs · high confidence
New \`serve restic\` command with append-only mode, private repositories, and object caching
A new \serve restic\ command has been added to \cmd/serve/restic\, allowing rclone to act as a backend for the restic backup tool via its REST API. This implementation introduces several key capabilities: an append-only mode that prevents overwriting or deleting repository data (with tests verifying concurrent upload safety), private repository isolation that restricts users to their own paths and blocks path traversal attacks, and an optional object cache to speed up listing operations. The server also supports HTTP/2 over stdin/stdout for integration scenarios.
cmd/serve/restic · high confidence
New alias backend allows renaming remotes
A new 'alias' backend has been added, enabling users to create a virtual provider that renames or re-paths an existing remote. By configuring an alias with a 'remote' setting pointing to another remote (e.g., 'myremote:path'), users can access that underlying storage under a different name or path structure. The implementation validates that the alias does not point to an empty remote or itself, and delegates all operations to the cached instance of the target remote.
backend/alias · high confidence
New archive backend for reading remote archives
Introduces a new 'archive' backend that allows users to mount and browse archive files (such as ZIP and SquashFS) stored on remote storage as if they were local directories. The backend wraps an upstream remote, lazily instantiates archive readers, and supports nested archives. It includes security hardening to prevent path traversal attacks (entries escaping the archive namespace) and robustness improvements to handle malformed images without crashing.
backend/archive · high confidence
New atexit library for signal-based cleanup
A new \lib/atexit\ package has been added to provide robust handling for functions that need to run when the program exits unexpectedly due to signals. It allows registering and unregistering cleanup functions, automatically triggering them upon receiving SIGINT or SIGTERM on Unix (or Interrupt on Windows), and ensures non-zero exit codes are returned when signals are received. The package also includes an \OnError\ helper for deferring cancellation logic and uses atomic types for thread-safe state management.
lib/atexit · high confidence
New bucket utilities and caching library
Added a new \lib/bucket\ package providing utilities for managing bucket-based backends. This includes path manipulation functions (\Split\, \Join\, \IsAllSlashes\) that handle bucket and object key paths without normalizing slashes, and a \Cache\ struct to track bucket existence and deletion status with thread-safe creation and removal operations.
lib/bucket · high confidence
New buffer pool and thread-safe reader/writer for memory management
The lib/pool package introduces a deterministic memory pool for managing buffer allocations, supporting both standard heap and mmap-backed allocations. It includes a new thread-safe Read/Writer (RW) component that allows data to be written and read concurrently, featuring configurable buffer limits via the --max-buffer-memory flag and accounting hooks to track read usage. This infrastructure provides the foundation for optimized multi-threaded uploads and multipart transfers by reducing memory overhead and preventing deadlocks.
lib/pool · high confidence
New checksum command to verify files against a SUM file
A new \checksum\ command has been added, allowing users to verify that files in a destination path match the hash values recorded in a SUM file. The command supports various hash types (such as MD5 and SHA1) and treats hash values in the SUM file as case-insensitive. It includes a \--download\ flag to calculate content hashes on the fly by downloading data from the remote, which is useful for remotes that do not natively support hashing. This feature is introduced in version v1.56.
cmd/checksum · high confidence
New chunk size calculation helper for large uploads
A new \fs/chunksize\ package has been introduced to automatically calculate the optimal chunk size for large file uploads. This helper ensures that uploads stay within the maximum number of parts allowed by storage backends (such as Azure Blob, B2, and S3) by dynamically adjusting the chunk size upward when the default is insufficient, while rounding up to the nearest MiB to satisfy backend constraints. This prevents upload failures caused by exceeding part limits without unnecessarily increasing memory usage.
fs/chunksize · high confidence
New combine backend to merge multiple remotes into a single directory tree
A new 'combine' backend has been added, allowing users to configure multiple upstream remotes (such as local directories or memory stores) and present them as a single unified filesystem. By specifying upstream paths via the 'upstreams' configuration option, the backend maps files from different sources into one coherent directory structure, enabling operations across combined storage locations.
backend/combine · high confidence
New compress backend with Gzip and Zstd support
The backend/compress directory introduces a new experimental 'compress' remote that wraps an existing storage backend to automatically compress uploaded files and decompress them on download. It supports two compression modes: Gzip (using the sgzip library) and Zstandard (using the klauspost/compress and a1ex3/zstd-seekable-format-go libraries). The implementation handles file metadata, compressibility heuristics, and efficient streaming uploads, allowing users to save storage space on compatible remotes.
backend/compress · high confidence
New configmap package for prioritized configuration management
A new \configmap\ package has been added to provide a generic abstraction for reading and writing configuration. It introduces a \Map\ type that supports multiple getters with defined priorities (Normal, Config, Default), allowing the system to resolve configuration values from different sources in a specific order. The package also includes a \Simple\ map implementation for testing, featuring consistent string representations (\String\ and \Human\ methods) and encoding capabilities suitable for command-line usage.
fs/config/configmap · high confidence
New configstruct package for parsing configuration maps into Go structs
A new \configstruct\ package has been added to parse unstructured configuration maps into Go structs. It supports nested structs, custom \config\ struct tags, and automatic conversion between string representations and various types (including integers, booleans, durations, and string arrays encoded as CSV). The package provides functions to extract configuration items from structs and to set struct fields from configuration maps, enabling more structured and type-safe configuration handling.
fs/config/configstruct · high confidence
New convmv command for in-place file and directory name conversion
A new \convmv\ command has been added to rclone, allowing users to convert and rename files and directories in place by applying name transformations (such as NFC/NFD normalization, prefix/suffix addition, or character encoding changes) via the \--name-transform\ flag. This command registers itself under the root command and leverages the existing \sync.Transform\ and \operations.TransformFile\ functions to perform the actual file system operations, supporting options to delete or create empty source directories after the move.
cmd/convmv · high confidence
New cryptcheck command to verify encrypted remote integrity
A new \cryptcheck\ command has been added to allow users to verify the integrity of an encrypted remote by comparing checksums of the encrypted files against the underlying unencrypted source. This command functions similarly to the existing \check\ command but is specifically designed to handle the encryption layer, ensuring that the data stored in the crypt remote matches the original files.
cmd/cryptcheck · high confidence
New cryptdecode command to decrypt or encrypt filenames
A new \cryptdecode\ command has been added to allow users to retrieve unencrypted filenames from a crypt remote, or conversely, encrypt filenames using the \--reverse\ flag. The command accepts up to 11 filenames at once and requires the target remote to be of type 'crypt'. It leverages the underlying crypt backend's cipher to perform the name transformations, providing a convenient alternative to the \rclone backend encode/decode\ methods for filename manipulation.
cmd/cryptdecode · high confidence
New development and release tooling scripts
The bin directory now includes a suite of new scripts to support development workflows and release management. This includes \check\_autogenerated\_edits.py\ to prevent unauthorized changes to auto-generated documentation, \make\_backend\_docs.py\ and \make\_bisync\_docs.go\ for generating backend and bisync documentation, and \make\_changelog.py\ for automating changelog generation. Release and build processes are supported by \cross-compile.go\ for multi-architecture builds, \get-github-release.go\ for fetching releases, and \fetch-gui-dist.sh\ for managing the embedded GUI. Additional utilities include \bisect-rclone.sh\ and \bisect-go-rclone.sh\ for debugging regressions, \config.py\ for testing remote configuration, \decrypt\_names.py\ for decrypting log files, \make-test-certs.sh\ for generating TLS certificates, and \backend-versions.sh\ to track backend introduction versions. A new \.ignore-emails\ file allows filtering contributor emails from the authors list.
bin · high confidence
New environment variable and tilde expansion utility
A new \lib/env\ package has been added, providing a \ShellExpand\ function that automatically expands leading \\~\ characters to the user's home directory and resolves environment variables (such as \${RCLONE\_CONFIG\_DIR}\) within file paths. This utility is intended to be used by backends to ensure consistent path handling across different operating systems.
lib/env · high confidence
New error counting utility for aggregated error reporting
A new \lib/errcount\ package has been introduced to help aggregate multiple errors without overwhelming the user. It provides a thread-safe \ErrCount\ type that tracks the number of errors and the last error encountered. When queried, it returns a formatted summary indicating either a single error or a count of errors along with the most recent one, simplifying error handling in operations that may encounter multiple issues.
