DFSG NEW Queue

DFSG, Licensing & New Packages Team

Review: borgstore 0.5.1-2

Package Information

DescriptionGeneral purpose key/value store in Python

borgstore implements a general purpose key/value store in Python.

Overview --------

Keys are simple strings like `config/main` or `data/0123456789abcdef` `[str]` (config and data are namespaces here). Values are binary objects `[bytes]`.

The `Store` class is the high-level API, so you can comfortably work with the kv store without caring for low-level details.

The `backends` package has misc. storage backend implementations.

The `server` package has a REST server implementation, complementing the REST client functionality in the `rest` backend. To actually store stuff, the REST server can use any backend internally, e.g. the `posixfs` backend.

Store features --------------

- supports URLs, like `file:///srv/borgstore` or `https://myserver/path` - easy to use, high-level `Store` API: create/destroy, open/close, list, load/store, delete, move, soft delete/undelete, hash, defrag, ... - uses a backend to implement the storage - optionally uses an additional caching backend, with a configurable cache policy per namespace - name nesting / unnesting, recursive directory listing - statistics collection - latency/bandwidth emulator

Backend features ----------------

- existing backends for local filesystem, sftp, REST, S3 / B2 (native) and many other cloud storage protocols via rclone - new backends are simple to implement - key validation - partial loads / range requests - stored object hashing - stored object defragmentation - quota support (only `posixfs`) - permissions checking (only `posixfs`)

REST server features --------------------

- server-side permissions/quota enforcement - server-side hashsum check of transferred objects before storing - network traffic optimization by doing stuff server-side:

- stored object hashing - stored object defragmentation - the REST server can internally use any backend for storage, e.g. `posixfs` - for the REST server, we provide CI tested configs for:

- an nginx-based reverse proxy - systemd-based on-demand `borgstore.server` process creation

State of this project ---------------------

**API is still unstable and expected to change as development goes on.**

**As long as the API is unstable, there will be no data migration tools, such as tools for upgrading an existing store's data to a new release.**

There are tests, and they pass for the basic functionality, so some functionality is already working well.

There might be missing features or optimization potential. Feedback is welcome!

Many possible backends are still missing. If you want to create and support one, pull requests are welcome.

Borg? -----

Please note that this code is currently **not** used by the stable release of BorgBackup (also known as "borg"), but only by Borg 2 beta 10+ and the master branch.

MaintainerGianfranco Costamagna <locutusofborg@debian.org>
Changed ByGianfranco Costamagna <locutusofborg@debian.org>
Sponsorlocutusofborg@debian.org
Distributionunstable
Architectureall
VCSgit: https://salsa.debian.org/debian/borgstore.git (browse)
Popcon Installs133
Binary NEWYes (binary-only upload)
Trackerhttps://tracker.debian.org/pkg/borgstore
Uploaded1 month, 27 days ago

New Package Report

.changes
Version0.5.1-2
Changed-ByGianfranco Costamagna
Architecturesource all
Distributionunstable
DateWed, 10 Jun 2026 18:56:33 +0000
Sourceborgstore
Changelog
borgstore (0.5.1-2) unstable; urgency=medium
 .
   * Add a doc package with sphinx documentation
   * Add rest package.
     - note: this requires configuration for username/password/backend
       this is specific for the user installing it
.dsc
Package-Listpython3-borgstore deb python optional arch=all
python3-borgstore-doc deb python optional arch=all
python3-borgstore-server-rest deb python optional arch=all
Sectionpython
Priorityoptional
Componentmain
debian/copyright
Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Upstream-Name: borgstore
Source: https://github.com/borgbackup/borgstore

Files: *
Copyright: 2024-2026 Thomas Waldmann <tw@waldmann-edv.de>
License: BSD-3-clause

Files: debian/*
Copyright: 2024-2026 Gianfranco Costamagna <locutusofborg@debian.org>
License: BSD-3-clause

License: BSD-3-clause
 Redistribution and use in source and binary forms, with or without
 modification, are permitted provided that the following conditions
 are met:
 .
  1. Redistributions of source code must retain the above copyright
     notice, this list of conditions and the following disclaimer.
  2. Redistributions in binary form must reproduce the above copyright
     notice, this list of conditions and the following disclaimer in
     the documentation and/or other materials provided with the
     distribution.
  3. The name of the author may not be used to endorse or promote
     products derived from this software without specific prior
     written permission.
 .
 THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
 "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
 LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
 A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
 OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
 SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
 LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
 DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
 THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
 (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
 OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.

