Shirt Pocket Watch

The blog

Where I humiliate myself in public: release notes, backup deep-dives, and various and sundry other things that strike my fancy.

Dog Dazed

Executive Summary

SuperDuper! 4.0.1 now available in-app, and as a direct download.

Never have I ever

Never have I ever released a major version without following it up with a “quick fix” release. The saying is true: no plan survives an encounter with the public.

Or, as Mike Tyson said, everyone has a plan ‘til they get punched in the mouth.

So, thanks for punching me, oh-so-lightly, in the mouth. More like a love tap. Because things are working better than I’d hoped, given the sheer amount and complexity of the new code (namely, all of it).

Also, and I don’t say this enough, thank you to everyone who reached out to send a kind word. Developing something like this in relative secrecy can be lonely, as you wonder whether changes this extensive are going to hit folks as a good thing, Release day itself is full of detail work, and I was doing a lot more than just posting a build: a whole new website, self-implemented blog engine, dynamic page release notes…it was quite a lot!

But now that it’s all finally out in the wild, the positive feedback has been encouraging, and I really appreciate the time each of you spent to send it in. Thanks.

The windup, and the pitch

So, you might ask, with all that said, what’s wrong, then? Well:

  • There was a timing related issue with Backup on connect that caused a backup to fail, before it started, if the APFS container mounted quickly, but its volumes mounted slowly.
  • In some situations, Backup on connect would only work once until the server was restarted.
  • An encrypted drive would fail to unlock if there were bad credentials in the keychain along with good ones.
  • I missed a few time localizations (embarrassing; sorry, non-US folks).

And that’s it. So far. Let’s hope it stays that way!

The new update is available in-app, of course, or you can download and install manually.

SupererDuperer

Executive Summary

Brand new, top-to-bottom rewrite of SuperDuper now available.

All the Details

22 years.

SuperDuper has had an impressive run. It has lasted, in its original form, for longer than any other product I’ve ever been involved with over the (so far) 43 years of my working career. Somehow, Shirt Pocket—and SuperDuper—has been more than half of that. Over those years, most of the design decisions made way back in 2004 have proven to withstand the test of time:

  • The text-based What’s going to happen? section;
  • The status view that clearly shows the process that’s taking place during the copy, ticking off the steps as it goes along;
  • The minimal number of options that let you stay focused on the task at hand.

At the same time, some choices constrained what the program could do:

  • It was document-based, which made sense at the time, but wasn’t really how users thought about the process;
  • Scheduling was a bit of a bolt-on (and suffered from a disastrous initial usability test before release), driving the interface through scripting (RIP AppleScript, hello direct event dispatch from Swift) and isolating its details in a separate window, divorced from the source;
  • Copy failures, while rare, basically gave a “whoops” and asked users to examine a log filled with technical details of the error;
  • Only “native” Apple file systems were supported (HFS+ and APFS);
  • And some concepts, like the Sandbox—great in the days of macOS before the Sealed System Volume—were rendered obsolete, sent to the land of wind and ghosts by Apple’s relentless forward march.

I could go on: products are a combination of good and bad, of success and failure, and I learned to live with the (mostly good!) balance.

Dreams Become Reality

Back in 2007, I designed what was intended to be SuperDuper v3.0. It was a rewrite that greatly expanded its capabilities while retaining its essence.

But, in those days, it just wasn’t possible for us to implement those grand plans. The new UI was much more complex, the logic more elaborate, and the systems we had then didn’t support the things needed to make it a reality without a lot of complex coding we didn’t have time for.

On top of that, macOS itself was a moving target (and still is!): adding and deprecating features; completely changing the file system; locking down the OS; supporting not just one change in CPU, but three.

With a tool so tied to how the system operated at a low level, it was a lot of work just keeping up with what Apple was doing.

So, I put the notebook with that design in it on a shelf.

For nearly 20 years.

Today, I’m happy to say that I’ve finally been able to carve out enough time to grab that “old” redesign, flesh it out further, modernize it, and make that dream a reality.

Welcome to SuperDuper! 4

SuperDuper! 4

The new version of SuperDuper is a ground-up rewrite, a tip-to-tail reinvention of what SuperDuper looks like, how it works, what it can do, and where I can take it in the future.

