From bd12e38b563bc8d94824c8b9e36ed4d0190279a3 Mon Sep 17 00:00:00 2001 From: Jakob Borg Date: Wed, 29 Nov 2017 07:45:17 +0100 Subject: [PATCH] gui, man: Update docs & translations --- gui/default/assets/lang/lang-fr.json | 2 +- gui/default/assets/lang/lang-ja.json | 16 +- gui/default/assets/lang/lang-ru.json | 4 +- man/stdiscosrv.1 | 36 ++-- man/strelaysrv.1 | 20 +-- man/syncthing-bep.7 | 38 ++-- man/syncthing-config.5 | 251 ++++++++++++++++++++------- man/syncthing-device-ids.7 | 50 +++--- man/syncthing-event-api.7 | 8 +- man/syncthing-faq.7 | 74 ++++---- man/syncthing-globaldisco.7 | 14 +- man/syncthing-localdisco.7 | 2 +- man/syncthing-networking.7 | 4 +- man/syncthing-relay.7 | 14 +- man/syncthing-rest-api.7 | 14 +- man/syncthing-security.7 | 12 +- man/syncthing-stignore.5 | 26 +-- man/syncthing-versioning.7 | 36 ++-- man/syncthing.1 | 18 +- 19 files changed, 382 insertions(+), 257 deletions(-) diff --git a/gui/default/assets/lang/lang-fr.json b/gui/default/assets/lang/lang-fr.json index 9af26dea2..d138d0ca2 100644 --- a/gui/default/assets/lang/lang-fr.json +++ b/gui/default/assets/lang/lang-fr.json @@ -191,7 +191,7 @@ "See external versioning help for supported templated command line parameters.": "Consulter l'aide à la gestion externe des versions pour voir les paramètres de ligne de commande supportés.", "Select a version": "Choisissez une version", "Select the devices to share this folder with.": "Synchroniser avec :", - "Select the folders to share with this device.": "Sélectionner les partages auxquels cet appareil doit participer :", + "Select the folders to share with this device.": "Choisir les partages auxquels cet appareil doit participer :", "Send & Receive": "Envoi & réception", "Send Only": "Envoi (lecture seule)", "Settings": "Configuration", diff --git a/gui/default/assets/lang/lang-ja.json b/gui/default/assets/lang/lang-ja.json index afea3bce4..c5419dbfb 100644 --- a/gui/default/assets/lang/lang-ja.json +++ b/gui/default/assets/lang/lang-ja.json @@ -24,7 +24,7 @@ "An external command handles the versioning. It has to remove the file from the shared folder.": "外部コマンドにバージョン管理を任せます。ここで指定するコマンドは、共有フォルダーからファイルを削除するものでなくてはなりません。", "An external command handles the versioning. It has to remove the file from the synced folder.": "外部コマンドにバージョンを管理させます。ここで指定するコマンドは、同期フォルダーからファイルを削除するものでなくてはなりません。", "Anonymous Usage Reporting": "匿名での使用状況レポート", - "Anonymous usage report format has changed. Would you like to move to the new format?": "Anonymous usage report format has changed. Would you like to move to the new format?", + "Anonymous usage report format has changed. Would you like to move to the new format?": "匿名での使用状況レポートのフォーマットが変わりました。新形式でのレポートに移行しますか?", "Any devices configured on an introducer device will be added to this device as well.": "紹介者デバイス上で設定されたデバイスは、このデバイス上にも追加されます。", "Automatic upgrade now offers the choice between stable releases and release candidates.": "自動アップグレードは、安定版とリリース候補版のいずれかを選べるようになりました。", "Automatic upgrades": "自動アップグレード", @@ -54,7 +54,7 @@ "Device Identification": "デバイスID", "Device Name": "デバイス名", "Devices": "デバイス", - "Disabled": "Disabled", + "Disabled": "無効", "Disconnected": "切断中", "Discovered": "探索結果", "Discovery": "探索サーバー", @@ -152,7 +152,7 @@ "Outgoing Rate Limit (KiB/s)": "上り帯域制限 (KiB/s)", "Override Changes": "他のデバイスの変更を上書きする", "Path": "パス", - "Path to the folder on the local computer. Will be created if it does not exist. The tilde character (~) can be used as a shortcut for": "ローカルコンピュータ上のフォルダーパス。フォルダーが存在しない場合は作成されます。チルダ (~) で次のフォルダーを短縮入力できます:", + "Path to the folder on the local computer. Will be created if it does not exist. The tilde character (~) can be used as a shortcut for": "ローカルコンピュータ上のフォルダーパス。フォルダーが存在しない場合は作成されます。チルダ (~) で以下のフォルダーを短縮入力できます:", "Path where versions should be stored (leave empty for the default .stversions directory in the shared folder).": "古いバージョンを保存するパス (空欄の場合、デフォルトで共有フォルダー内の .stversions ディレクトリ)", "Path where versions should be stored (leave empty for the default .stversions folder in the folder).": "古いバージョンを保存するパス (空欄の場合、デフォルトでフォルダー内の .stversions フォルダー)", "Pause": "一時停止", @@ -188,8 +188,8 @@ "Scan Time Remaining": "スキャン残り時間", "Scanning": "スキャン中", "See external versioner help for supported templated command line parameters.": "See external versioner help for supported templated command line parameters.", - "See external versioning help for supported templated command line parameters.": "See external versioning help for supported templated command line parameters.", - "Select a version": "Select a version", + "See external versioning help for supported templated command line parameters.": "使用可能なコマンドラインパラメータについてはお使いのバージョン管理ツールのヘルプを参照してください。", + "Select a version": "バージョンを選択してください", "Select the devices to share this folder with.": "このフォルダーを共有するデバイスを選択してください。", "Select the folders to share with this device.": "このデバイスと共有するフォルダーを選択してください。", "Send & Receive": "送受信", @@ -203,7 +203,7 @@ "Shared With": "共有中のデバイス", "Show ID": "IDを表示", "Show QR": "QRコードを表示", - "Show diff with previous version": "Show diff with previous version", + "Show diff with previous version": "前バージョンとの差分を表示", "Shown instead of Device ID in the cluster status. Will be advertised to other devices as an optional default name.": "ステータス画面でデバイスIDの代わりに表示されます。他のデバイスに対してもデフォルトの名前として通知されます。", "Shown instead of Device ID in the cluster status. Will be updated to the name the device advertises if left empty.": "ステータス画面でデバイスIDの代わりに表示されます。空欄にすると相手側デバイスが通知してきた名前で更新されます。", "Shutdown": "シャットダウン", @@ -229,7 +229,7 @@ "Syncthing seems to be down, or there is a problem with your Internet connection. Retrying…": "Syncthingが落ちているか、インターネット接続に問題があります。リトライ中です…", "Syncthing seems to be experiencing a problem processing your request. Please refresh the page or restart Syncthing if the problem persists.": "リクエストの処理に問題があるようです。問題が継続する場合、ページを更新するかSyncthingを再起動してください。", "The Syncthing admin interface is configured to allow remote access without a password.": "Syncthingの管理画面が、パスワードなしで外部からアクセスできるように設定されています。", - "The aggregated statistics are publicly available at the URL below.": "集計結果は次のURLで公開されています。", + "The aggregated statistics are publicly available at the URL below.": "集計結果は以下のURLで公開されています。", "The configuration has been saved but not activated. Syncthing must restart to activate the new configuration.": "設定が保存されましたが、まだ有効になっていません。新しい設定を有効にするにはSyncthingを再起動してください。", "The device ID cannot be blank.": "デバイスIDを入力してください。", "The device ID to enter here can be found in the \"Actions > Show ID\" dialog on the other device. Spaces and dashes are optional (ignored).": "ここに入力するデバイスIDは、接続したい相手側デバイスの [メニュー]→[IDを表示] で確認できます。