Review Information

accepted — allocated to awm 1 month, 26 days ago, started 1 month, 26 days ago, completed 1 month, 26 days ago.

Final Comment

Hi,

Some poor packaging hygeine here around the description and such - see the Lintian report for the details. The licensing is fine though, so there's that...

Thanks!

Public Notes

1 month, 26 days ago ● public

Lintian

Command: lintian -Iiv -L '>=warning' --show-overrides --color=never ../$(basename $PWD)_*.changes
Exit code: 0

N:
W: python3-borgstore: extended-description-line-too-long line 15
N: 
N:   One or more lines in the extended part of the "Description:" field have
N:   been found to contain more than 80 characters. For the benefit of users of
N:   80x25 terminals, it is recommended that the lines do not exceed 80
N:   characters.
N: 
N:   Please refer to The single line synopsis (Section 3.4.1) in the Debian
N:   Policy Manual for details.
N: 
N:   Visibility: warning
N:   Show-Always: no
N:   Check: fields/description
N: 
N:
W: python3-borgstore: extended-description-line-too-long line 67
N:
W: python3-borgstore: extended-description-line-too-long line 71
N:
W: python3-borgstore: extended-description-line-too-long line 77
N:
W: python3-borgstore-doc: extended-description-line-too-long line 15
N:
W: python3-borgstore-doc: extended-description-line-too-long line 67
N:
W: python3-borgstore-doc: extended-description-line-too-long line 71
N:
W: python3-borgstore-doc: extended-description-line-too-long line 77
N:
W: python3-borgstore-server-rest: extended-description-line-too-long line 15
N:
W: python3-borgstore-server-rest: extended-description-line-too-long line 67
N:
W: python3-borgstore-server-rest: extended-description-line-too-long line 71
N:
W: python3-borgstore-server-rest: extended-description-line-too-long line 77
N:
W: python3-borgstore: no-manual-page [usr/bin/borgstore-server-rest]
N: 
N:   Each binary in /usr/bin, /usr/sbin, /bin, /sbin or /usr/games should have
N:   a manual page
N:   
N:   Note that though the man program has the capability to check for several
N:   program names in the NAMES section, each of these programs should have its
N:   own manual page (a symbolic link to the appropriate manual page is
N:   sufficient) because other manual page viewers such as xman or tkman don't
N:   support this.
N:   
N:   If the name of the manual page differs from the binary by case, man may be
N:   able to find it anyway; however, it is still best practice to match the
N:   exact capitalization of the executable in the manual page.
N:   
N:   If the manual pages are provided by another package on which this package
N:   depends, Lintian may not be able to determine that manual pages are
N:   available. In this case, after confirming that all binaries do have manual
N:   pages after this package and its dependencies are installed, please add a
N:   Lintian override.
N: 
N:   Please refer to Manual pages (Section 12.1) in the Debian Policy Manual
N:   for details.
N: 
N:   Visibility: warning
N:   Show-Always: no
N:   Check: documentation/manual
N:   Renamed from: binary-without-manpage
N: 
N:
W: python3-borgstore: possible-unindented-list-in-extended-description line 21
N: 
N:   The package "Description:" contains an unindented line which starts with a
N:   dash (-) or asterisk (*). If this was meant to be a list of items these
N:   lines need to be indented (dselect would word-wrap these lines otherwise).
N: 
N:   Please refer to Description (Section 5.6.13) in the Debian Policy Manual
N:   for details.
N: 
N:   Visibility: warning
N:   Show-Always: no
N:   Check: fields/description
N: 
N:
W: python3-borgstore-doc: possible-unindented-list-in-extended-description line 21
N:
W: python3-borgstore-server-rest: possible-unindented-list-in-extended-description line 21
1 month, 26 days ago ● public

License Check

Command: dnq license-check -prepare
Exit code: 0

License check [main]:

Found 1 unique license identifier(s) in debian/copyright:

COMPATIBLE (1):
  BSD-3-clause

Result: ALL LICENSES RECOGNIZED AS DFSG-COMPATIBLE

Back to Dashboard | View all reviews for this package