lib/errcount · high confidence
New error-walking utility in lib/errors
The \lib/errors\ package introduces a \Walk\ function that traverses an error chain, supporting standard \Unwrap()\ methods, multi-error unwrapping (\Unwrap() \[\]error\), legacy \Cause()\ interfaces, and reflection-based detection of \Err\ fields in standard library error types. This provides a robust way to inspect nested errors without panicking on uncomparable types.
lib/errors · high confidence
New fs/hash package with expanded algorithm support
The fs/hash package has been introduced to centralize hashing utilities, adding support for CRC-32, SHA-512, BLAKE3, XXH3, and XXH128 alongside existing MD5, SHA-1, Whirlpool, and SHA-256. This change enables filesystems to compute multiple hash types simultaneously via the new MultiHasher and allows users to select specific algorithms for operations like hashsum.
fs/hash · high confidence
New fs/rc/jobs package for managing background jobs
The \fs/rc/jobs\ package has been introduced to centralize the management of background jobs executed via the remote control interface. This new component provides a \Job\ struct that tracks execution status, including start/end times, success/failure states, and execution duration, while supporting listener callbacks for job completion. It introduces an \executeId\ to group jobs by server instance and implements thread-safe job expiration and ID generation using atomic types. The package also exposes functions to retrieve job context and IDs, and includes comprehensive tests to ensure reliability under concurrent execution.
fs/rc/jobs · high confidence
New fspath package for parsing remote connection strings
A new \fspath\ package has been introduced to handle the parsing and validation of remote connection strings (e.g., \remote:path\ or \:backend:config:path\). This includes logic to decompose paths into remote names, configuration strings, and file paths, while enforcing strict rules on valid remote names (allowing Unicode, \+\, \@\, and spaces, but rejecting leading dashes or spaces). The package also provides fuzz testing capabilities to ensure robustness against malformed inputs.
fs/fspath · high confidence
New fstest integration testing framework
The fstest package has been restructured into a new modular testing framework. This introduces the \fstests\ package containing generic integration tests for Fs and Object interfaces, and the \runs\ package which manages test execution, configuration, and reporting (including HTML and JSON outputs). New mock implementations (\mockfs\, \mockobject\, \mockdir\) are provided to facilitate isolated testing, while \fstest/run.go\ centralizes test run lifecycle management with features like retry logic for eventual consistency and precision-based time checks.
fstest · high confidence
New generic cache library with expiration, pinning, and error handling
A new generic cache implementation is available in lib/cache, providing string-keyed storage with automatic expiration (defaulting to 5 minutes of inactivity) and configurable intervals. Users can now pin entries to prevent expiration, put values with associated errors for negative caching, and delete entries by key or prefix. The library includes comprehensive tests covering retrieval, error caching, expiration logic, and pinning behavior.
lib/cache · high confidence
New generic file handle pool for concurrent writes
A new \filepool\ package has been added to manage reusable write handles for a single remote file path. This allows multiple goroutines to write to the same file concurrently at non-overlapping offsets without sharing a single handle, which is particularly useful for backends that implement \fs.OpenWriterAter\ over a connection pool. The pool automatically reuses free handles and opens new ones on demand, ensuring thread-safe access and proper cleanup via a \Drain\ method.
lib/filepool · high confidence
New generic hashsum command with local download and stdin support
A new \hashsum\ command has been added, allowing users to generate hashes for any supported algorithm in a format compatible with standard tools like md5sum. This command introduces a \--download\ flag to force local hashing when the remote does not support the requested hash, and supports reading data from standard input (stdin) by omitting the path argument or passing a hyphen. It also includes flags for base64 output, writing results to a file, and validating against a checksum file.
cmd/hashsum · high confidence
New hasher backend for caching and computing checksums
A new 'hasher' backend has been added that wraps an existing remote to provide a local cache for file checksums. It supports importing hashes from SUM files (including a fast 'sticky' mode), dumping the cache, and automatically computing hashes for small files. Users can configure which hash types to cache, set a maximum age for cache entries, and use backend commands like 'drop', 'dump', and 'import' to manage the checksum database.
backend/hasher · high confidence
New iCloud Drive and iCloud Photos backends with SRP authentication
This change introduces the \iclouddrive\ backend, enabling access to both iCloud Drive files and iCloud Photos. It replaces previous plaintext sign-in methods with Secure Remote Password (SRP) authentication, which handles Apple ID credentials securely and manages two-factor authentication flows. The implementation includes a dedicated API client for Drive operations (listing, retrieving, and uploading files) and a comprehensive Photos service that supports browsing libraries, albums, and individual assets, including handling of various media formats and metadata. Session state, including trust tokens and service endpoints, is persisted to disk to minimize re-authentication overhead.
backend/iclouddrive/api · high confidence
New lib/encoder library for filename character substitution and quoting
The \lib/encoder\ package introduces a new configurable system for translating file names to ensure compatibility with restrictive storage systems. It provides a \MultiEncoder\ that maps reserved characters (such as slashes, quotes, and control characters) to Unicode equivalents (like fullwidth variants) and quotes others to distinguish raw from encoded forms. The library includes OS-specific default encodings for Windows, macOS, and other platforms, and adds a separate \filename\ sub-package that compresses and encodes file names using various tables (including SCSU and Huffman coding) to reduce storage size.
lib/encoder · high confidence
New lib/file package for Windows file handling and path utilities
This change introduces the lib/file package, which provides Windows-specific file operations and path utilities. It includes a custom OpenFile implementation that allows open files to be renamed or deleted by enabling FILE\_SHARE\_DELETE, and adds IsReserved to prevent using Windows reserved names (like CON, NUL, or trailing spaces) in file paths. The package also adds UNCPath to convert absolute Windows paths to long UNC format, FindUnusedDriveLetter to locate available drive letters, and PreAllocate/SetSparse functions to manage file allocation and sparse files on Windows and Linux, including proper handling of disk-full errors.
lib/file · high confidence
New listremotes command with filtering, ordering, and JSON output
A new \listremotes\ command has been added to list all remotes defined in the config file and environment variables. Users can filter results by name, type, source, or description using both positional arguments and dedicated flags (\--name\, \--type\, \--source\, \--description\), with an \--exact\ flag to enforce whole-value matching instead of the default fuzzy matching. Output can be ordered by any attribute (e.g., \--order-by type,name=descending\) and formatted as human-readable text, a long tabular view (\--long\), or machine-readable JSON (\--json\).
cmd/listremotes · high confidence
New lock-step directory traversal library for sync operations
The \fs/march\ package introduces a new library that traverses two directories in lock-step to identify source-only, destination-only, and matching entries. This component replaces the previous inline traversal logic in the sync codebase, providing a dedicated \March\ struct with callback-based results (\SrcOnly\, \DstOnly\, \Match\) and support for context cancellation, unicode normalization, and case-insensitive matching. By centralizing this logic, sync operations now rely on a reusable, testable module for comparing file trees.
fs/march · high confidence
New lsf command for script-friendly directory listings
A new \lsf\ command has been added to list directory contents in a format designed for easy parsing by scripts. It supports customizable output formats (including path, size, modification time, hashes, object IDs, MIME types, and metadata), configurable separators, CSV output, and flags to filter for files or directories only, recurse into subdirectories, and use absolute paths.
cmd/lsf · high confidence
New modular HTTP server library with comprehensive authentication and serving capabilities
The \lib/http\ package has been restructured into a new, modular HTTP server library that centralizes HTTP serving logic. This change introduces a robust authentication system supporting multiple methods: standard basic authentication (single user/password), htpasswd files (MD5, SHA1, Bcrypt), client certificate authentication via TLS, and header-based authentication for proxied setups (\--user-from-header\). The library also provides a new file serving engine (\lib/http/serve\) that handles object retrieval with support for HTTP ranges, metadata headers, and directory listings with customizable HTML templates. Additionally, it includes CORS middleware, TLS configuration, and support for Unix sockets and socket activation, providing a unified foundation for all HTTP-based serve commands.