スペースとハイフンは入力しなくてもかまいません。", @@ -259,7 +259,7 @@ "Time": "日時", "Trash Can File Versioning": "ゴミ箱によるバージョン管理", "Type": "タイプ", - "Undecided (will prompt)": "Undecided (will prompt)", + "Undecided (will prompt)": "未決定(再確認する)", "Unknown": "不明", "Unshared": "非共有", "Unused": "未使用", diff --git a/gui/default/assets/lang/lang-ru.json b/gui/default/assets/lang/lang-ru.json index d01af1e94..a6ae2c402 100644 --- a/gui/default/assets/lang/lang-ru.json +++ b/gui/default/assets/lang/lang-ru.json @@ -54,7 +54,7 @@ "Device Identification": "Идентификация устройства", "Device Name": "Имя устройства", "Devices": "Устройства", - "Disabled": "Disabled", + "Disabled": "Отключено", "Disconnected": "Нет соединения", "Discovered": "Обнаружено", "Discovery": "Обнаружение", @@ -86,7 +86,7 @@ "Files are moved to date stamped versions in a .stversions directory when replaced or deleted by Syncthing.": "Когда Syncthing изменяет или удаляет файлы, их версии с таймштампами помещаются в папку .stversions", "Files are moved to date stamped versions in a .stversions folder when replaced or deleted by Syncthing.": "Файлы с временнОй меткой версии помещаются в папку .stversions при их замене или удалении Syncthing.", "Files are protected from changes made on other devices, but changes made on this device will be sent to the rest of the cluster.": "Файлы защищены от изменений сделанных на других устройствах, но изменения сделанные на этом устройстве будут отправлены всему кластеру.", - "Filesystem Notifications": "Filesystem Notifications", + "Filesystem Notifications": "Уведомления файловой системы", "Folder": "Папка", "Folder ID": "ID папки", "Folder Label": "Ярлык папки", diff --git a/man/stdiscosrv.1 b/man/stdiscosrv.1 index 65da64852..be6056714 100644 --- a/man/stdiscosrv.1 +++ b/man/stdiscosrv.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "STDISCOSRV" "1" "November 18, 2017" "v0.14" "Syncthing" +.TH "STDISCOSRV" "1" "Nov 23, 2017" "v0.14" "Syncthing" .SH NAME stdiscosrv \- Syncthing Discovery Server . @@ -51,17 +51,17 @@ can run a discovery server and point Syncthing installations to it. .INDENT 0.0 .TP .B \-cert= -Certificate file (default "cert.pem"). +Certificate file (default “cert.pem”). .UNINDENT .INDENT 0.0 .TP .B \-db\-backend= -Database backend to use (default "ql"). +Database backend to use (default “ql”). .UNINDENT .INDENT 0.0 .TP .B \-db\-dsn= -Database DSN (default "memory://stdiscosrv"). +Database DSN (default “memory://stdiscosrv”). .UNINDENT .INDENT 0.0 .TP @@ -76,7 +76,7 @@ Listen on HTTP (behind an HTTPS proxy). .INDENT 0.0 .TP .B \-key= -Key file (default "key.pem"). +Key file (default “key.pem”). .UNINDENT .INDENT 0.0 .TP @@ -96,7 +96,7 @@ Limiter cache entries (default 10240). .INDENT 0.0 .TP .B \-listen=
-Listen address (default ":8443"). +Listen address (default “:8443”). .UNINDENT .INDENT 0.0 .TP @@ -107,8 +107,8 @@ File to write periodic operation stats to. .sp By default, Syncthing uses a number of global discovery servers, signified by the entry \fBdefault\fP in the list of discovery servers. To make Syncthing use -your own instance of stdiscosrv, open up Syncthing\(aqs web GUI. Go to settings, -Global Discovery Server and add stdiscosrv\(aqs host address to the comma\-separated +your own instance of stdiscosrv, open up Syncthing’s web GUI. Go to settings, +Global Discovery Server and add stdiscosrv’s host address to the comma\-separated list, e.g. \fBhttps://disco.example.com:8443/v2/\fP\&. Note that stdiscosrv uses port 8443 by default. For stdiscosrv to be available over the internet with a dynamic IP address, you will need a dynamic DNS service. @@ -119,7 +119,7 @@ entry from the list. .SS Description .sp This guide assumes that you have already set up Syncthing. If you -haven\(aqt yet, head over to getting\-started first. +haven’t yet, head over to getting\-started first. .SS Installing .sp Go to \fI\%releases\fP <\fBhttps://build.syncthing.net/job/stdiscosrv\fP> and @@ -129,7 +129,7 @@ this in whatever way you are most comfortable with; double clicking should work in any graphical environment. At first start, stdiscosrv will generate the directory \fB/var/stdiscosrv\fP (\fBX:\evar\estdiscosrv\fP on Windows, where X is the partition \fBstdiscosrv.exe\fP is executed from) with configuration. If the user -running \fBstdiscosrv\fP doesn\(aqt have permission to do so, create the directory +running \fBstdiscosrv\fP doesn’t have permission to do so, create the directory and set the owner appropriately or use the command line switches (see below) to select a different location. .SS Configuring @@ -151,10 +151,10 @@ from clients there are three options: .IP \(bu 2 Use a CA\-signed certificate pair for the domain name you will use for the discovery server. This is like any other HTTPS website; clients will -authenticate the server based on it\(aqs certificate and domain name. +authenticate the server based on it’s certificate and domain name. .IP \(bu 2 Use any certificate pair and let clients authenticate the server based on -it\(aqs "device ID" (similar to Syncthing\-to\-Syncthing authentication). In +it’s “device ID” (similar to Syncthing\-to\-Syncthing authentication). In this case, using \fBsyncthing \-generate\fP is a good option to create a certificate pair. .IP \(bu 2 @@ -163,7 +163,7 @@ reverse proxy. See below for configuration. .UNINDENT .sp For the first two options, the discovery server must be given the paths to -the certificate and key at startup. This isn\(aqt necessary with the \fBhttp\fP flag: +the certificate and key at startup. This isn’t necessary with the \fBhttp\fP flag: .INDENT 0.0 .INDENT 3.5 .sp @@ -176,7 +176,7 @@ Server device ID is 7DDRT7J\-UICR4PM\-PBIZYL3\-MZOJ7X7\-EX56JP6\-IK6HHMW\-S7EK32 .UNINDENT .UNINDENT .sp -The discovery server prints it\(aqs device ID at startup. In the case where you +The discovery server prints it’s device ID at startup. In the case where you are using a non CA signed certificate, this device ID (fingerprint) must be given to the clients in the discovery server URL: .INDENT 0.0 @@ -218,10 +218,10 @@ Run the discovery server using the \-http flag \fBstdiscosrv \-http\fP\&. .IP \(bu 2 SSL certificate/key configured for the reverse proxy .IP \(bu 2 -The "X\-Forwarded\-For" http header must be passed through with the client\(aqs +The “X\-Forwarded\-For” http header must be passed through with the client’s real IP address .IP \(bu 2 -The "X\-SSL\-Cert" must be passed through with the PEM\-encoded client SSL +The “X\-SSL\-Cert” must be passed through