Understand QCBM Off-Site Export Verification and Resumable Cloud Transfers

QCBM does more than report that an upload request completed. Before export, it verifies the local Recovery Package it intends to send, and after transfer it performs provider-specific checks on the remote object. Google Drive and OneDrive also use resumable upload sessions so large packages can continue from provider-confirmed byte ranges during the active upload.

Verification differs by provider. Do not assume every connector can return the same checksum metadata.

Local Package Verification Comes First

A backup export begins only after QCBM has a completed Backup Set and a ready canonical Recovery Package. The export path rechecks the package/part health and calculates the source SHA-256 used to protect the local package before copying it.

If the local package health check fails, QCBM blocks the export instead of sending a damaged source file.

Local / Server Path Verification

For a Local / Server Path destination, QCBM copies the Recovery Package and then compares both the copied file size and a SHA-256 checksum with the local source. A mismatch marks the export attempt failed.

SFTP, FTP, and FTPS Verification

For remote-server connectors, QCBM uploads the Recovery Package and checks the remote file size against the local source size. The connector records the remote path and verified size in the export record.

The remote-server backup-export path does not claim a provider-side SHA-256 checksum when the protocol/API does not supply one. SFTP separately protects server identity through the configured SSH host-key fingerprint.

Google Drive Resumable Upload and MD5

Google Drive exports use a resumable upload session. QCBM sends the package in chunks and follows Google's confirmed byte range when the provider returns a resume response.

After the upload completes, QCBM retrieves file metadata when necessary, verifies the exact remote size, calculates the local file's MD5, and compares it with Google's md5Checksum. The export is not marked complete if the size or MD5 comparison fails.

OneDrive Resumable Upload and Provider Hashes

OneDrive exports use a Microsoft Graph upload session with chunk sizes compatible with Graph's 320 KiB fragment requirement. QCBM follows nextExpectedRanges while the upload is in progress.

After completion, QCBM retrieves the final OneDrive item and verifies its size. If Microsoft supplies a SHA-1 hash, QCBM calculates the local SHA-1 and requires an exact match. If SHA-1 is unavailable but QuickXorHash metadata is returned, QCBM records that provider hash while reporting that size was verified.

What Resumable Means—and What It Does Not

Resumable cloud upload means QCBM can continue within the active provider upload session from the byte range the provider confirms, rather than assuming every chunk must restart from byte zero.

It does not mean an export can survive every credential revocation, expired upload session, administrator cancellation, or indefinite outage. If an export run ultimately fails, QCBM records the failed or partial result and the local Recovery Package remains a separate recovery point.

How to Verify an Export Operationally

Review the export result and destination-specific message after a transfer. QCBM stores grouped export-run information and file-attempt evidence such as destination, status, remote path, remote size, and verification message.

For critical recovery points, keep the local package until the remote export is confirmed and periodically confirm that the provider account remains accessible.


Community Discussion

Want to compare workflows, share practical tips, or discuss how you use this QCBM feature? Visit the QC Backup Manager Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.