The new version feels different, yet familiar. The successful elements of SuperDuper’s design, like What’s going to happen? and the status view, are still there, but they’ve been refreshed and modernized.

Documents have been retired and replaced with Copy Jobs, which are stored internally and organized by source. If you want to copy Macintosh HD, that’s where you start. Click, and you’re presented with one or more template copy operations, or you can start from scratch.

Configuration is done right inline by clicking bold, underlined link elements and selecting options from pop-ups. The effect of your choices is immediately reflected in What’s going to happen?, ensuring you know what to expect when you click Copy Now.

Preview

And if you’re still unsure, you can safely see what’s going to happen…for real. Click the Preview button and SuperDuper will run the copy without making changes and present you with a report that shows exactly what would have been updated, added, deleted, etc., had this been a real run.

Blazing Speed!

Once you decide it’s time to make the copy, SuperDuper 4 is much faster than before. And I’m not just talking 20% or 30% faster. Smart Updates are between 2x and, with the new Turbo feature, an order of magnitude faster.

As an example, my typical nightly Smart Update, of an 8-million-file volume, about 2.5TB of data, used to take around 40 minutes to run.

Without Turbo, it now takes about 20 minutes. But with Turbo…it’s only about a minute.

One minute. OK, yes, sticklers—that’s actually quite a bit more than an order of magnitude. ¯\_(ツ)_/¯

History

Successful and failed runs are shown at the bottom of the copy job, with color-coded dots that can be clicked to display details.

If scheduled, a clear indication of when the next run will occur is there as well. And for those going for the Guinness Book of Backup Records, there’s an indication of how many successful runs this job has done in a row.

No UI Needed

At a technical level, SuperDuper has been split into a “helper” or “server”, which runs the copy, and an interface, which is the part you interact with. That means that, once registered, you can quit the SuperDuper application and your backups will still run. They’ll even run if you log out!

It also means that a scheduled copy doesn’t suddenly show the interface. It just happens, in the background.

If a copy is in progress, re-opening the app will show you the status and progress of the copy—and while a copy is going on, a menu bar item is present to show a compressed view of the same information.

Many Copies at Once

You can run any number of copies at the same time. If you have four backups you need to do, just click Copy Now for each, and they’ll all run simultaneously.

Have four backups scheduled to run at 4am? They’ll all run at that time, rather than back to back.

File Systems and Folders

SuperDuper 4 now supports copying to and from any file system the Mac supports. Using a “Photos” drive with both Windows and Mac that’s formatted as exFAT? No problem: you can copy it.

Need to copy your Documents folder to “Documents Backup” on a NAS? Now you can.

Have a network volume that you want to copy to a local folder? SuperDuper 4 can do it.

Copy Rules

Copy Scripts have been replaced by Copy Rules. Now, you can easily create rules that can select files and folders from the source or destination for special handling. Need to ensure that a specific folder is never written to or deleted? You can do that with a few clicks.

Want to exclude any folder named Caches in /Library? No problem. And you can see the effect of your rule as you create it, so you can be sure you’ve done the right thing.

No More Shell Scripts

I’ve added Shortcuts support, so you can create a shortcut that runs before or after a copy, on success, or on error. Want to send an email on success or failure? Beep when copies are done? It’s now easy, and with Golden Gate’s Apple Intelligence shortcut support, anyone can do it.

Or, at least, probably anyone.

And if you still want to run a shell script, you can…from the shortcut.

Speaking of Shortcuts

Not only does SuperDuper let you call a shortcut from a copy—you can create, run, and check on a copy job from a shortcut!

If you have an unusual workflow—say, you want to copy any SD card with photos on it to a folder named after that card—you can now do it with a few clicks.

…And So Much More

This is already (much) too long, but there’s so much new stuff that I’ve been wanting to show you. I hope you’re as excited to use this as I am to get it into your hands after all this time.

System Requirements

SuperDuper 4 requires macOS 14 (Sonoma) or later. SuperDuper 3 is still available for those who need to copy under macOS 13 (Ventura) or earlier.

Upgrades

In all the years SuperDuper has been on the market, we’ve never charged for updates and never even raised the price. That’s 22 years of free updates.

SuperDuper 4 is a totally new version, far more capable than before, and as such, I’ve decided this is going to be its first paid upgrade. I’ve also adjusted the price for inflation since 2004. So it’s still the same bargain it was back when it was first released, but in today’s dollars.