with the PEM\-encoded client SSL certificate .IP \(bu 2 The proxy must request the client SSL certificate but not require it to be @@ -296,10 +296,10 @@ server { .UNINDENT .sp An example of automating the SSL certificates and reverse\-proxying the Discovery -Server and Syncthing using Nginx, \fI\%Let\(aqs Encrypt\fP <\fBhttps://letsencrypt.org/\fP> and Docker can be found \fI\%here\fP <\fBhttps://forum.syncthing.net/t/docker-syncthing-and-syncthing-discovery-behind-nginx-reverse-proxy-with-lets-encrypt/6880\fP>\&. +Server and Syncthing using Nginx, \fI\%Let’s Encrypt\fP <\fBhttps://letsencrypt.org/\fP> and Docker can be found \fI\%here\fP <\fBhttps://forum.syncthing.net/t/docker-syncthing-and-syncthing-discovery-behind-nginx-reverse-proxy-with-lets-encrypt/6880\fP>\&. .SH SEE ALSO .sp -\fIsyncthing\-networking(7)\fP, \fIsyncthing\-faq(7)\fP +\fBsyncthing\-networking(7)\fP, \fBsyncthing\-faq(7)\fP .SH AUTHOR The Syncthing Authors .SH COPYRIGHT diff --git a/man/strelaysrv.1 b/man/strelaysrv.1 index 837a1c5a9..605917d01 100644 --- a/man/strelaysrv.1 +++ b/man/strelaysrv.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "STRELAYSRV" "1" "November 18, 2017" "v0.14" "Syncthing" +.TH "STRELAYSRV" "1" "Nov 23, 2017" "v0.14" "Syncthing" .SH NAME strelaysrv \- Syncthing Relay Server . @@ -72,12 +72,12 @@ Global rate limit, in bytes/s. .INDENT 0.0 .TP .B \-keys= -Directory where cert.pem and key.pem is stored (default "."). +Directory where cert.pem and key.pem is stored (default “.”). .UNINDENT .INDENT 0.0 .TP .B \-listen= -Protocol listen address (default ":22067"). +Protocol listen address (default “:22067”). .UNINDENT .INDENT 0.0 .TP @@ -127,13 +127,13 @@ How often pings are sent (default 1m0s). .TP .B \-pools= Comma separated list of relay pool addresses to join (default -"\fI\%http://relays.syncthing.net/endpoint\fP"). Blank to disable announcement to +“\fI\%http://relays.syncthing.net/endpoint\fP”). Blank to disable announcement to a pool, thereby remaining a private relay. .UNINDENT .INDENT 0.0 .TP .B \-protocol= -Protocol used for listening. \(aqtcp\(aq for IPv4 and IPv6, \(aqtcp4\(aq for IPv4, \(aqtcp6\(aq for IPv6 (default "tcp"). +Protocol used for listening. ‘tcp’ for IPv4 and IPv6, ‘tcp4’ for IPv4, ‘tcp6’ for IPv6 (default “tcp”). .UNINDENT .INDENT 0.0 .TP @@ -143,7 +143,7 @@ An optional description about who provides the relay. .INDENT 0.0 .TP .B \-status\-srv= -Listen address for status service (blank to disable) (default ":22070"). +Listen address for status service (blank to disable) (default “:22070”). Status service is used by the relay pool server UI for displaying stats (data transfered, number of clients, etc.) .UNINDENT .SH SETTING UP @@ -191,7 +191,7 @@ relay://private\-relay\-1.example.com:443/?id=ITZRNXE\-YNROGBZ\-HXTH5P7\-VK5NYE5 .UNINDENT .UNINDENT .sp -The relay\(aqs device ID is output on start\-up. +The relay’s device ID is output on start\-up. .SS Running on port 443 as an unprivileged user .sp It is recommended that you run the relay on port 443 (or another port which is @@ -213,7 +213,7 @@ iptables \-t nat \-A PREROUTING \-i eth0 \-p tcp \-\-dport 443 \-j REDIRECT \-\- .UNINDENT .UNINDENT .sp -Or, if you\(aqre using \fBufw\fP, add the following to \fB/etc/ufw/before.rules\fP: +Or, if you’re using \fBufw\fP, add the following to \fB/etc/ufw/before.rules\fP: .INDENT 0.0 .INDENT 3.5 .sp @@ -266,8 +266,8 @@ iptables \-I INPUT \-p tcp \-\-dport 22070 \-j ACCEPT Please consult Linux distribution documentation to persist firewall rules. .SH SEE ALSO .sp -\fIsyncthing\-relay(7)\fP, \fIsyncthing\-faq(7)\fP, -\fIsyncthing\-networking(7)\fP +\fBsyncthing\-relay(7)\fP, \fBsyncthing\-faq(7)\fP, +\fBsyncthing\-networking(7)\fP .SH AUTHOR The Syncthing Authors .SH COPYRIGHT diff --git a/man/syncthing-bep.7 b/man/syncthing-bep.7 index 4381b90c7..6d6ca3567 100644 --- a/man/syncthing-bep.7 +++ b/man/syncthing-bep.7 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SYNCTHING-BEP" "7" "November 18, 2017" "v0.14" "Syncthing" +.TH "SYNCTHING-BEP" "7" "Nov 23, 2017" "v0.14" "Syncthing" .SH NAME syncthing-bep \- Block Exchange Protocol v1 . @@ -44,8 +44,8 @@ other devices in the cluster. File data is described and transferred in units of \fIblocks\fP, each being 128 KiB (131072 bytes) in size. .sp -The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", -"SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this +The key words “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, +“SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “MAY”, and “OPTIONAL” in this document are to be interpreted as described in RFC 2119. .SH TRANSPORT AND AUTHENTICATION .sp @@ -70,8 +70,8 @@ v ... v .UNINDENT .sp The encryption and authentication layer SHALL use TLS 1.2 or a higher -revision. A strong cipher suite SHALL be used, with "strong cipher -suite" being defined as being without known weaknesses and providing +revision. A strong cipher suite SHALL be used, with “strong cipher +suite” being defined as being without known weaknesses and providing Perfect Forward Secrecy (PFS). Examples of strong cipher suites are given at the end of this document. This is not to be taken as an exhaustive list of allowed cipher suites but represents best practices @@ -83,7 +83,7 @@ connection. Possibilities include certificates signed by a common trusted CA, preshared certificates, preshared certificate fingerprints or certificate pinning combined with some out of band first verification. The reference implementation uses preshared certificate -fingerprints (SHA\-256) referred to as "Device IDs". +fingerprints (SHA\-256) referred to as “Device IDs”. .sp There is no required order or synchronization among BEP messages except as noted per message type \- any message type may be sent at any time and @@ -92,9 +92,9 @@ another. .sp The underlying transport protocol MUST guarantee reliable packet delivery. .sp -In this document, in diagrams and text, "bit 0" refers to the \fImost -significant\fP bit of a word; "bit 15" is thus the least significant bit of a -16 bit word (int16) and "bit 31" is the least significant bit of a 32 bit +In this document, in diagrams and text, “bit 0” refers to the \fImost +significant\fP bit of a word; “bit 15” is thus the least significant bit of a +16 bit word (int16) and “bit 31” is the least significant bit of a 32 bit word (int32). Non protocol buffer integers are always represented in network byte order (i.e., big endian) and are signed unless stated otherwise, but when describing message lengths negative values do not make sense and the @@ -107,7 +107,7 @@ message is \fIvalid\fP with all fields empty \- for example, an index entry for file that does not have a name is not useful and MAY be rejected by the implementation. However the folder label is for human consumption only so an empty label should be accepted \- the implementation will have to choose some -way to represent the folder, perhaps by using the ID in it\(aqs place or +way to represent the folder, perhaps by using the ID in it’s place or automatically generating a label. .SH PRE-AUTHENTICATION MESSAGES .sp @@ -169,7 +169,7 @@ name or host name, for the remote device. The \fBclient_name\fP and \fBclient_version\fP identifies the implementation. The values SHOULD be simple strings identifying the implementation name, as a user would expect to see it, and the version string in the same manner. An -example client name is "syncthing" and an example client version is "v0.7.2". +example client name is “syncthing” and an example client version is “v0.7.2”. The client version field SHOULD follow the patterns laid out in the \fI\%Semantic Versioning\fP <\fBhttp://semver.org/\fP> standard. .sp @@ -460,7 +460,7 @@ The \fBfiles\fP field is a list of files making up the index information. The \fBname\fP is the file name path relative to the folder root. Like all strings in BEP, the Name is always in UTF\-8 NFC regardless of operating system or file system specific conventions. The name field uses the slash -character ("/") as path separator, regardless of the implementation\(aqs +character (“/”) as path separator, regardless of the implementation’s operating system conventions. The combination of folder and name uniquely identifies each file in a cluster. .sp @@ -519,7 +519,7 @@ symlink type. It is empty for all other entry types. .SS Request .sp The Request message expresses the desire to receive a data block -corresponding to a part of a certain file in the peer\(aqs folder. +corresponding to a part of a certain file in the peer’s folder. .SS Protocol Buffer Schema .INDENT 0.0 .INDENT 3.5 @@ -542,7 +542,7 @@ message Request { .SS Fields .sp The \fBid\fP is the request identifier. It will be matched in the -corresponding \fBRequest\fP message. Each outstanding request must have a +corresponding \fBResponse\fP message. Each outstanding request must have a unique ID. .sp The \fBfolder\fP and \fBname\fP fields are as documented for the Index message. @@ -556,7 +556,7 @@ requested hash. The other device MAY reuse a block from a different file and offset having the same size and hash, if one exists. .sp The \fBfrom temporary\fP field is set to indicate that the read should be -performed from the temporary file (converting name to it\(aqs temporary form) +performed from the temporary file (converting name to it’s temporary form) and falling back to the non temporary file if any error occurs. Knowledge of contents of temporary files comes from DownloadProgress messages. .SS Response @@ -754,7 +754,7 @@ directions. .sp In send\-only mode, a device does not apply any updates from the cluster, but publishes changes of its local folder to the cluster as usual. The local -folder can be seen as a "master copy" that is never affected by the actions +folder can be seen as a “master copy” that is never affected by the actions of other cluster devices. .INDENT 0.0 .INDENT 3.5 @@ -783,7 +783,7 @@ index data. For situations with large indexes or frequent reconnects this can be quite inefficient. A mechanism can then be used to retain index data between connections and only transmit any changes since that data on connection -start. This is called "delta indexes". To enable this mechanism the +start. This is called “delta indexes”. To enable this mechanism the \fBsequence\fP and \fBindex ID\fP fields are used. .INDENT 0.0 .TP @@ -832,7 +832,7 @@ Update messages rather than sending a very large Index message. The Syncthing implementation imposes a hard limit of 500,000,000 bytes on all messages. Attempting to send or receive a larger message will result in a connection close. This size was chosen to accommodate Index messages -containing a large block list. It\(aqs intended that the limit may be further +containing a large block list. It’s intended that the limit may be further reduced in a future protocol update supporting variable block sizes (and thus shorter block lists for large files). .SH EXAMPLE EXCHANGE @@ -943,7 +943,7 @@ T} T{ T} _ T{ -\&... +… T} T{ T} T{ T} diff --git a/man/syncthing-config.5 b/man/syncthing-config.5 index 529e1c962..febbde829 100644 --- a/man/syncthing-config.5 +++ b/man/syncthing-config.5 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SYNCTHING-CONFIG" "5" "November 18, 2017" "v0.14" "Syncthing" +.TH "SYNCTHING-CONFIG" "5" "Nov 23, 2017" "v0.14" "Syncthing" .SH NAME syncthing-config \- Syncthing Configuration . @@ -58,7 +58,7 @@ directory the following files are located: The configuration file, in XML format. .TP .B \fBcert.pem\fP, \fBkey.pem\fP -The device\(aqs RSA public and private key. These form the basis for the +The device’s RSA public and private key. These form the basis for the device ID. The key must be kept private. .TP .B \fBhttps\-cert.pem\fP, \fBhttps\-key.pem\fP @@ -81,9 +81,10 @@ The following shows an example of the default configuration file (IDs will diffe .sp .nf .ft C - - + + + basic 1 0 @@ -92,17 +93,19 @@ The following shows an example of the default configuration file (IDs will diffe random false 0 - 0 0 \-1 false false - false + false + 25 + .stfolder - +
dynamic
+ false
- +
127.0.0.1:8384
k1dnz1Dd0rzTBjjFFh7CXPnrF12C49B1 default @@ -125,21 +128,34 @@ The following shows an example of the default configuration file (IDs will diffe 30 10 0 - + 0 + LFWe2vn3 https://data.syncthing.net/newdata false 1800 true 12 + false 24 false 5 false 1 - https://api.github.com/repos/syncthing/syncthing/releases?per_page=30 + https://upgrades.syncthing.net/meta.json false 10 + 0 + auto + default + 24 + false + 25 + false + true + 128 + 128 ~ + 0