lib/http · high confidence
New mountlib package with Linux mount validation and RC API
The \cmd/mountlib\ package now includes OS-specific mount validation logic, introducing \CheckMountReady\ on Linux to verify that a mount point is actively served by rclone using the \/proc/self/mountinfo\ API, while non-Linux platforms fall back to a no-op. Additionally, the package exposes Remote Control (RC) commands (\mount/mount\, \mount/unmount\, \mount/listmounts\, \mount/types\) that allow users to create, list, and remove mounts programmatically via the API, supporting both flat and nested option structures for VFS and mount configurations.
cmd/mountlib · high confidence
New nfsmount command for mounting NFS shares on Unix systems
A new \nfsmount\ command has been added, allowing users to mount remote file systems via NFS on Unix-like operating systems (Linux, macOS, FreeBSD, OpenBSD) without requiring FUSE. This feature introduces a dedicated mount mechanism that starts an internal NFS server and uses the system's native \mount\ utilities (with optional \sudo\ support) to attach the share. It supports mounting specific subpaths of the remote via the \--nfs-mount-path\ flag and includes platform-specific handling for mount options (such as TCP and port settings) and unmounting (using \diskutil\ on macOS and \umount\ elsewhere).
cmd/nfsmount · high confidence
New ranges library for tracking byte ranges in partially downloaded files
Added a new \lib/ranges\ package that provides a \Ranges\ type to manage and track byte ranges, specifically designed for scenarios involving partially downloaded files. The library includes functionality to insert, coalesce, and clip ranges, as well as methods to find intersections and identify which specific byte ranges are present or absent in a collection.
lib/ranges · high confidence
New rcd command for dedicated remote control server
A new \rcd\ command has been introduced to run rclone in a mode dedicated solely to listening for remote control (rc) API commands. This command initializes the rc server via the refactored \rcserver\ package, optionally serves a specified local directory for GET requests, and integrates systemd notification support for proper service lifecycle management. It enforces that the general \--rc\ flag is not supplied simultaneously, ensuring a clean separation of concerns for users managing rclone via the API.
cmd/rcd · high confidence
New rclone archive command introduced in v1.72
A new \rclone archive\ command has been added, allowing users to create, list, and extract archive files (such as zip, tar, and various compressed formats) from and to remote storage. This feature is introduced in version 1.72 and includes support for archiving to stdout, enabling integration with other command-line tools.
cmd/archive · high confidence
New rclone archive extract command
Users can now extract archive files to a destination using the new \rclone archive extract\ command (introduced in v1.72). This feature auto-detects the archive format, supports filtering specific files during extraction, and includes path sanitization to prevent directory traversal attacks ([CVE redacted]) by stripping leading \./\ prefixes and rejecting unsafe paths like \../\.
cmd/archive/create, cmd/archive/extract · high confidence
New rclone gui command with embedded web interface and flexible serving options
The \rclone gui\ command (introduced in v1.74) launches a new web-based GUI for rclone, embedding the \rclone-web\ interface (version 1.1.12) directly into the binary for reproducible builds. Users can now serve the GUI from the embedded assets, or override it by passing a path to a local directory or a \dist.zip\ archive. The command starts both the GUI server and the RC API server on separate localhost ports, automatically generating credentials and opening the browser. It supports explicit binding via \--addr\ and \--api-addr\, allows disabling authentication with \--no-auth\, and respects the \--rc-allow-origin\ flag for cross-origin request handling instead of always deriving it from the bind address.
cmd/gui · high confidence
New reader utilities for context handling, gzip, and seeking
The lib/readers package now includes several new reader adapters and utilities. NewContextReader allows readers to fail immediately when a context is cancelled. NewGzipReader wraps gzip.Reader to ensure the underlying stream is closed properly. NoCloser and NoCloserNotify prevent io.Reader instances from being accidentally closed by HTTP transports, with NoCloserNotify providing a callback to detect when the body is finished. FakeSeeker and NoSeeker adapt io.Reader to io.ReadSeeker, with FakeSeeker allowing pre-set length and NoSeeker returning an error on seek. RepeatableReader provides a thread-safe, seekable cache for reading data multiple times. NewPatternReader generates deterministic byte patterns for testing, and NewCountingReader tracks bytes read.
lib/readers · high confidence
New remote control commands for cache management, option configuration, and filesystem access
The remote control interface now includes new commands to manage the filesystem cache (\fscache/clear\, \fscache/entries\), inspect and modify global configuration options (\options/blocks\, \options/get\, \options/info\, \options/set\, \options/local\), and retrieve filesystem instances by name or JSON config (\GetFsNamed\, \GetFsNamedFileOK\). These additions allow users to programmatically control caching behavior, view and update runtime settings, and access remote filesystems directly through the RC API.
fs/rc · high confidence
New scan package for concurrent directory tree building in NCDU
The \cmd/ncdu/scan\ package introduces a new concurrent scanning mechanism that builds an in-memory directory tree from remote filesystems. This change adds support for tracking modification times and correctly handles files with unknown sizes (where backends return -1) by counting them separately without inflating the total size. It also improves error handling by propagating read errors through the directory hierarchy rather than aborting immediately, allowing the user interface to highlight problematic entries. Unit tests are included to verify size accumulation, unknown-size handling, and error propagation.
cmd/ncdu/scan · high confidence
New selfupdate command for in-place binary updates
Rclone now includes a \selfupdate\ command that allows users to update the binary in place. The command supports checking for the latest stable or beta release, installing specific versions, and downloading \.deb\ or \.rpm\ packages on Linux. It verifies downloads using PGP-signed SHA256 checksums and prevents updates that would discard FUSE capabilities in static builds. A \noselfupdate\ build tag is available to exclude this functionality from the binary.
cmd/selfupdate · high confidence
New static and memory object implementations with metadata support
The fs/object package now provides StaticObjectInfo and MemoryObject types, allowing users to create and manipulate file objects entirely in memory without a backend filesystem. StaticObjectInfo supports setting metadata and MIME types via WithMetadata and WithMimeType methods, while MemoryObject allows reading, seeking, and updating content in memory. These types implement the standard fs.Object and fs.ObjectInfo interfaces, enabling their use in operations that require object handling without persistent storage.
fs/object · high confidence
New structs library for reflection-based field copying
A new \lib/structs\ package has been added, providing two reflection-based functions for manipulating struct fields: \SetFrom\, which copies values between structs with matching field names and assignable types (useful for merging auto-generated cloud storage structs), and \SetDefaults\, which copies public members from one struct to another of the same type (useful for copying configuration from standard library types like \http.Transport\ that contain private mutexes).
lib/structs · high confidence
New sync report flags for detailed file change logging
Sync operations now support a set of new flags that write detailed reports of file changes to specified output files. Users can use flags like \--combined\, \--missing-on-src\, \--missing-on-dst\, \--match\, \--differ\, \--error\, and \--dest-after\ to track exactly which files were identical, missing, different, or encountered errors during the sync. The \--dest-after\ flag specifically generates a list of files present on the destination post-sync, using a format similar to the \lsf\ command, allowing users to verify the final state of their remote storage.
fs/operations/operationsflags · high confidence
New test commands for generating test data and benchmarking remote speeds
Added the \rclone test makefiles\ command to generate random file hierarchies with configurable sizes, depths, and content patterns (zero-filled, sparse, ASCII, patterned, or chargen), and the \rclone test speed\ command to benchmark remote upload and download performance across small, medium, and large file sizes with optional JSON output.
cmd/test/makefiles · high confidence
New transfer accounting utility for server-side transfers
A new \transferaccounter\ package has been added to provide utilities for accounting server-side transfers. It introduces a \TransferAccounter\ struct that tracks byte counts via a provided callback function, supporting operations to start, add bytes, and reset the counter. The accounter is integrated into the Go context for easy retrieval, with a null implementation provided to handle cases where no accounter is present, ensuring safe usage without panics.
lib/transferaccounter · high confidence
New union backend policies for file selection and creation
The union backend now includes a comprehensive set of new policies in the \backend/union/policy\ package, allowing users to control how files are selected across multiple upstream remotes. These include \epff\ (existing path, first found), \epall\ (existing path, all found), \eplfs\ (least free space), \eplno\ (least number of objects), \eplus\ (least used space), \epmfs\ (most free space), \eprand\ (random), and \newest\ (largest modification time). Additionally, non-existing-path variants like \ff\ (first found), \lfs\, \lno\, \lus\, \mfs\, and \rand\ are provided for creation operations. These policies define behavior for Action, Create, and Search categories, enabling granular control over which remote handles file modifications, creations, and lookups based on space usage, object counts, timestamps, or random selection.