SuperDuper 4 is free for qualifying recent purchases. Other SuperDuper 3 customers who purchased after July 31, 2020, receive an upgrade discount of up to 30%, based on purchase date.

As before, even without a license, you can make full, bootable backups for free, and I (yes, it’s really me, I work too much) provide support for both registered and unregistered users.

Dinner’s Served

I’ve been looking forward to this day for a long time, and now that the day has finally arrived, I’m excited to see what you think. Reach out to support if you have any questions, praise, or, if you must, complaints.

And please register or upgrade! The only way I can continue to do this is with your financial support. If you like SuperDuper, share the love and tell your friends!

With that:

Download SuperDuper 4

SuperDuper v3.12 Now Available!

We’re happy to announce the release of SuperDuper v3.12 (with a forthcoming, identical update to the v3.20 Beta), which has a number of improvements, bug fixes, and a fix for security issue CVE-2025-69604. This version is available through the normal update mechanism in SuperDuper, or you can download it from here.

Security First - CVE-2025-69604

Let’s discuss the security issue first. In SuperDuper v3.11 and earlier, a 3rd party could construct an installer package that did something malicious. They could then modify the settings to install this package, allowing root access.

The package install step was initially designed to be a convenient way to install an OS update on a copy. This is rarely done these days, so rather than fix this the way we fixed “shell script” execution and force “root” ownership of the installer package, we decided to remove the option completely.

As with the “shell script” fixes in v3.11, a user can see that this has happened because it’s specifically referenced in “What’s going to happen?”, so if you’re running a version of SuperDuper prior to v3.12, and see an unexpected section saying a package will be installed, turn that option off in the Advanced tab of Options.

We’ve added this CVE information to the security discussion posted earlier.

Improvements Second

Due to the accelerated release of v3.11, which was a mid-development “branch” to address the security issues involved, in our haste to get the update out, we were unable to fully test some of the changes in that release. Alas, this resulted in some corner-case crashes, which we’ve fixed.

We also found a longstanding issue where, in some unusual circumstances, we weren’t reliably detecting a read error on some source files. We’ve fixed that as well.

We’ve made some improvements to our scheduler to help mitigate some of the Tahoe “stalling during Dark Wake” problems. They’re not 100%, but things are better, and we’re investigating additional improvements for the next update.

Finally. there are some other little fixes in there (a Dark Mode issue, a goof in the “amount of data deleted” statistic) as well.

Work Continues

We’re still hard at work on additional Tahoe improvements…so back to it.

Thanks, as always, for using SuperDuper!

SuperDuper Security Update v3.11

Mistakes are a part of life.

They’re not a great part, but when viewed “correctly”, they’re an opportunity.

Well, we have three opportunities, brought to our attention by a security researcher. They’re security vulnerabilities that have been in SuperDuper! since the very first version, released almost 22 years ago.

Today, we’re releasing fixes for the current release (the SuperDuper! v3.20 Beta is already fixed), a discussion of the problems, and the steps users can take to mitigate the issues if they cannot install the update.

We don’t know of any bad actors making use of these exploits as of this post.

Mistake #1 (CVE-2025-61228)

Our auto-update mechanism can be hijacked and convinced to install a package that isn’t SuperDuper.

Even though we signed and notarized our installer package, Gatekeeper is not checking that notarization when installed by macOS’s package installer. As such, the download could be changed, and we’d install that instead. Since the install is being done with escalated privileges, that could allow a malicious 3rd party’s program, which you would also have to install, to gain administrator access to your system.

This can only happen if a program running on your system is looking for SuperDuper to perform an update, a real update is presented through legitimate means, and you click Upgrade.

To fix this, we’ve done three things:

  1. We’ve put out an update, which you may have seen before reading this post, that explains that the fixed version of SuperDuper, v3.11, should be downloaded and installed directly from the Shirt Pocket web site…and the Upgrade button, at the bottom of the window, should not be pressed.

  2. We’ve changed our updater to validate the signature and notarization of the install package ourselves before installing the update.

  3. After this announcement, we will not present update notices for any version of SuperDuper prior to v3.11 unless absolutely necessary, and in those cases we will clearly indicate, as we have here, that the user should not click Upgrade. Users who cannot install the update can prevent these notices from appearing by turning off automatic updates in SuperDuper’s preferences.