.ft P @@ -147,22 +163,55 @@ The following shows an example of the default configuration file (IDs will diffe .UNINDENT .UNINDENT .SH CONFIGURATION ELEMENT +.INDENT 0.0 +.INDENT 3.5 .sp -This is the root element. +.nf +.ft C + + + + + + 5SYI2FS\-LW6YAXI\-JJDYETS\-NDBBPIO\-256MWBO\-XDPXWVG\-24QPUM4\-PDW4UQU + bd7q3\-zskm5 + +.ft P +.fi +.UNINDENT +.UNINDENT +.sp +This is the root element. It has one attribute: .INDENT 0.0 .TP .B version The config version. Increments whenever a change is made that requires migration from previous formats. .UNINDENT +.sp +It contains the elements described in the following sections and these two +additional child elements: +.INDENT 0.0 +.TP +.B ignoredDevice +Contains the ID of the device that should be ignored. Connection attempts +from this device are logged to the console but never displayed in the web +GUI. +.TP +.B ignoredFolder +Contains the ID of the folder that should be ignored. This folder will +always be skipped when advertised from a remote device, i.e. this will be +logged, but there will be no dialog about it in the web GUI. +.UNINDENT .SH FOLDER ELEMENT .INDENT 0.0 .INDENT 3.5 .sp .nf .ft C - - + + + basic 1 0 @@ -171,12 +220,13 @@ migration from previous formats. random false 0 - 0 0 \-1 false false - false + false + 25 + .stfolder .ft P .fi @@ -208,7 +258,7 @@ Controls how the folder is handled by Syncthing. Possible values are: The folder is in default mode. Sending local and accepting remote changes. .TP .B readonly -The folder is in "send\-only" mode \-\- it will not be modified by +The folder is in “send\-only” mode – it will not be modified by Syncthing on this device. .UNINDENT .TP @@ -216,6 +266,13 @@ Syncthing on this device. The rescan interval, in seconds. Can be set to zero to disable when external plugins are used to trigger rescans. .TP +.B fsWatcherEnabled +If enabled this detects changes to files in the folder and scans them. +.TP +.B fsWatcherDelayS +The duration during which changes detected are accumulated, before a scan is +scheduled (only takes effect if fsWatcherEnabled is true). +.TP .B ignorePerms True if the folder should ignore permissions. .TP @@ -257,7 +314,7 @@ versioning .B copiers, pullers, hashers The number of copier, puller and hasher routines to use, or zero for the system determined optimum. These are low level performance options for -advanced users only; do not change unless requested to or you\(aqve actually +advanced users only; do not change unless requested to or you’ve actually read and understood the code yourself. :) .TP .B order @@ -288,9 +345,9 @@ delete files from other devices. The interval with which scan progress information is sent to the GUI. Zero means the default value (two seconds). .TP -.B pullerSleepS, pullerPauseS -Tweaks for rate limiting the puller. Don\(aqt change these unless you know -what you\(aqre doing. +.B pullerPauseS +Tweak for rate limiting the puller when it retries pulling files. Don’t +change these unless you know what you’re doing. .TP .B maxConflicts The maximum number of conflict copies to keep around for any given file. @@ -307,9 +364,30 @@ By default, devices exchange information about blocks available in transfers that are still in progress. When set to true, such information is not exchanged for this folder. .TP +.B paused +True if this folder is (temporarily) suspended. +.TP +.B weakHashThresholdPct +Use weak hash if more than the given percentage of the file has changed. Set +to \-1 to always use weak hash. Default value is 25. +.TP +.B markerName +Name of a directory or file in the folder root to be used as +marker\-faq\&. Default is “.stfolder”. +.TP .B fsync +Deprecated since version v0.14.37. + +.sp Transfer updated (from other devices) files to permanent storage before committing the changes to the internal database. +.TP +.B pullerSleepS +Deprecated since version v0.14.41. + +.sp +Tweak for rate limiting the puller. Don’t change these unless you know +what you’re doing. .UNINDENT .SH DEVICE ELEMENT .INDENT 0.0 @@ -317,11 +395,13 @@ committing the changes to the internal database. .sp .nf .ft C - +
dynamic
tcp://192.0.2.1:22001
+ true + 192.168.0.0/16
.ft P .fi @@ -382,11 +462,16 @@ to even if the original introducer is no longer listing the remote device as kno Defines which device has introduced us to this device. Used only for following de\-introductions. .UNINDENT .sp -In addition, one or more \fBaddress\fP child elements must be present. Each -contains an address or host name to use when attempting to connect to this device and will -be tried in order. Entries other than \fBdynamic\fP must be prefixed with \fBtcp://\fP (dual\-stack), \fBtcp4://\fP (IPv4 only) or \fBtcp6://\fP (IPv6 only). Note that IP addresses need not use tcp4/tcp6; these are optional. Accepted formats are: +From following child elements at least one \fBaddress\fP child must exist. .INDENT 0.0 .TP +.B address +Contains an address or host name to use when attempting to connect to this device. +Entries other than \fBdynamic\fP must be prefixed with \fBtcp://\fP (dual\-stack), +\fBtcp4://\fP (IPv4 only) or \fBtcp6://\fP (IPv6 only). Note that IP addresses need +not use tcp4/tcp6; these are optional. Accepted formats are: +.INDENT 7.0 +.TP .B IPv4 address (\fBtcp://192.0.2.42\fP) The default port (22000) is used. .TP @@ -402,35 +487,32 @@ The address and port is used as given. The address must be enclosed in square brackets. .TP .B Host name (\fBtcp6://fileserver\fP) -The host name will be used on the default port (22000) and connections will be attempted only via IPv6. +The host name will be used on the default port (22000) and connections +will be attempted only via IPv6. .TP .B Host name and port (\fBtcp://fileserver:12345\fP) -The host name will be used on the given port and connections will be attempted via both IPv4 and IPv6, depending on name resolution. +The host name will be used on the given port and connections will be +attempted via both IPv4 and IPv6, depending on name resolution. .TP .B \fBdynamic\fP -The word \fBdynamic\fP (without \fBtcp://\fP prefix) means to use local and global discovery to find the -device. +The word \fBdynamic\fP (without \fBtcp://\fP prefix) means to use local and +global discovery to find the device. .UNINDENT -.SH IGNOREDDEVICE ELEMENT -.INDENT 0.0 -.INDENT 3.5 -.sp -.nf -.ft C -5SYI2FS\-LW6YAXI\-JJDYETS\-NDBBPIO\-256MWBO\-XDPXWVG\-24QPUM4\-PDW4UQU -.ft P -.fi +.TP +.B paused +True if synchronization with this devices is (temporarily) suspended. +.TP +.B allowedNetwork +If given, this restricts connections to this device to only this network +(see allowed\-networks). .UNINDENT -.UNINDENT -.sp -This optional element lists device IDs that have been specifically ignored. One element must be present for each device ID. Connection attempts from these devices are logged to the console but never displayed in the web GUI. .SH GUI ELEMENT .INDENT 0.0 .INDENT 3.5 .sp .nf .ft C - +
127.0.0.1:8384