backend/union/policy · high confidence
New versioning library for timestamp-based file names
A new \lib/version\ package has been introduced to handle versioning of file names using timestamp-based version strings. This library provides functions to add a version suffix (e.g., \-v2006-01-02-150405.000\) to file names, remove existing version strings to retrieve the original name and timestamp, and check if a file name contains a version string. It correctly handles edge cases such as files with no extension, hidden files (starting with a dot), and files with multiple dots in the name. This refactoring centralizes version handling logic, likely to support features like B2 versioning as indicated by commit messages, ensuring consistent behavior across the application.
lib/version · high confidence
New zip archive backend with security and correctness fixes
A new zip archiver backend has been added to the archive system, allowing users to read zip files stored on cloud storage as if they were local directories. This implementation includes critical security hardening against zip-slip path traversal attacks ([GHSA redacted]) by sanitizing entry names and skipping those that escape the archive namespace. It also corrects behavioral issues where directory-named entries (like "." or "/") previously hid other files or caused confusion, and ensures that listing a zip directory multiple times returns consistent results without corruption. The backend properly isolates the root directory boundary so that sibling directories sharing a name prefix are not exposed.
backend/archive/zip · high confidence
OneDrive API type definitions for metadata and sharing
The OneDrive backend now includes explicit Go type definitions in \backend/onedrive/api/types.go\ to support richer metadata and sharing capabilities. These types define structures for file hashes (including QuickXorHash), package types (such as OneNote), and detailed sharing permissions (including link scopes, expiry, and invitations), enabling the backend to handle advanced OneDrive for Business features like shared folder support and granular link creation.
backend/onedrive/api · high confidence
OneDrive backend adds system metadata and permissions support
The OneDrive backend now supports reading and writing system metadata (such as content type, modification time, and creation user) and file/folder permissions via the \--metadata-mapper\ tool. Users can manage access controls by adding, updating, or removing permissions, with the \--onedrive-metadata-permissions\ flag controlling read/write access. This feature is available for both OneDrive Personal and Business accounts, though some properties like descriptions are limited to Personal, and permissions are stored in JSON format compatible with the Microsoft Graph API.
backend/onedrive · high confidence
Prometheus metrics endpoint for the remote control server
The remote control server now exposes a dedicated Prometheus metrics endpoint at /metrics, configurable via the --metrics-addr flag. This new service runs on a separate listener, allowing users to scrape operational statistics (such as bytes transferred, files checked, and errors) independently of the main RC API, and supports its own authentication and template configuration.
fs/rc/rcserver · high confidence
Remote control interface for managing serve servers
Users can now start, stop, and list active serve servers (HTTP, WebDAV, FTP, SFTP, NFS, etc.) via the rclone remote control (rc) interface using the new \serve/start\, \serve/stop\, \serve/list\, \serve/stopall\, and \serve/types\ commands. This allows programmatic management of background file servers without needing separate CLI processes, with servers identified by unique IDs and configurable via rc parameters.
cmd/serve · high confidence
Shell auto-completion now supports Fish and fixes PowerShell non-ASCII characters
The \rclone completion\ command (with \genautocomplete\ as an alias) now generates scripts for Fish and Zsh in addition to Bash and PowerShell. The PowerShell completion script includes a fix to force UTF-8 output encoding, preventing corruption of non-ASCII remote names on Windows systems using non-UTF-8 code pages. All completion scripts can be written to a specified file or output to stdout.
cmd/genautocomplete · high confidence
Squashfs archive backend added with improved robustness
The archive backend now supports reading Squashfs images (files with the .sqfs extension). This new capability allows users to browse and access files within Squashfs archives stored on any configured remote. The implementation includes a file-handle caching mechanism to optimize read performance and incorporates safety measures to prevent crashes when encountering malformed or corrupt images, converting internal parser panics into standard errors.
backend/archive/squashfs · high confidence
Standardize development environment with AI agent guidance and linting configuration
The repository now includes configuration files to standardize the development environment and code quality checks. A \.golangci.yml\ file configures golangci-lint v2 with explicit linters (errcheck, govet, staticcheck, gocritic, revive, etc.) and formatters (goimports). A \.markdownlint.yml\ file enforces consistent Markdown styling for documentation. Additionally, \AGENTS.md\ and \CLAUDE.md\ provide guidance for AI coding assistants, outlining project conventions, architecture, and commit message standards to support AI-assisted contributions.
(repo-wide) · high confidence
Support for SharePoint cookie-based authentication in WebDAV
Users can now authenticate to SharePoint WebDAV endpoints using cookie-based authentication. This change introduces a new \odrvcookie\ package that handles the retrieval and renewal of authentication cookies (FedAuth and rtFa) required by SharePoint. It supports multiple Microsoft cloud regions (com, cn, us, de) by mapping the endpoint's top-level domain to the correct token service URL, and automatically renews cookies to maintain persistent access.
backend/webdav/odrvcookie · high confidence
Sync command now supports creating empty source directories and logging results
The sync command has been updated to include the \--create-empty-src-dirs\ flag, which allows users to create empty directories in the destination that exist in the source but contain no files. Additionally, the command now supports logger flags (such as \--log-file\) to store the results of the sync operation, enabling better tracking and auditing of synchronization activities.
cmd/sync · high confidence
Sync, copy, and move operations now support remote control (rc) commands and configurable transfer ordering
Users can now invoke sync, copy, and move operations via the remote control interface (rc) using the new sync/sync, sync/copy, and sync/move endpoints, which accept parameters like srcFs, dstFs, and createEmptySrcDirs, and can return detailed reports on combined, missing, matching, differing, and errored files. Additionally, the sync engine now supports the --order-by flag, allowing transfers to be sorted by criteria such as name, size, or modtime (with ascending/descending/mixed modes), implemented via a new pipe-based queue system that replaces the previous container/heap dependency with github.com/aalpar/deheap.
fs/sync · high confidence
Union backend adds min\_free\_space configuration option
The union backend now supports a new \min\_free\_space\ configuration option, allowing users to specify a minimum free space threshold for write operations. This option is defined in the common options structure alongside existing policies (action, create, search) and upstream definitions, enabling finer control over storage allocation behavior within union mounts.
backend/union/common · high confidence
Union backend now supports multiple writable remotes and parallel operations
The union backend has been rewritten to support multiple writable upstreams, allowing files to be written to several backends simultaneously based on the configured action policy. This change introduces parallel execution for operations like file updates, removals, and metadata changes across all candidate upstreams, significantly improving performance and reliability. It also adds a \min\_free\_space\ option to control which remotes are eligible for writes in space-aware policies, and implements optional interfaces such as Move, DirMove, and Copy to leverage capabilities of underlying backends.
backend/union · high confidence
Upstream abstraction supports read-only, no-create, and writeback modes
The \backend/union/upstream\ package now introduces a structured \Fs\ wrapper that interprets remote configuration suffixes to control behavior: appending \:ro\ marks the upstream as read-only (disabling both writing and creation), \:nc\ allows writing but prevents new file creation, and \:writeback\ designates the remote as a write-back cache target. This change enables the union backend to manage multiple writable remotes and implement caching strategies by delegating specific write operations to designated upstreams, while also ensuring created backends are pinned in the cache until their parents are finalized.
backend/union/upstream · high confidence
WebDAV backend adds chunked upload support for Nextcloud and tus protocol
The WebDAV backend now supports chunked uploads for large files. For Nextcloud, it implements the native chunking protocol, allowing users to configure the chunk size via the \nextcloud\_chunk\_size\ option to improve upload performance and reliability. Additionally, it adds support for the tus resumable upload protocol, enabling chunked uploads for ownCloud Infinite Scale and other tus-compatible servers. This change introduces new files (\chunking.go\, \tus.go\, \tus-upload.go\, \tus-uploader.go\, \tus-errors.go\) to handle the upload logic and integrates with the existing test suite to verify chunked upload functionality.