Mistake #2 (CVE-2025-57489)

When the lock in SuperDuper is unlocked to allow execution to occur without having to enter an administrator password, a 3rd party program could make use of our authorization to run something other than a backup with administrator privileges.

Again, this can only happen if you install something that is, itself, malicious. And it’s one mechanism of many that could be used by a bad actor to gain “root” access on your system. But this one is due to our error.

To fix it, as above, we’ve done three things:

  1. In the same update notice, we’ve instructed people to install SuperDuper v3.11, downloaded directly from the web site.

  2. We’ve changed our program to validate that the commands being executed with escalated privileges are actually coming from our own, known, sealed, signed source.

  3. Users who cannot run the new version can lock the lock in the main window, which closes the security hole.

While the new SuperDuper v3.11, released today, ensures that all users who could run v3.10 are no longer vulnerable, one problem remains: we cannot fix older versions of SuperDuper. There are versions of SuperDuper available for macOS versions as early as 10.1, and we have no way to rebuild them. On top of that, we cannot “patch” the faulty element, because SuperDuper itself ensures that it’s unmodified before running, and would refuse to run at all if patched.

Unfixed versions can be made secure by locking the lock in the main window. However, doing so means scheduled backups will not run: with the lock locked, all backups must be made by manually running SuperDuper.

Mistake #3 (CVE-2025-61229)

User-settable Before/After shell scripts run escalated, with SuperDuper’s TCC Full Disk Access permissions. Since those shell scripts are referenced by the settings files for the copy or schedule, a malicious actor could modify those settings to run their own script.

As before, this would require another malicious program to be installed.

To mitigate this vulnerability, in v3.11 we’ve made two changes:

  1. Before/After shell scripts are forced to run with the user’s ID and privileges. Individuals who require alternative execution contexts can do so through normal Unix methods such as suid.

  2. Scripts must be owned by the root user, even when run in the normal user’s context. This ensures that any script that would run has been explicitly authorized by an administrative user.

Note that these Before/After scripts are explicitly referenced in the What’s going to happen? section of the main window. Users who cannot update to v3.11 are advised to review that information before pressing Copy Now to ensure no unexpected entries are present.

Mistake #4 (CVE-2025-69604, addressed in v3.12)

In SuperDuper v3.11 and earlier, a 3rd party could construct an installer package that did something malicious. They could then modify the user’s settings to install this package, allowing root access.

The package install step was initially designed to be a convenient way to install an OS update on a copy. This is rarely done these days, so rather than fix this the way we fixed “shell script” execution and force “root” ownership of the installer package, we decided to remove the option completely.

As with the “shell script” fixes above, a user can see that this has happened because it’s specifically referenced in “What’s going to happen?”, so if you’re running a version of SuperDuper prior to v3.12, and see an unexpected section saying a package will be installed, turn that option off in the Advanced tab of Options.

Practical Considerations

People running old versions of macOS, with old versions of SuperDuper, on old Macs, are exposed to many security vulnerabilities, from web pages that can gain escalated privileges due to bugs in Safari or its sandbox, to other errors in the kernel that can do the same. These errors, when found, are fixed, but those fixes are not available to earlier macOS versions. Once a Mac becomes “vintage”, or a version of macOS is no longer supported, security updates are no longer provided, and those issues persist.

On a system where we cannot provide a fix, you have to make a judgement call after balancing the risks of this flaw being exploited, in your personal situation, versus the inconvenience of having to manually perform backups. If you do not install malicious programs from sketchy sources after these vulnerabilities have been disclosed, you are at the same level of risk you were at before, especially since you were already at risk from actors who could exploit your unsupported OS without installing another application, such as by simply visiting a web page.

However, if you feel the additional risk is too great, you can lock the lock, set a scheduled reminder via iCal, and perform your backups manually (and, of course, you can, and should, use Time Machine as well).

Arrgh-arrgh-arrgh-arrgh (argh)

This post obviously uses a more serious tone than you may be used to on the blog.

We take security and safety extremely seriously here—if we didn’t, we wouldn’t have made a backup program—and, to be frank, feel frustrated and ashamed that our program can be exploited to make your system less safe.