l7jSbCqPD95JYZ0g8vi4ZLAMg3ulnN1b default @@ -453,8 +535,8 @@ If set to \fBtrue\fP, TLS (HTTPS) will be enforced. Non\-HTTPS requests will be redirected to HTTPS. When this is set to \fBfalse\fP, TLS connections are still possible but it is not mandatory. .TP -.B theme -The name of the theme to use. +.B debugging +This enables profiling and additional debugging endpoints in the rest\-api\&. .UNINDENT .sp The following child elements may be present: @@ -484,6 +566,13 @@ Contains the bcrypt hash of the real password. .TP .B apikey If set, this is the API key that enables usage of the REST interface. +.TP +.B insecureAdminAccess +If true, this allows access to the web GUI from outside (i.e. not localhost) +without authorization. A warning will displayed about this setting on startup. +.TP +.B theme +The name of the theme to use. .UNINDENT .SH OPTIONS ELEMENT .INDENT 0.0 @@ -560,12 +649,6 @@ The port on which to listen and send IPv4 broadcast announcements to. .B localAnnounceMCAddr The group address and port to join and send IPv6 multicast announcements on. .TP -.B relayServer -Lists one or more relay servers, on the format \fBrelay://hostname:port\fP\&. -Alternatively, a relay list can be loaded over https by using an URL like -\fBdynamic+https://somehost/path\fP\&. The default loads the list of relays -from the relay pool server, \fBrelays.syncthing.net\fP\&. -.TP .B maxSendKbps Outgoing data rate limit, in kibibytes per second. .TP @@ -604,6 +687,9 @@ Whether the user has accepted to submit anonymous usage data. The default, point in the future. \fB\-1\fP means no, a number above zero means that that version of usage reporting has been accepted. .TP +.B urSeen +The highest usage reporting version that has already been shown in the web GUI. +.TP .B urUniqueID The unique ID sent together with the usage report. Generated when usage reporting is enabled. @@ -627,6 +713,10 @@ waking from sleep mode (i.e. a folded up laptop). Check for a newer version after this many hours. Set to zero to disable automatic upgrades. .TP +.B upgradeToPreReleases +If true, automatical upgrades include release candidates (see +release\-channels). +.TP .B keepTemporariesH Keep temporary failed transfers for this many hours. While the temporaries are kept, the data they contain need not be transferred again. @@ -644,18 +734,6 @@ the GUI. Whether to apply bandwidth limits to devices in the same broadcast domain as the local device. .TP -.B databaseBlockCacheMiB -Override the automatically calculated database block cache size. Don\(aqt, -unless you\(aqre very short on memory, in which case you want to set this to -\fB8\fP\&. -.TP -.B pingTimeoutS -Ping\-timeout in seconds. Don\(aqt change it unless you are having issues due to -slow response time (slow connection/cpu) and large index exchanges. -.TP -.B pingIdleTimeS -Ping interval in seconds. Don\(aqt change it unless you feel it\(aqs necessary. -.TP .B minHomeDiskFree The minimum required free space that should be available on the partition holding the configuration and index. Accepted units are \fB%\fP, \fBkB\fP, @@ -664,6 +742,9 @@ partition holding the configuration and index. Accepted units are \fB%\fP, \fBkB .B releasesURL The URL from which release information is loaded, for automatic upgrades. .TP +.B alwaysLocalNet +Network that should be considered as local given in CIDR notation. +.TP .B overwriteRemoteDeviceNamesOnConnect If set, device names will always be overwritten with the name given by remote on each connection. By default, the name that the remote device @@ -673,9 +754,53 @@ announces will only be adopted when a name has not already been set. When exchanging index information for incomplete transfers, only take into account files that have at least this many blocks. .TP +.B unackedNotificationID +ID of a notification to be displayed in the web GUI. Will be removed once +the user acknowledged it (e.g. an transition notice on an upgrade). +.TP +.B trafficClass +Specify a type of service (TOS)/traffic class of outgoing packets. +.TP +.B weakHashSelectionMethod +Specify whether weak hashing is used, possible options are +\fBWeakHashAlways\fP, \fBWeakHashNever\fP and \fBWeakHashAuto\fP\&. Deciding +automatically means running benchmarks at startup to decide whether the +performance impact is acceptable (this is the default). +.TP +.B stunServer +Specify whether weak hashing is used, possible options are +.TP +.B stunKeepaliveSeconds +Specify whether weak hashing is used, possible options are +.TP +.B kcpNoDelay, kcpUpdateIntervalMs, kcpFastResend, kcpCongestionControl, kcpSendWindowSize, kcpReceiveWindowSize +Various KCP tweaking parameters. +.TP .B defaultFolderPath The UI will propose to create new folders at this path. This can be disabled by setting this to an empty string. +.TP +.B relayServer +Deprecated since version v0.13.0: You can now specify custom relay servers with \fBlistenAddress\fP\&. + +.sp +Lists one or more relay servers, on the format \fBrelay://hostname:port\fP\&. +Alternatively, a relay list can be loaded over https by using an URL like +\fBdynamic+https://somehost/path\fP\&. The default loads the list of relays +from the relay pool server, \fBrelays.syncthing.net\fP\&. +.TP +.B pingTimeoutS +Deprecated since version v0.12.0. + +.sp +Ping\-timeout in seconds. Don’t change it unless you are having issues due to +slow response time (slow connection/cpu) and large index exchanges. +.TP +.B pingIdleTimeS +Deprecated since version v0.12.0. + +.sp +Ping interval in seconds. Don’t change it unless you feel it’s necessary. .UNINDENT .SS Listen Addresses .sp @@ -741,9 +866,9 @@ that the files you are backing up are in a folder\-sendonly to prevent other devices from overwriting the per device configuration. The folder on the remote device(s) should not be used as configuration for the remote devices. .sp -If you\(aqd like to sync your home folder in non\-send\-only mode, you may add the +If you’d like to sync your home folder in non\-send\-only mode, you may add the folder that stores the configuration files to the ignore list\&. -If you\(aqd also like to backup your configuration files, add another folder in +If you’d also like to backup your configuration files, add another folder in send\-only mode for just the configuration folder. .SH AUTHOR The Syncthing Authors diff --git a/man/syncthing-device-ids.7 b/man/syncthing-device-ids.7 index 1ee98e81c..1c918dcd7 100644 --- a/man/syncthing-device-ids.7 +++ b/man/syncthing-device-ids.7 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SYNCTHING-DEVICE-IDS" "7" "November 18, 2017" "v0.14" "Syncthing" +.TH "SYNCTHING-DEVICE-IDS" "7" "Nov 23, 2017" "v0.14" "Syncthing" .SH NAME syncthing-device-ids \- Understanding Device IDs . @@ -33,8 +33,8 