backend/webdav · high confidence
WebDAV server now supports HTTP directory listings and custom templates
The WebDAV serve command now handles standard HTTP GET requests for directory listings and file content, in addition to the WebDAV protocol. This allows users to browse their remote storage via a web browser or standard HTTP clients. The directory listing output is now customizable using the new --template flag, which accepts an HTML template file (defaulting to a simple listing). This feature is implemented in the cmd/serve/webdav package, which now includes comprehensive integration tests and golden files to verify the HTTP response behavior.
cmd/serve/webdav · high confidence
fshttp: New dialer, transport, and testing infrastructure
The fshttp package now includes a new dialer (dialer.go) that supports DSCP traffic class settings and applies bandwidth limiting and idle timeouts to connections. A fault injector (fault.go) has been added to allow tests to simulate transient HTTP failures. The transport layer now exposes Prometheus metrics for HTTP status codes (prometheus.go) and supports customizing the HTTP client. Comprehensive tests (dump\_test.go, fault\_test.go, http\_test.go) verify retryable error detection, selective dumping of failed transactions, and client certificate handling.
fs/fshttp · high confidence
lsd command gains -R flag for recursive listing
The lsd command now supports a -R (recursive) flag, allowing users to list directories across all nested levels rather than just the immediate path. This change also includes the introduction of the ls command and refactors the command definitions into separate packages.
cmd/lsd · high confidence
pcloud API type definitions added
The pcloud backend now includes a new \types.go\ file defining the Go structs for API responses, including \Item\, \Error\, \Hashes\, and various response wrappers for file operations, checksums, and public links.
backend/pcloud/api · high confidence
Security
FTP backend: security fix for command injection and new TLS options
The FTP backend now sanitizes filenames to prevent command injection via raw CR/LF characters in path arguments, addressing a potential security vulnerability. Additionally, users can now configure FTP over TLS (FTPS) using explicit or implicit modes, disable TLS 1.3 for compatibility with buggy servers, allow insecure TLS ciphers, and control TLS session caching. The backend also introduces options to disable EPSV, MLSD, and UTF-8 modes, and adds support for SOCKS5 and HTTP proxies.
backend/ftp · high confidence
Architecture
Azure Blob storage authentication logic extracted to shared library
The authentication and client creation logic for Azure Blob storage has been refactored into a new shared \backend/azureblob/auth\ package. This change consolidates common authentication options (such as account name, keys, SAS URLs, and service principal settings) into a single library, allowing both Azure Blob and Azure Files backends to reuse the same credential handling code. Users will not notice a change in functionality, but the underlying structure is now more maintainable and consistent across Azure storage backends.
backend/azureblob/auth · high confidence
Consolidated backend registration in a single import package
The \backend/all\ package now serves as the central registration point for all supported storage backends. By importing this package, users can access the full suite of available remote types—including cloud providers like Google Drive, Dropbox, and OneDrive, as well as specialized backends like Combine, Union, and Archive—without needing to manually import individual backend packages. This change simplifies the dependency graph for applications that require access to the complete set of rclone backends.
backend/all · high confidence
Consolidation of all CLI commands into a single import package
The \cmd/all\ package now serves as the central registry for all rclone subcommands, importing every available command (such as \mount\, \serve\, \bisync\, and \test\) via blank imports to ensure they are registered with the CLI framework. This structural change replaces the previous mechanism where commands were imported individually or in smaller groups, providing a single point of inclusion for the entire command set.
cmd/all · high confidence
Extracted obscure and reveal functions into a dedicated package
The Obscure and Reveal commands, used for encrypting and decrypting configuration values via AES-CTR, have been moved from the main config package into a new, standalone \fs/config/obscure\ package. This refactoring isolates the cryptographic logic, making it easier to maintain and test independently, while also including comprehensive tests for the encryption, decryption, and error-handling paths.
fs/config/obscure · high confidence
Introduce filterflags package for centralized flag registration
A new \filterflags\ package has been added to centralize the registration of filter-related command-line flags. This change extracts the logic for adding non-file-system-specific flags into a dedicated module, which now delegates to the \filter.OptionsInfo\ structure via the \flags.AddFlagsFromOptions\ helper. This refactoring supports the broader effort to modularize the \fs\ package and decouple filter configuration from specific filesystem implementations.
fs/filter/filterflags · high confidence
New centralized global flag configuration package
A new \fs/config/configflags\ package has been introduced to centralize the definition and processing of global command-line flags. This change decouples global flag handling (such as logging levels, config paths, cache/temp directories, HTTP headers, metadata settings, and network binding) into a dedicated module, allowing it to be replaced or extended more easily. Users will see this as the underlying infrastructure for existing global options, ensuring consistent parsing and validation of these settings across the application.
fs/config/configflags · high confidence
Refactor rclone command internals into the cmd package
The internal implementation of the rclone CLI has been moved into the \cmd\ package to allow it to be imported and reused by external tools. This refactoring introduces new files for core functionality: \cmd.go\ (main command logic and file system creation), \completion.go\ (shell auto-completion), \help.go\ (help and flag display), \progress.go\ (progress bar handling), and platform-specific handlers for self-update and SIGINFO signals.
cmd · high confidence
Refactor rmdir command into its own package
The rmdir command implementation has been moved from the central cmd package into a dedicated cmd/rmdir package. This change improves code organization by isolating the command's logic, including its definition, argument checking, and execution flow, into a separate module while maintaining the same user-facing behavior for removing empty directories.
cmd/rmdir · high confidence
Behavioural changes
Centralized exit status codes with new transfer limits
Exit status codes have been moved to a dedicated package to provide a single source of truth for error handling. This change introduces a new exit code (10) for when network I/O exceeds the transfer quota, and updates the exit code for syntax and usage errors from 1 to 2 to better distinguish argument mistakes from general failures.
lib/exitcode · high confidence
Centralized logging flag configuration
The logging command-line flags are now managed through a dedicated logflags package, which provides a single AddFlags function to register options with the application's flag set. This change consolidates the flag registration logic, ensuring that log configuration options are consistently added to the command-line interface.
fs/log/logflags · high confidence
Check command now supports hash file verification and download-based checking
The check command has been refactored to support new verification modes. Users can now use the --checkfile flag to verify files against a SUM file containing hashes, enabling validation against external checksum sources. Additionally, the --download flag allows checking by downloading data from both remotes and comparing it on the fly, which is useful for remotes that do not support hashes or for verifying actual data integrity beyond metadata. The command also now logs the specific hash type being used for comparisons.
cmd/check · high confidence
Clarifies recursive listing behavior and bucket-based remote semantics in help text
The help documentation for list commands (ls, lsl, lsd, lsf, lsjson) has been updated to clarify that lsd, lsf, and lsjson do not recurse by default and require the -R flag to do so, whereas ls and lsl recurse by default. It also explains that on bucket-based remotes (such as S3, GCS, and B2), directories are represented as key prefixes, meaning a non-recursive listing shows each prefix as a single entry rather than the objects contained within it.
cmd/ls/lshelp · high confidence
Copy command refactored with new flags and direct file handling
The copy command has been restructured into its own package and now supports the --create-empty-src-dirs flag to create empty directories on the destination, as well as logger flags to store sync results. Additionally, the implementation now copies single files directly rather than relying on a --files-from workaround, improving efficiency for individual file transfers.
cmd/copy · high confidence
Crypt backend refactored to use a dedicated Cipher struct
The crypt backend implementation has been restructured to use a dedicated \Cipher\ struct for handling encryption and decryption logic, replacing the previous \NewFs\-based approach. This change consolidates the cryptographic operations, including filename encryption modes (standard, obfuscated, off) and encoding methods (base32, base64, base32768), into a single reusable component. The refactoring improves code clarity and maintainability while preserving existing functionality for users, such as directory name encryption, data encryption options, and custom suffixes.
backend/crypt · high confidence
DLNA service descriptors and root template moved to static assets
The DLNA server now serves its UPnP service control protocol descriptors (ConnectionManager, ContentDirectory, X\_MS\_MediaReceiverRegistrar) and the root device description template from the static assets directory. This change ensures that the XML definitions for these services are correctly bundled and served, which is essential for DLNA clients to discover and interact with the media server properly.
cmd/serve/dlna/data/static · high confidence
DLNA static assets are now embedded in the binary
The DLNA server's static files—including the root descriptor template, UPnP XML descriptors, and device icons—are now compiled directly into the application binary using the vfsgen tool. This change replaces the previous method of loading these files from the filesystem at runtime, ensuring the server operates correctly regardless of the working directory and simplifying deployment by removing external file dependencies.