We’ve taken the steps needed to fix the bugs, inform our valued users, registered or not, about the problems, and have explained how to mitigate them on any version of SuperDuper, old or new. As previously mentioned, and as far as we are aware, these vulnerabilities have not been exploited by a bad actor (which does not mean they can’t be, of course).

We’d like to thank the anonymous security researcher who brought these bugs to our attention, and for working with us to verify that our fixes have corrected the errors they found.

Finally, we’d like to take this opportunity to apologize to all our users for these bugs. We hate making mistakes. We’re truly sorry for these, and will continue to do our best to put out versions of SuperDuper that you can trust as one method, of many, to keep your data safe.

Thanks for reading, and for using SuperDuper. We couldn’t continue to do this without you.

—Dave Nanian & Bruce Lacey

Three Steps Forward

So, Tahoe.

As you’ve seen here, we’ve had a series of Betas that have focused on compatibility, fixing some longstanding-but-minor bugs, and adding some enhancements.

The Best Laid Plans

We had some additional things in mind for this cycle, which is why we had given it a major version number change - v4.0.

This beta version, though, is v3.20, and the reason is quite simple: we ran into enough compatibility roadblocks and similar things in Tahoe that we just didn’t have enough time to create a reliable version of the new stuff.

That Said…

This new Beta is another nice little advancement over the last one, with some fixes for low-contrast items in dark mode, internal changes that improve compatibility, some little tweaks like adding the ability to open the Copy Scripts folder (which is in ~/Library/Application Support/SuperDuper!) from the File menu (rather than dealing with the hidden Library folder mess).

Coverage

You may have noticed, if you’re running under pre-release versions of Tahoe, that you were offered the Beta automatically, so that you could continue to use SuperDuper! without running into compatibility issues during the Tahoe Beta.

This was enthusiastically welcomed, which is nice, and also ensured we had as much testing coverage possible during the Developer and Public Beta periods.

So, thanks to everyone who installed it - you helped make a better release.

Automagic

As always, this update will be offered automatically if you’re running a Beta version of SuperDuper! or Tahoe. Or, you can

Download SuperDuper! v3.20 B3

Thanks for using SuperDuper!

Deeper Into Tahoe

A quick update with some minor changes, but one thing we’ve never done before.

We’ve automatically offering this Beta update to any user who is running SuperDuper! and a Tahoe Beta.

We think it’s important for all users running Tahoe to run the SuperDuper Beta, since there are specific fixes in there that deal with Tahoe peculiarities. Since they’ve already opted in to the Tahoe Beta, we figure they should also opt in to the SuperDuper Beta that supports it.

It’s not forced, of course: it’s just an update like any other. But we strongly encourage all Tahoe users to install it.

Of course, you can also install it manually, if you:

Download SuperDuper! v4.0 B2

Enjoy!

v4.0 Beta 1 Now Available

When I write a blog post, I try to put some generally useful information along with the “required” stuff. And when it came to writing the v3.10 post, I just couldn’t come up with anything worth writing about; everything was discussed in the previous posts.

But today, we’ve got our first Beta of v4.0 (trumpets)!

Download SuperDuper v4.0 B1

A little tidbit first, though.

Flooding the Zone

As I’ve discussed in the past, we’ve noticed situations where folders with a lot of files in them are extremely slow to deal with.

We’ve seen this on pre-BigSur systems with the mdworker folders, which can have millions of folders and files in them.

We’ve also seen it with people who had Fitbit installed: their drivers crashed constantly on later OS versions and filled their folder with crash logs.

Today, we’ve found a new case. A user with Sequoia 15.4.1 on Intel, completely up to date, reported SuperDuper was running slowly. Our new trace capability showed quite clearly that the folder we were working on was

~/Pictures/Photos Library.photoslibrary/database/search/Spotlight/SpotlightKnowledgeEvents/index.V2/journals/12/cs_default

And that’s a folder I don’t have. When the user navigated to it at first, he said it was “empty”…which was weird. But later, he noticed that there was a spinner at the bottom of the Finder window. I asked him to wait, and >24 hours later, he finally got a list of files.

6,166,838 of them.

That’s right. 6,166,838 files. Generated by Spotlight. In one folder. Growing daily.

So, the new “WTFIH” feature, in introduced in v3.10, is proving useful. What’s going on with that user’s Spotlight, though… yikes.