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]] .SH DESCRIPTION .sp Every device is identified by a device ID. The device ID is used for address -resolution, authentication and authorization. The term "device ID" could -interchangeably have been "key ID" since the device ID is a direct property of +resolution, authentication and authorization. The term “device ID” could +interchangeably have been “key ID” since the device ID is a direct property of the public key in use. .SH KEYS .sp @@ -43,7 +43,7 @@ startup, Syncthing will create a public/private keypair. .sp Currently this is a 3072 bit RSA key. The keys are saved in the form of the private key (\fBkey.pem\fP) and a self signed certificate (\fBcert.pem\fP). The self -signing part doesn\(aqt actually add any security or functionality as far as +signing part doesn’t actually add any security or functionality as far as Syncthing is concerned but it enables the use of the keys in a standard TLS exchange. .sp @@ -94,7 +94,7 @@ Certificate: .sp We can see here that the certificate is little more than a container for the public key; the serial number is zero and the Issuer and Subject are both -"syncthing" where a qualified name might otherwise be expected. +“syncthing” where a qualified name might otherwise be expected. .sp An advanced user could replace the \fBkey.pem\fP and \fBcert.pem\fP files with a keypair generated directly by the \fBopenssl\fP utility or other mechanism. @@ -138,7 +138,7 @@ MFZWI3D\-BONSGYC\-YLTMRWG\-C43ENR5\-QXGZDMM\-FZWI3DP\-BONSGYY\-LTMRWAD .UNINDENT .SS Connection Establishment .sp -Now we know what device IDs are, here\(aqs how they are used in Syncthing. When +Now we know what device IDs are, here’s how they are used in Syncthing. When you add a device ID to the configuration, Syncthing will attempt to connect to that device. The first thing we need to do is figure out the IP and port to connect to. There are three possibilities here: @@ -150,13 +150,13 @@ dynamic DNS setup this might be a good option. .IP \(bu 2 Using local discovery, if enabled. Every Syncthing instance on a LAN periodically broadcasts information about itself (device ID, address, -port number). If we\(aqve seen one of these broadcasts for a given -device ID that\(aqs where we try to connect. +port number). If we’ve seen one of these broadcasts for a given +device ID that’s where we try to connect. .IP \(bu 2 Using global discovery, if enabled. Every Syncthing instance announces itself to the global discovery service (device ID and external port number \- the internal address is not announced to the -global server). If we don\(aqt have a static address and haven\(aqt seen +global server). If we don’t have a static address and haven’t seen any local announcements the global discovery server will be queried for an address. .UNINDENT @@ -188,11 +188,11 @@ The SHA\-256 hash is cryptographically collision resistant. This means that there is no way that we know of to create two different messages with the same hash. .sp -You can argue that of course there are collisions \- there\(aqs an infinite +You can argue that of course there are collisions \- there’s an infinite amount of inputs and a finite amount of outputs \- so by definition there are infinitely many messages that result in the same hash. .sp -I\(aqm going to quote \fI\%stack +I’m going to quote \fI\%stack overflow\fP <\fBhttps://stackoverflow.com/questions/4014090/is-it-safe-to-ignore-the-possibility-of-sha-collisions-in-practice\fP> here: .INDENT 0.0 @@ -203,28 +203,28 @@ civilization\-as\-we\- know\-it, and killing off a few billion people ? It can be argued that any unlucky event with a probability lower than that is not actually very important. .sp -If we have a "perfect" hash function with output size n, and we have +If we have a “perfect” hash function with output size n, and we have p messages to hash (individual message length is not important), then probability of collision is about p2/2n+1 (this is an -approximation which is valid for "small" p, i.e. substantially +approximation which is valid for “small” p, i.e. substantially smaller than 2n/2). For instance, with SHA\-256 (n=256) and one billion messages (p=10^9) then the probability is about 4.3*10^\-60. .sp A mass\-murderer space rock happens about once every 30 million years on average. This leads to a probability of such an event occurring -in the next second to about 10^\-15. That\(aqs 45 orders of magnitude +in the next second to about 10^\-15. That’s 45 orders of magnitude more probable than the SHA\-256 collision. Briefly stated, if you find SHA\-256 collisions scary then your priorities are wrong. .UNINDENT .UNINDENT .sp -It\(aqs also worth noting that the property of SHA\-256 that we are using is not +It’s also worth noting that the property of SHA\-256 that we are using is not simply collision resistance but resistance to a preimage attack, i.e. even if -you can find two messages that result in a hash collision that doesn\(aqt help you +you can find two messages that result in a hash collision that doesn’t help you attack Syncthing (or TLS in general). You need to create a message that hashes -to exactly the hash that my certificate already has or you won\(aqt get in. +to exactly the hash that my certificate already has or you won’t get in. .sp -Note also that it\(aqs not good enough to find a random blob of bits that happen to +Note also that it’s not good enough to find a random blob of bits that happen to have the same hash as my certificate. You need to create a valid DER\-encoded, signed certificate that has the same hash as mine. The difficulty of this is staggeringly far beyond the already staggering difficulty of finding a SHA\-256 @@ -239,8 +239,8 @@ Currently, neither the local nor global discovery mechanism is protected by crypto. This means that any device can in theory announce itself for any device ID and potentially receive connections for that device. .sp -This could be a denial of service attack (we can\(aqt find the real device -for a given device ID, so can\(aqt connect to it and sync). It could also +This could be a denial of service attack (we can’t find the real device +for a given device ID, so can’t connect to it and sync). It could also be an intelligence gathering attack; if I spoof a given ID, I can see which devices try to connect to it. .sp @@ -259,21 +259,21 @@ The user could statically configure IP or host name for the devices. The user could run a trusted global server. .UNINDENT .sp -It\(aqs something we might want to look at at some point, but not a huge +It’s