Windows backups Preview
On Windows, sqz backup can read a frozen shadow copy of the drive, use the NTFS change journal to skip unchanged folders, and keep file attributes, alternate data streams and permissions.
Everything on this page is new and has not yet been proven on real Windows machines. Try it on data you also back up another way, and run check --read-data and a drill afterwards.
Shadow copies (VSS)#
sqz backup run D:\backups\laptop C:\Users\me --vss
sqz backup run D:\backups\laptop C:\Users\me --vss-fallback
With --vss, SQZ asks Windows for a Volume Shadow Copy of the drive first and backs up from it. Files that are open or changing (mailboxes, databases, documents being edited) are read as they were at one instant. The snapshot still records the folder you named, not the shadow copy's path.
- It needs to run as Administrator.
- If Windows refuses (not elevated, not enough space for the shadow copy, a VSS writer failed, a network drive),
--vssstops and gives the reason. --vss-fallbackbacks up the live files instead, with a warning and exit code4, so a scheduled backup still happens.
The NTFS change journal (USN)#
NTFS keeps a journal of changes to every file. SQZ can use it in two ways. Both need Administrator and an NTFS drive.
Check mode: --usn-check#
sqz backup run D:\backups\laptop C:\Users\me --usn-check
The backup scans everything as usual, but first asks the journal what changed since the last backup, and afterwards compares that with what the scan found. It changes nothing about what is backed up; it tells you whether the journal can be trusted on your machine. Exit code 5 means the journal missed a changed file. When the journal cannot be used (another volume or snapshot, a reset or wrapped journal, not NTFS, no Administrator), it says why and carries on.
Fast mode: --usn#
sqz backup run D:\backups\laptop C:\Users\me --usn
Only the folders the journal names are read from the disk; the rest is taken from the previous snapshot. On a mostly unchanged drive this makes far fewer file-system calls. The stored snapshot is the same one a full scan would make. Guards:
- 20 folders the journal says are untouched are compared with the disk on every run, and any difference means a full scan;
- anything the journal cannot vouch for (a reset or wrapped journal, another volume, a folder it cannot resolve, hard links) means a full scan;
- every 30th run is a full scan regardless.
Hard links and --usn#
A full scan under --usn or --usn-check counts the files that have more than one name (hard links) and remembers the count. While any exist, --usn does a full scan and says why: the journal names only the folder a file was changed through, not the other folders that hold the same file, so it cannot vouch for them.
Use --usn-check for a while before --usn, to see that the journal holds up on your machine.
Windows metadata#
- File attributes (read-only, hidden, system, archive and so on) are stored and restored.
- Alternate data streams, such as the
Zone.Identifierstream that marks downloaded files, are stored and restored. They are chunked, encrypted, deduplicated and verified like file contents. - Permissions (ACLs) are stored, and restored when you ask:
sqz backup restore D:\backups\laptop latest C:\restore --acls
--acls needs the same users and groups to exist on the machine you restore to, so it is off by default.
Unchanged files on Windows#
On Windows, a file counts as unchanged when its size and modification time match the last snapshot (Windows has no change time to compare, unlike Unix). --read-all reads everything.