Back to Beta

This first Beta version is primarily focused on Tahoe compatibility. Things are looking good, and bootable backups work as expected.

Of course, we’ve been polishing and improving a number of things over the past few months as well.

For example, we added the number of files being deleted from the destination to the “runtime statistics” in the Status View. Of course, we’ve always know that we were “deleting files” (after all, that’s part of a Smart Update when files are removed from the source), but left it out of the stats so we didn’t panic users.

We’ve added it in (for now) to see how people react. It’s useful in that deletion is a (surprisingly) slow operation, and if we’re deleting a folder of stuff, it may look like SuperDuper is “stuck” when it’s not.

This new count allow users to see that something is happening…and hopefully they won’t think it’s something scary.

Window (?) Menu

We also made another change that we’ve been resisting for some time, but actually makes sense.

The Window menu has a Show Log command that was designed to show the logs for the current copy window (i.e. the “Main Window”). That’s easy enough.

But when the Scheduled Copies window is active, each schedule (and you can have any number of them) has its own log, and it always felt like you weren’t getting the “log for the window”, but rather the log “for the selected copy”, and so there’s a Show Log that operates on the selection…as opposed to the window.

People, though, would often use Window > Show Log, the “wrong” log would come up (from the main window), and get confused.

So, now, it brings up the log for the main window, if it’s in front, or the selected schedule, if that’s in front.

I think that meets user expectations better, even if it’s a bit conceptually weird.

Liquid (Gl)ass

There are obviously a kajillion (= 100 bazillion) changes in Tahoe, and the most visible one is the new Liquid Glass theme.

You may notice that SuperDuper does not implement it.

There are some controls in SuperDuper (such as the Copy Now button with the snapshot selector) that don’t render well in the new, ass-ified theme. Apple’s own use of a similar control (the PDF selector in the Print menu) looks better when it’s not the default button (because the blobs aren’t weird and oversized), but you can see things going wrong when you click on the pop-up, where the highlight exceeds the button size, has a “waist”, etc. Blergh.

We’re trying to find a solution, but until then, enjoy the fact that your window has more space for content that isn’t covered up by weird translucent blobs.

I guess I have opinions about Liquid (Gl)ass

Waking the Neighbors Redux

Another thing we’ve found during the Developer Beta period is that scheduled copies will sometimes bring up the main window, start the backup, but never be able to launch the actual copy process.

This seems to have to do with “Dark Wake”: if the system is in, basically, “Power Nap” and is running dark processes, and SuperDuper starts, we’re unable to run properly/completely, because the system doesn’t transition out of Dark Wake, and there are special requirements and entitlements needed to run in that mode.

As a workaround, SuperDuper will turn on the screen, if it’s off-but-awake…until we find a better solution.

More to Come

That’s part of what we’ve been working on, with more to come. And I’ll have more to say about that as the summer winds on…but until then

Download SuperDuper v4.0 B1

Enjoy, and let us know if you have any problems, suggestions, issues, or just want to say hi.

Wrapping Up v3.10

tl;dr

SuperDuper! v3.10 B5 now available with minimal changes.

Medium Hanging Fruit

I discussed the speed of drives in the last post, not just to suggest that people use SSDs (which you should), but also to bring up the issue of “stalling”: situations where it looks like SuperDuper! isn’t doing anything, because accessing the drive is going slowly.

We’ve been thinking about this situation for some time. Coming up with a reasonable heuristic to detect what the user might consider “stalling” is a particular problem, as is doing something “sensible” when a stall is detected.

When this happens in a support case, I’ll often provide a user with a few Terminal commands that interrogate the file system calls to show what we’re doing, both to reassure the user that something is, indeed, happening…but also to provide a path that indicates what we’re working on.

That process is clumsy and can be confusing, though. So, it was time to take a baby step towards a solution.

Minimal But Useful

To that end, rather than change the status view when a stall is detected (which, again, isn’t easy to detect in a useful way), we’ve decided to add an “on-demand” bit of logging that I’ve named “WTFIH”, in honor of “What’s Going to Happen”.

Basically, if the user opens the log window (thus asking the question “What’s going on?”), we ask the copy engine what it’s doing and add a line to the log that indicates where we’re operating “right now”.

We’ll do this every time they open the log window, and that entry remains part of the log for the copy.