cmd/serve/dlna/data · high confidence
Daemonization support for Unix platforms with automount compatibility
The lib/daemonize package now provides a functional implementation for Unix systems, enabling rclone to run as a background daemon. This change specifically disables the setsid system call during process creation to maintain the process group ID, ensuring compatibility with automount services that rely on detecting the mounting process by its group. On non-Unix platforms (including AIX), the package remains a stub that returns an error indicating daemon mode is not supported.
lib/daemonize · high confidence
Dedupe command now supports listing duplicates and hash-based detection
The dedupe command has been updated to include a new 'list' mode via the --dedupe-mode flag, which allows users to identify duplicate files and directories without making any changes. Additionally, the command now supports the --by-hash flag, enabling duplicate detection based on file content hashes rather than just filenames, which is useful for backends that do not support duplicate names. The command also now merges directories with identical names before processing files.
cmd/dedupe · high confidence
Deprecation of the cachestats command
The \rclone cachestats\ command is now deprecated and hidden from standard help listings. When executed, it displays a warning message directing users to use \rclone backend stats \<remote\>\ instead. The command remains functional for backward compatibility, continuing to output cache statistics in JSON format for cache remotes, but will no longer be actively promoted.
cmd/cachestats · high confidence
Directory listing now enforces root confinement and supports on-disk sorting
Directory listings now automatically filter out any entries whose paths escape the configured root directory, preventing potential traversal vulnerabilities from malicious or buggy backends. Additionally, the listing mechanism now supports sorting large directories on disk via an external sorter when the entry count exceeds the configured cutoff, reducing memory usage for massive directory trees.
fs/list · high confidence
Directory walking now respects context cancellation and supports recursive listing
The directory walking logic in fs/walk has been updated to stop traversal immediately when the context is cancelled, preventing hangs on slow or infinite directory structures. Additionally, the package now implements walk.ListR, allowing the system to use efficient recursive listing (ListR) APIs on backends that support them, falling back to standard directory walking when necessary.
fs/walk · high confidence
Dropbox backend refactored to use v6 SDK and new batcher
The Dropbox backend has been updated to use the dropbox-sdk-go-unofficial v6 library and now utilizes the shared lib/batcher for handling upload sessions. This change introduces a new batcher.go file to manage batch commits and updates the main dropbox.go implementation to integrate with the new SDK and batching logic, which improves upload reliability and performance.
backend/dropbox · high confidence
Enhanced HTTP client security and range-request validation
The lib/rest library now includes stricter security measures for HTTP redirects, specifically refusing HTTPS-to-HTTP downgrades to prevent credential leakage, and offers options to preserve HTTP methods (like PROPFIND) during redirects. It also introduces validation for HTTP range requests by parsing and checking Content-Range headers to ensure responses match the requested byte ranges, and adds utilities to parse file sizes from response headers.
lib/rest · high confidence
Enhanced version reporting with OS, kernel, and build details
The \lib/buildinfo\ package now provides detailed system and build information via the \version\ command. It reports the OS version, kernel version, and bitness (e.g., "64 bit") for non-Windows platforms, and adds friendly version names (like "22H2") for Windows 10/11 by reading registry keys. It also detects and reports the specific ARM architecture compatibility level (ARMv5, v6, or v7) based on CPU features, and displays build tags (such as \cgo\, \snap\, \noselfupdate\) and linking type (static vs. dynamic) in the version output.
lib/buildinfo · high confidence
Extracted fs cache into a standalone package with canonicalization and pinning
The filesystem caching logic has been factored out of the remote configuration package into a dedicated \fs/cache\ package. This change introduces canonical name lookups to ensure consistent cache keys, adds \Pin\ and \Unpin\ methods to control backend lifecycle (preventing premature shutdown), and implements specific handling for \fs.ErrorIsFile\ to correctly cache file references. Users benefit from more robust backend management, particularly in remote control contexts where backends are now pinned until jobs complete, and improved accuracy when accessing file-based remotes.
fs/cache · high confidence
Filtering engine refactored with new options and enhanced glob support
The file filtering system has been restructured to support new configuration options and improved pattern matching. Users can now use the \--files-from-raw\ flag to read file lists without comment processing, \--files-from0\ for NUL-delimited input, and \--ignore-case\ for case-insensitive filtering. The glob syntax now supports nested alternates (e.g., \a{b,{c,d}}e\) and raw regular expressions via the \{{ ... }}\ syntax. Additionally, metadata filtering rules (\--metadata-include\, \--metadata-exclude\) and deterministic file selection via \--hash-filter\ are now available. The internal filter configuration has been deglobalized to use context, and the \--files-from\ option now prevents mixing with other filter rules to avoid ambiguity.
fs/filter · high confidence
Google Drive backend migration to API v3 with enhanced metadata and upload reliability
The Google Drive backend has been migrated from the legacy Drive API v2 to the current Drive API v3, bringing improved support for Shared Drives (formerly Team Drives) and modern API features. This update introduces comprehensive read/write metadata support, allowing users to manage file permissions, descriptions, starred status, and folder colors directly through rclone. Upload reliability is significantly improved through the implementation of resumable multipart uploads with chunk buffering, ensuring that transient network errors do not corrupt data or lose progress. Additionally, the backend now supports shortcut resolution, better handling of Google Docs export/import formats, and new configuration flags like \--drive-impersonate\ for service accounts and \--drive-stop-on-upload-limit\ to respect quota constraints.
backend/drive · high confidence
HTTP server implementation refactored to use lib/http and VFS
The \serve http\ command now uses the shared \lib/http\ server infrastructure and the VFS layer for file serving, replacing the previous direct filesystem implementation. This change introduces support for VFS caching modes, Range header requests, and custom HTML templates via the \--template\ flag, while also adding \--disable-zip\ and \--disable-dir-list\ options to control directory listing and zip download behavior.
cmd/serve/http · high confidence
Improved WebDAV response parsing and error reporting
The WebDAV backend now handles mixed property statuses in multi-status responses more robustly by treating any 2xx status as successful, ensuring that resources with partial errors are still processed correctly. It also supports additional time formats (including RFC3339 and variants without leading zeros) to fix compatibility issues with various servers, and enhances error messages by including exception types and status codes for better debugging. Additionally, the API now parses MD5 and SHA1 checksums from WebDAV responses, enabling hash verification for backends like Owncloud and Nextcloud.
backend/webdav/api · high confidence
Improved terminal color support and Windows console management
The terminal library now enables native ANSI/VT100 color support on Windows 10+ by switching to the mattn/go-colorable library and enabling virtual terminal sequences, replacing the previous Azure/go-ansiterm dependency. It also introduces a new --no-console flag for Windows that hides the console window using kernel32.dll, and adds the ability to update the terminal window title with progress information via the --progress-terminal-title flag.
lib/terminal · high confidence
Introduce pluggable INI-based config file storage
The configuration system now supports a new, pluggable storage backend that persists settings in a standard INI file format. This change introduces the \configfile\ package, which handles loading, saving, and reloading configuration data from disk, including support for encrypted config files and automatic reloading when the file changes externally. It also ensures safe file operations by using temporary files and backups during saves, preserving file permissions and ownership (on Unix systems), and correctly handling symbolic links.
fs/config/configfile · high confidence
Introduce state-based backend configuration system
The fs package now uses a new state-based configuration system for backend setup, replacing the previous global variable approach. This change introduces new types like ConfigIn and ConfigOut to manage the interactive config flow, allowing different frontends (such as the API or web interface) to drive the configuration process. It also adds utilities for handling ephemeral config keys, password redaction, and provider matching, while moving configuration logic out of global state to improve testability and modularity.
fs · high confidence
Logging subsystem refactored to use Go's log/slog with new output targets
The logging implementation in fs/log has been rewritten to use the Go standard library's log/slog package, replacing the previous logging mechanism. This change introduces support for logging to the Windows Event Log (via the --windows-event-log-level flag) and adds support for syslog LOCAL facilities. It also improves the reliability of systemd integration and ensures that stderr is correctly redirected to the log file on panic across different operating systems.