something we might want to look at at some point, but not a huge problem as I see it. .SS Long Device IDs are Painful .sp -It\(aqs a mouthful to read over the phone, annoying to type into an SMS or even +It’s a mouthful to read over the phone, annoying to type into an SMS or even into a computer. And it needs to be done twice, once for each side. .sp -This isn\(aqt a vulnerability as such, but a user experience problem. There are +This isn’t a vulnerability as such, but a user experience problem. There are various possible solutions: .INDENT 0.0 .IP \(bu 2 -Use shorter device IDs with verification based on the full ID ("You +Use shorter device IDs with verification based on the full ID (“You entered MFZWI3; I found and connected to a device with the ID MFZWI3\-DBONSG\-YYLTMR\-WGC43E\-NRQXGZ\-DMMFZW\-I3DBON\-SGYYLT\-MRWA, please -confirm that this is correct"). +confirm that this is correct”). .IP \(bu 2 Use shorter device IDs with an out of band authentication, a la Bluetooth pairing. You enter a one time PIN into Syncthing and give diff --git a/man/syncthing-event-api.7 b/man/syncthing-event-api.7 index b5814523e..c1c1fb00c 100644 --- a/man/syncthing-event-api.7 +++ b/man/syncthing-event-api.7 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SYNCTHING-EVENT-API" "7" "November 18, 2017" "v0.14" "Syncthing" +.TH "SYNCTHING-EVENT-API" "7" "Nov 23, 2017" "v0.14" "Syncthing" .SH NAME syncthing-event-api \- Event API . @@ -45,7 +45,7 @@ only the desired event types, add a parameter list below. .sp The optional parameter \fBsince=\fP sets the ID of the last event -you\(aqve already seen. Syncthing returns a JSON encoded array of event objects, +you’ve already seen. Syncthing returns a JSON encoded array of event objects, starting at the event just after the one with this last seen ID. The default value is 0, which returns all events. There is a limit to the number of events buffered, so if the rate of events is high or the time between polling calls is @@ -186,8 +186,8 @@ Generated each time a connection to a device has been terminated. .INDENT 0.0 .INDENT 3.5 The error key contains the cause for disconnection, which might not -necessarily be an error as such. Specifically, "EOF" and "unexpected -EOF" both signify TCP connection termination, either due to the other +necessarily be an error as such. Specifically, “EOF” and “unexpected +EOF” both signify TCP connection termination, either due to the other device restarting or going offline or due to a network change. .UNINDENT .UNINDENT diff --git a/man/syncthing-faq.7 b/man/syncthing-faq.7 index 7cd0cd68e..1bd3d8c67 100644 --- a/man/syncthing-faq.7 +++ b/man/syncthing-faq.7 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SYNCTHING-FAQ" "7" "November 18, 2017" "v0.14" "Syncthing" +.TH "SYNCTHING-FAQ" "7" "Nov 23, 2017" "v0.14" "Syncthing" .SH NAME syncthing-faq \- Frequently Asked Questions . @@ -39,10 +39,10 @@ machine will automatically be replicated to your other devices. We believe your data is your data alone and you deserve to choose where it is stored. Therefore Syncthing does not upload your data to the cloud but exchanges your data across your machines as soon as they are online at the same time. -.SS Is it "syncthing", "Syncthing" or "SyncThing"? +.SS Is it “syncthing”, “Syncthing” or “SyncThing”? .sp -It\(aqs \fBSyncthing\fP, although the command and source repository is spelled -\fBsyncthing\fP so it may be referred to in that way as well. It\(aqs definitely not +It’s \fBSyncthing\fP, although the command and source repository is spelled +\fBsyncthing\fP so it may be referred to in that way as well. It’s definitely not SyncThing, even though the abbreviation \fBst\fP is used in some circumstances and file names. .SS How does Syncthing differ from BitTorrent/Resilio Sync? @@ -118,9 +118,9 @@ in the configuration file (24 hours by default). .sp When troubleshooting a slow sync, there are a number of things to check. .sp -First of all, verify that you are not connected via a relay. In the "Remote -Devices" list on the right side of the GUI, double check that you see -"Address: " and \fInot\fP "Relay: ". +First of all, verify that you are not connected via a relay. In the “Remote +Devices” list on the right side of the GUI, double check that you see +“Address: ” and \fInot\fP “Relay: ”. [image] .sp If you are connected via a relay, this is because a direct connection could @@ -152,7 +152,7 @@ There is a certain amount of housekeeping that must be done to track the current and available versions of each file in the index database. .IP 4. 3 By default Syncthing uses periodic scanning every 60 seconds to detect -file changes. This means checking every file\(aqs modification time and +file changes. This means checking every file’s modification time and comparing it to the database. This can cause spikes of CPU usage for large folders. .UNINDENT @@ -166,20 +166,20 @@ To limit the amount of CPU used when syncing and scanning, set the environment variable \fBGOMAXPROCS\fP to the maximum number of CPU cores Syncthing should use at any given moment. For example, \fBGOMAXPROCS=2\fP on a machine with four cores will limit Syncthing to no more than half the -system\(aqs CPU power. +system’s CPU power. .sp To reduce CPU spikes from scanning activity, use a filesystem notifications plugin. This is delivered by default via Synctrayzor, Syncthing\-GTK and on Android. For other setups, consider using \fI\%syncthing\-inotify\fP <\fBhttps://github.com/syncthing/syncthing-inotify\fP>\&. .SS Should I keep my device IDs secret? .sp -No. The IDs are not sensitive. Given a device ID it\(aqs possible to find the IP +No. The IDs are not sensitive. Given a device ID it’s possible to find the IP address for that device, if global discovery is enabled on it. Knowing the device -ID doesn\(aqt help you actually establish a connection to that device or get a list +ID doesn’t help you actually establish a connection to that device or get a list of files, etc. .sp -For a connection to be established, both devices need to know about the other\(aqs -device ID. It\(aqs not possible (in practice) to forge a device ID. (To forge a +For a connection to be established, both devices need to know about the other’s +device ID. It’s not possible (in practice) to forge a device ID. (To forge a device ID you need to create a TLS certificate with that specific SHA\-256 hash. If you can do that, you can spoof any TLS certificate. The world is your oyster!) @@ -206,16 +206,16 @@ device where it was deleted. Beware that the \fB.sync\-conflict\-\-