In addition, if the user ever asks the copy process to stop, we log the same info.

Information is Power

This new logging gives the user information about what’s happening on demand and adds detail to the log that gives me more data without requiring them to run a Terminal command…and with that, assurance that things are operating as desired.

Every Little Thing

There are other small changes in this release, most of which you probably won’t notice. As is our way, as we get close to an official release.

Download Away

And with that, it’s time to

Download SuperDuper! v3.10 B5

As usual, this update will be offered to people who already have a previous Beta version installed. When the final release is made available, that will also be offered to Beta users, after which you’ll only be offered normal updates until you manually install a future Beta.

So that’s it! Let me know if you have any issues, and thanks for using SuperDuper!

WGTH & SSDs, Redux

tl;dr—Beta 4 of v3.10 is now available, and can be downloaded with the link at the bottom of this post, or via the auto-updater inside SuperDuper itself.

Progress Report

So, our last update was a big one, internally, and the results, so far, are quite promising, with nearly 100% boot success.

People who are having trouble are typically using slow destination devices. If they’re too slow, not only does the boot process take a very long time, it can fail due to kernel watchdog timeout errors. (It’s quite clear that these watchdogs are expecting fast storage operation.)

Quantification

Every so often, we run into a user who is seeing extended “stalls” when working with large folders of data. Inevitably, the folders have a lot of files in them, and they’re using an HDD either for the source (for much older Macs) or the destination.

For example, let’s take a some cases of a million or so objects. (This happens more than you might think.) We have three folders - one with just files, one with folders, and one with files with basic metadata (Safari attributes and Quarantine).

Unpacking a tar archive with those folders to an SSD takes a few minutes. Unpacking the same archive to an HDD takes a few…hours (in fact, more than a few - we’re talking over four).

Both freshly formatted, both fast USB-C devices.

Minutes vs. hours.

That’s just creating the test case. Now, just to use pure, unadulterated, standard Mac commands that make use of the standard iteration calls, we’ve tried doing a timed ls (list files) on those folders and counting the result:

SSD

time ls -1 dirWithAlotOfEntries | wc -l
1000000
real 0m11.152s
user 0m3.152s
sys 0m2.774s

time ls -1 dirWithAlotOfFolders | wc -l
1000000
real Om9.420s
user 0m2.713s
sys Om2.822s

time ls -1 dirWithAlot0fMetadataFiles | wc -l
1098579
real Om11.254s
user Om5.371s
sys 0m2.296s

HDD

time ls -1 dirWithAlotOfEntries | wc -l
1000000
real Om54.112s
user Om2.898s
sys Om3.473s

time ls -1 dirWithAlotOfFolders | wc -l
1000000
real 13m6.616s
user Om2.512s
sys Om4.594s

time ls -1 dirWithAlot0fMetadataFiles | wc -l
1098579
real 42m1.864s
user Om5.359s
sys Om11.220s

Interpret That For Me, Please

Just take the metadata example: to list the contents of the folder stored on the SSD, it takes about 11 seconds. With the HDD, it takes 42 minutes. And that’s just to list files. We obviously have to do more than that.

Conclusion

At this point, I think it’s wise to use an external SSD for your backups. They’re affordable, reliable, and significantly faster. They’re not flawless, and fail just like everything does, but you’ll likely be a much happier camper with one.

Small Changes (Are Still Changes)

This new Beta is mostly a “cleanup” update.

We noticed during aspects of testing, in certain combinations, the “What’s going to happen?” section of the main window didn’t always give quite the right information in some edge cases (the sizes would be missing and stuff like that).

So, it’s been extensively reworked internally, and all the various bits and pieces should appear in the expected way, in the expected order, and at the expected time.

Or so we expect.

Cough/Hack

Here at SPHQ, I’ve been a bit under the weather with my first (!) Covid-19 case (ah, I thought I was a lucky, lucky unicorn, but it seems not). Definitely out of the “woods”, so to speak, with only general tiredness and an annoying cough remaining, but if support requests seem a little slower and/or loopier than normal, let’s just chalk it up to that and not my senescence, eh?

Have At It

That’s about it! We’ve got some plans for some other things for the next significant update, but for this beta, this should do.

As always, if you already have a Beta installed, this will be offered as an update. If not, and you download and install the linked version, it will update to the next beta (etc) until the “final release” of v3.10 is out.