fs/log · high confidence
New path sanitization library for archive extraction
A new \lib/sanitize\ package has been introduced to validate and clean untrusted path names, specifically targeting rclone remote paths used during archive extraction. The package provides two functions: \Path\, which cleans slash-separated paths and rejects any components containing \..\ to prevent Zip Slip (path traversal) attacks, and \Leaf\, which ensures individual directory entries are safe single components by rejecting empty names, \.\/\..\, and embedded slashes. This change adds defensive validation to ensure that extracted files remain within their intended directory structure.
lib/sanitize · high confidence
OAuth utility library refactored with client credentials support and remote control
The lib/oauthutil package has been restructured to support the OAuth 2.0 client credentials flow alongside the existing authorization code flow, allowing backends to authenticate without user interaction. The library now exposes remote control commands (config/oauthstatus and config/oauthstop) to monitor and terminate active OAuth sessions, and introduces a background token renewal mechanism to prevent upload failures during token expiry. Additionally, the web-based authorization response is now rendered using Go templates, and the library includes improved error handling for expired tokens and security fixes for multi-user environments.
lib/oauthutil · high confidence
Purge command now exits with an error if filters are configured
The purge command now prevents accidental data loss by exiting with a fatal error if any include/exclude filters are active. Since purge is designed to remove all contents unconditionally, it ignores filters; this change ensures users are explicitly warned when filters are set, rather than silently proceeding with a full deletion that might not align with their filtered expectations.
cmd/purge · high confidence
Redesigned command documentation generation with Hugo-compatible frontmatter and alias redirects
The gendocs tool has been rewritten to produce markdown documentation optimized for the Hugo static site generator. Key changes include adding structured frontmatter (title, description, aliases, annotations) to each command page, automatically generating URL aliases for command variants to support redirects, and inserting links to a dedicated global flags page within the command documentation. The tool now also handles platform-specific exclusions (e.g., skipping mount/NFS docs on Windows/macOS where build tags are missing) and regularizes header levels and section structures for consistent rendering.
cmd/gendocs · high confidence
Refactor Box API types and add upload preflight support
The Box backend API layer has been refactored to improve reliability and performance. New type definitions in types.go now correctly parse file and directory sizes as floating-point numbers, addressing issues with large numbers (e.g., 1.0e+18) that previously caused unmarshaling errors. The system now supports upload preflight checks via PreUploadCheck and PreUploadCheckResponse structs, allowing the backend to verify upload capabilities before transferring data. Additionally, the Item struct includes an OwnedBy field to support filtering items by owner, and the Error struct provides more detailed context information for better error reporting.
backend/box/api · high confidence
Refactor fs/operations into modular files and add check command support
The fs/operations package has been restructured into separate files (check.go, copy.go, dedupe.go, logger.go, lsjson.go, etc.) to improve maintainability. This change introduces a new check command implementation with one-way support and detailed reporting of matching, differing, and missing files. The copy operation now supports server-side copies across different configurations and includes multi-threaded copy improvements. The dedupe command has been enhanced with additional modes (first, newest, oldest, largest) and better handling of duplicate files. The lsjson command now supports metadata output and improved performance. These changes provide users with more granular control over file operations and better visibility into sync and check results.
fs/operations · high confidence
Refactored accounting package into modular components
The fs/accounting package has been restructured into separate files (accounting.go, stats.go, stats\_groups.go, token\_bucket.go, etc.) to improve maintainability and isolate concerns. This refactoring introduces a stats grouping system that allows remote control (rc) of bandwidth limits and stats retrieval per group, adds Prometheus metrics support for monitoring transfer activity, and implements a more robust token bucket limiter with configurable burst sizes and signal-based toggling on Unix systems. The change also standardizes the stats interface and improves the accuracy of transfer speed calculations and ETA estimates.
fs/accounting · high confidence
Refactored configuration system with pluggable storage and daemon key handoff
The configuration subsystem in fs/config has been restructured to support pluggable storage backends via a new Storage interface, replacing the previous monolithic implementation with a thread-safe in-memory default storage. This change introduces a secure key-handoff mechanism for encrypted configurations when running in daemon mode: the parent process writes the obscured config key to a temporary file (referenced by the \_RCLONE\_CONFIG\_KEY\_FILE environment variable), which the child daemon process reads and then deletes, ensuring the --password-command is not executed twice. The refactor also includes new remote control (rc) endpoints for managing configuration (config/unlock, config/dump, config/get, config/listremotes, config/providers, config/create, config/update, config/password, config/unset, config/delete) and adds support for custom authorization templates via the authorize command.
fs/config · high confidence
Refactored error handling with platform-specific out-of-space detection
The fserrors package has been restructured to improve error classification and platform support. A new \IsErrNoSpace\ function now correctly identifies disk-full conditions across operating systems, handling \syscall.ENOSPC\ on Unix and specific Windows error codes (\ERROR\_DISK\_FULL\, \ERROR\_HANDLE\_DISK\_FULL\) via platform-specific build tags. The core error logic now uses \liberrors.Walk\ to inspect wrapped errors for retry, fatal, and no-retry behaviors, ensuring that underlying causes are correctly identified even when errors are deeply nested. Additionally, the list of retriable network errors has been expanded to include more Windows-specific socket errors (such as \WSAECONNREFUSED\ and \WSAETIMEDOUT\) to improve resilience during transfers.
fs/fserrors · high confidence
Refactored pacer into modular components with new calculators and concurrency controls
The pacer logic has been restructured into separate files (pacer.go, pacers.go, tokens.go) and a new caller package for stack inspection. This introduces a pluggable Calculator interface allowing distinct pacing strategies, including a new ZeroDelayCalculator, an AzureIMDS-specific pacer, and a GoogleDrive pacer that now uses a rate limiter with a default burst of 100. Concurrency is now managed via a TokenDispenser and configurable max connections, while the default pacer's sleep time is re-read after waiting for tokens to prevent staleness issues.
lib/pacer · high confidence
S3 backend rewritten for AWS SDK v2 with provider-driven configuration and security hardening
The S3 backend has been completely rewritten to use the AWS SDK v2, introducing a new provider-driven configuration system where provider-specific settings (regions, endpoints, storage classes, quirks) are defined in embedded YAML files and loaded at runtime. This enables seamless support for a wide range of S3-compatible providers (including IBM COS, Cloudflare R2, Alibaba OSS, and many others) without code changes. The rewrite also introduces significant security improvements by stripping sensitive headers (such as authorization tokens and SSE-C keys) on cross-host HTTP redirects to prevent credential leakage, and adds new authentication methods like IBM IAM signing. Users benefit from improved reliability, better memory management for multipart uploads, and expanded provider compatibility.
backend/s3 · high confidence
SFTP backend rewritten with external SSH support and multi-thread uploads
The SFTP backend has been completely rewritten to support using an external SSH binary (via the --sftp-ssh flag) alongside the internal Go SSH library, providing better compatibility with various server configurations. It now includes support for multi-threaded uploads via --sftp-multithread-upload, which significantly improves performance for high-latency connections. Additionally, the backend introduces new security features such as host key pinning (--sftp-pin-host-key) and configurable SSH ciphers, MACs, and key exchange algorithms, while also fixing several issues related to shell command injection and connection handling.
backend/sftp · high confidence
Updated rclone logos to new design
The rclone logo assets in the graphics directory have been updated to a new design. This change introduces a comprehensive set of new SVG logo files, including horizontal and vertical layouts in both color and monochrome variants, as well as symbol-only versions for light and dark backgrounds. A README file has also been added to the logo directory to document the assets and credit the designer.
graphics · high confidence
Yandex backend rewritten with new options and improved reliability
The Yandex backend has been completely rewritten to use the rest/pacer library directly, removing the previous API client dependency. This change introduces several new configuration options: 'app\_folder' allows using the application folder root for OAuth tokens with limited scope, 'spoof\_ua' enables mimicking the official Yandex Disk client to potentially improve upload speeds, and 'upload\_wait' adds a configurable delay after uploads to prevent 500 errors caused by asynchronous server finalization. The rewrite also fixes issues with truncated file uploads, missing MD5 hashes, and incorrect handling of root directory paths, while permanently disabling MIME type writing as Yandex ignores it.
