🛠️ projectrestore — Secure, Atomic, Verified Project Restore
projectrestore is the companion tool to
projectclone.
It safely restores project backups created via projectclone — with strict safety guarantees, atomic replacement, rollback, checksum verification, PID locking, and tar-bomb protection.
Mission: Restore project environments safely, predictably, and without trust assumptions — even across systems.
✅ Key Features
| Capability | Description |
|---|---|
| 🔐 Atomic restore | Extracts to temp dir → atomic swap → rollback if failed |
| 🛡️ Zero-trust archive validation | Rejects suspicious tar entries (symlink, device, traversal) |
| 📦 Tarbomb protection | Max-files & max-bytes enforcement |
| 🧾 SHA-256 integrity check | Optional digest validation before restore |
| 🚫 Privilege-safe | Strip setuid/setgid, block device nodes |
| 🔄 Dry-run validation | Verify archives without touching disk |
| 🔒 PID locking | Prevent concurrent restores |
| 🧯 Crash-safe | Best-effort rollback & cleanup |
| 📁 Cross-platform | Works on Linux, Termux/Android, VPS, containers |
| ⚡ No dependencies | Pure Python — clean install, small footprint |
🧩 Installation
pip install projectrestore
Or editable dev install:
git clone https://github.com/dhruv13x/projectrestore
cd projectrestore
pip install -e .
---
🚀 Quick Start
Restore the latest backup made by projectclone:
projectrestore
Restore to a specific directory:
projectrestore --backup-dir ~/project_backups --extract-dir ./restored_project
Dry-run (validate only):
projectrestore --dry-run
Verify SHA-256 before restore:
projectrestore --checksum checksums.txt
Limit archive extraction:
projectrestore --max-files 50000 --max-bytes 2G
Debug logs:
projectrestore --debug
---
🔍 How It Works (Safety Model)
1. Validate backup archive structure & metadata
2. Create PID lock → single-instance safety
3. Extract to isolated temporary directory
4. Apply strict checks:
No absolute paths
No ../ traversal
No symlinks / hardlinks
No device nodes / FIFO
No setuid/setgid preserved
5. Optionally verify SHA-256
6. Atomic swap:
Move old dir → backup
Move new dir → destination
7. Cleanup old state (or rollback on error)
---
⚠️ Design Philosophy
> Separation of responsibilities
projectclone = capture
projectrestore = apply safely
This tool intentionally does not share codebase or execution surface with projectclone to ensure:
Security isolation
Clear trust boundary
Maintenance clarity
Lower blast radius
Independent versioning & release trains
---
🧪 Exit Codes
Code Meaning
0 Success
1 Error
2 Interrupted / signal
3 Another instance running (PID lock)
---
📂 Compatibility
System Supported
Linux ✅
WSL ✅
Termux / Android ✅
Docker ✅
macOS ⚠️ tar behavior varies — full support in v1.0
---
🤝 Ecosystem
Tool Purpose
projectclone Create stateful reproducible project snapshots
projectrestore Securely apply snapshots with verification & rollback
These tools form a reproducible project state suite.
---
📦 Future Roadmap
Interactive restore preview (file diff, size, changeset)
Restore-to-new-path mode
Encrypted backup support
Signature verification (public key)
macOS hardened extractor extension
---
✅ Requirements
Python 3.8+
Tar archives built by projectclone
---
📜 License
MIT — free, open, audit-friendly, production-safe.
---
👨💻 Author
Dhruv13x — dhruv13x@gmail.com
Designed for reproducibility, disaster-recovery, and zero-trust restore paths.
---
> ⭐️ If this project saves your work or your sanity, consider starring the repo!
Issues & PRs welcome — security mindset first.
---
Metadata
Release files for projectrestore 4.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| projectrestore-4.0.1.tar.gz | 27.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| projectrestore-4.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 47.9 kB
Release files / projectrestore-4.0.1.tar.gz
| Download URL | projectrestore-4.0.1.tar.gz |
|---|---|
| Size | 27.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
94656a41ec9ea33aed5a17467f4125fe1f58f01b5f1c780f638b40a13cf07f65
|
|
BLAKE2b-256 checksum How to use checksums |
86c8559d788504d18db19fa98c96c9ef0d85c69d5124403a3a6401bfaf17bf64
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 7, 2025.
Transparency logRelease files / projectrestore-4.0.1-py3-none-any.whl
| Download URL | projectrestore-4.0.1-py3-none-any.whl |
|---|---|
| Size | 20.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0f3efb1e855736cb56f7fce4b44cf38036ed619416df4a16d670bd985f4cf622
|
|
BLAKE2b-256 checksum How to use checksums |
43160e1f9ee19fe797cbef2ac86e76ebc59dca725a7c90b37bafe36c59952441
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 7, 2025.
Transparency log