At that point, once that final is installed, you’ll be on the “regular” update unless you manually install a future Beta version.

Download v3.10 Beta 4

Improving Boot on Ventura and later

tl;dr

SuperDuper v3.10 B3 is now available, with various improvements, including significantly improved bootabilty for users who previously had problems. A download is available at the bottom of this post.

Or you can continue to read…

The Story

As you know, since Big Sur or so, external boot has become more difficult. Apple stopped allowing 3rd parties to copy the OS for security reasons, and enhanced asr, a command-line tool, so that it could be used to copy the OS.

Since Apple controls both the OS and asr, and can verify that chain of trust, this ensures that OS access remains secure and read-only. Combining that with various forms of cryptographic security and server-side checks allows detection of a modified OS after the fact.

Everyone who makes “bootable copies” of macOS above the sector level, since Big Sur, must use asr to make the copy.

Worthy Goals

The intention here, of course, is a good one. None of us want our system to get hacked (put your hand down, you in the back).

But we do want to be able to maintain a reliable, testable backup strategy, and many of us want to be able to run from an external drive both when diagnosing issues, to roll back some non-OS changes, or when time is of the essence, and we need to get back up and running immediately—not after doing a multi-hour restoration.

Changes

In Ventura, Apple made some new changes to allow for rapid security responses. Part of the previously described security setup—Cryptexes—also started showing up where asr no longer copied it: a new location in Preboot.

What was (and is) weird about this change requires a little discussion of how Preboot is laid out.

Since a given APFS container can hold multiple copies of the OS, Preboot and Recovery have folder structures that include UUIDs corresponding to the volume that “owns” that part of their shared volumes in the group. Inside that UUID-named folder are the files that “pair” with the system you’re trying to boot.

In Ventura and later, for some reason, one set of Cryptexes also appear outside this structure, at the top of Preboot.

Wait, What?

This is quite…strange. If the Cryptexes folder isn’t inside the appropriate UUID-based folder, then it’s shared between all of them. And if there are different systems in the same container, the Cryptexes would also be different. So they can’t be shared. (And, indeed, each Preboot sub volume also has its own Cryptexes…which we expected to be sufficient.)

What We Thought

On top of that, asr didn’t (and doesn’t) copy the Cryptexes. So we thought “well, there’s got to be a reason for this; they’re probably generating and grafting the right folder during the boot process”. And, indeed, that’s what it does.

Or seems to do.

Sometimes.

The Theory, by A. Elk (Miss)

Here’s the thing. For many users, the straight up copy, as above, seems to work just fine. Internally, on some of our test systems, backups boot as expected without trouble. Others, like my own development system, do not do so consistently.

The difference seems to have to do with what’s installed. Maybe.

On our test systems, we’re using a straight install of macOS. On my development system, which has been carried forward for years, I have some apps that require 3rd party kernel extensions.

Those extensions are necessary for some things I run, but they seem to interfere with boot. On the “plain” systems, you don’t even need the “root level” Cryptexes folder and yet it boots (using, I assume, the existing Cryptexes inside the UUID-based folder). But on others, you absolutely do need them at the top of Preboot, or you get a kernel panic.

A kernel panic we see too often, and that we’ve reported to The Powers That Be. And we’ve been waiting, for quite a while, for a fix.

That’s nice. What now?

So, what have we done? We’ve decided to not wait for asr to be fixed by TBTB. And we don’t want to continue to tell people to install the OS over the backup (which lets Apple fix the issue).

Instead, to improve bootability, and save user’s time (not to mention sanity), we’re decided to copy over the Cryptexes to the root of Preboot.

This shouldn’t be necessary…but it is. Sometimes. And in the cases where it isn’t, it doesn’t hurt anything.

Beta 3!

With no further ado, here’s Beta 3 of SuperDuper! v3.10. There are various other improvements in this beta (including much faster Diagnostics collection; see the Release Notes), with more to come in future Beta releases.

As always, if you install this Beta, subsequent v3.10 Beta releases will automatically be offered via the normal update mechanism.

When the final v3.10 comes out, you will receive that, and then you’ll be on the non-Beta release cycle again…unless you subsequently install a later Beta.

Enjoy!

Download SuperDuper! v3.10 Beta 3