backend/yandex · high confidence
bisync command released from beta with comprehensive sync and conflict resolution features
The bisync command is no longer in beta and introduces robust two-way synchronization capabilities, including automatic conflict resolution via --conflict-resolve and --conflict-loser, support for tracking renames with --track-renames, and a new --resilient mode for recovering from self-correctable errors. Users can now customize comparison logic with --compare (supporting checksum, size, and modtime), handle empty directories with --create-empty-src-dirs, and recover from interruptions without a full resync using --recover. The command also features improved error handling for unreadable lockfiles, graceful shutdown support, and better integration with crypt backends through automatic fallback to cryptcheck or download-based hashing.
cmd/bisync · high confidence
mkdir command warns on remotes that do not support empty directories
The mkdir command now checks if the target remote supports empty directories. If the remote does not support them and the path contains a directory component, the command logs a warning that the operation will effectively do nothing, rather than silently failing or succeeding without creating the directory structure.
cmd/mkdir · high confidence
Fixes
bisync: introduces bilib package for session naming and output capture
The bisync command now uses a new internal library (cmd/bisync/bilib) to manage session metadata and logging. Session names are normalized to remove non-canonical characters (such as spaces and special symbols) and strip trailing hex strings, ensuring consistent file paths for sync listings across different backends and operating systems. Additionally, a new CaptureOutput utility allows the command to safely capture log output during specific operations, improving the reliability of status reporting.
cmd/bisync/bilib · high confidence
Test coverage
Add 'rclone test' command to expose test utilities; Added \rclone test info\ command to detect remote filesystem limitations; Added bisync integration test scenarios and VS Code debug configurations; Added changenotify test command for debugging change notifications; Added deterministic tests for sync and check logging; Added integration test infrastructure for rclone serve backends; Added internal test utilities for processing and reporting control character test results; Added memory test command; Added mount seek performance and stress test utilities; Added test data for subtitle and metadata files; Added test fixtures for encrypted and plain configuration files; New end-to-end testing framework for commands and environment variables.
Dependencies
Swift backend upgraded to v2 of the underlying library
The Swift backend has been updated to use the v2.0.0 release of the github.com/ncw/swift library. This upgrade introduces a new authentication wrapper that allows overriding the storage URL and auth token, and brings in improved handling for large object segments, including better support for dynamic large objects, static large object copying, and more reliable deletion of segment containers. Users benefit from enhanced reliability, particularly with token expiry workarounds and improved error handling during uploads and deletions.
backend/swift · high confidence
Update Go version to 1.26 and refresh all dependencies
The project now requires Go 1.26 and has updated its dependency manifest to include the latest versions of all libraries, including AWS SDK v2, Azure SDK, golang.org/x/net, and golang.org/x/crypto. This update also enables the x509negativeserial GoDebug setting to handle certificates with negative serial numbers.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 56 → 55 (-0.8)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 61 → 75 (+14.7)
- Architecture 100 → 93 (-6.1)
- Maturity 63 → 63 (-0.1)
- Readiness 63 → 46 (-16.4)
- Security 46 → 54 (+7.9)
- Accessibility 71 → 71 (+0.0)
Resolved (397)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (backend/b2/b2.go)
- Duplicated block (10 lines × 2) (backend/box/box.go)
- Duplicated block (10 lines × 2) (backend/box/box.go)
- Duplicated block (10 lines × 2) (backend/cache/storage_persistent.go)
- Duplicated block (10 lines × 2) (backend/drive/drive.go)
- Duplicated block (10 lines × 2) (backend/fichier/api.go)
- Duplicated block (10 lines × 2) (backend/filelu/filelu_client.go)
- Duplicated block (10 lines × 2) (backend/ftp/ftp.go)
- Duplicated block (10 lines × 2) (backend/googlephotos/googlephotos.go)
- Duplicated block (10 lines × 2) (backend/hidrive/helpers.go)
- Duplicated block (10 lines × 2) (backend/internxt/internxt.go)
- Duplicated block (10 lines × 2) (backend/mailru/mailru.go)
- Duplicated block (10 lines × 2) (backend/mega/mega.go)
- Duplicated block (10 lines × 2) (backend/oracleobjectstorage/object.go)
- Duplicated block (10 lines × 2) (backend/oracleobjectstorage/object.go)
- Duplicated block (10 lines × 2) (backend/pikpak/pikpak.go)
- Duplicated block (10 lines × 2) (backend/premiumizeme/premiumizeme.go)
- Duplicated block (10 lines × 2) (backend/seafile/seafile.go)
- …and 377 more
New (1158)
- (anonymous) (cognitive 42) (fs/rc/js/wasm_exec.js)
- (anonymous) (cyclomatic 42) (fs/rc/js/wasm_exec.js)
- ClassTooLong: Dir (vfs/dir.go)
- ClassTooLong: File (vfs/file.go)
- ClassTooLong: Fs (backend/azureblob/azureblob.go)
- ClassTooLong: Fs (backend/b2/b2.go)
- ClassTooLong: Fs (backend/box/box.go)
- ClassTooLong: Fs (backend/cache/cache.go)
- ClassTooLong: Fs (backend/chunker/chunker.go)
- ClassTooLong: Fs (backend/drive/drive.go)
- ClassTooLong: Fs (backend/dropbox/dropbox.go)
- ClassTooLong: Fs (backend/filefabric/filefabric.go)
- ClassTooLong: Fs (backend/ftp/ftp.go)
- ClassTooLong: Fs (backend/gofile/gofile.go)
- ClassTooLong: Fs (backend/huaweidrive/huaweidrive.go)
- ClassTooLong: Fs (backend/local/local.go)
- ClassTooLong: Fs (backend/mailru/mailru.go)
- ClassTooLong: Fs (backend/netstorage/netstorage.go)
- ClassTooLong: Fs (backend/onedrive/onedrive.go)
- ClassTooLong: Fs (backend/pcloud/pcloud.go)
- …and 1138 more
Changes since last survey
- 300 commits — 183 feature/other, 117 fixes
By area
- docs/content — 54 commits
- cmd/serve — 25 commits
- fs/operations — 16 commits
- (root) — 11 commits
- backend/archive — 9 commits
- backend/onedrive — 9 commits
- backend/s3 — 9 commits
- backend/huaweidrive — 8 commits
- backend/local — 8 commits
- backend/internxt — 7 commits
- fs/accounting — 7 commits
- fs/rc — 7 commits
- backend/oracleobjectstorage — 6 commits
- backend/dropbox — 5 commits
- backend/webdav — 5 commits
- lib/rest — 5 commits
- backend/azureblob — 4 commits
- backend/hidrive — 4 commits
- backend/iclouddrive — 4 commits
- backend/box — 3 commits
Notable commits
- fix: accounting: fix bwlimit burst overflow - fixes #9820
- fix: accounting: fix memory leak from stats groups on long-running rcd
- fix: accounting: fix memory leak on long-running rcd
- fix: archive: fix "directory not found" for archive paths containing "./" or "//" [GHSA redacted]
- fix: archive: fix corrupt listings when listing a zip directory more than once
- fix: archive: fix crash when creating archive to stdout - fixes #9910
- fix: archive: fix listing entries with a leading slash as if they were in the root
- fix: archive: fix zip entry named "." hiding every other file [GHSA redacted]
- fix: archive: fix zip file entries named for a directory causing confusion
- fix: archive: fix zip slip path traversal in untrusted zip files [GHSA redacted] CVE-PENDING
- fix: archive: fix zip subdirectory root matching sibling directories [GHSA redacted]
- fix: azureblob: fix spurious vfs cache corruption errors during chunked reads - fixes #9782
- fix: azureblob: fix test which didn't compile
- fix: bisync: fix failed transfers of empty files being recorded as synced
- fix: box, serve s3: fix log messages with bad format strings
- fix: box: fix truncated files being uploaded successfully when the source ends early
- fix: build: disable staticcheck SA4023 to fix lint job timeout
- fix: build: fix TestS3Minio by pulling minio from quay.io as it has gone from Docker Hub
- fix: build: fix multiple CVEs by upgrading to go1.26.6
- fix: build: update golang.org/x/crypto to v0.55.0 to fix [CVE redacted]
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
rclone/rclone was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 3ac301eff1f730459da2aaa0ede0937bf0e2f968 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.