fix(p8h): restore daemon --super refusal, race-free secret-file check, remaining log escapes

- server_module_gate: refuse client-chosen ownership against the ORIGINAL config
  so an explicit --super is still refused under an operator --no-super veto
  (the veto must not turn a refusal into an accept).
- credentials: open-then-fstat the exact secret inode, require current-user
  ownership and no group/other bits, but continue to allow process-substitution
  FIFOs; removes the stat->fopen TOCTOU.
- file.c preallocate + protocol.c send-string debug logs escape attacker paths.
- usage/RSYNC_COMPAT updated for --old-args no-op and secret-file rules.
This commit is contained in:
2026-09-12 15:50:14 +02:00
parent e1bb2e9233
commit 108fee1e41
6 changed files with 69 additions and 43 deletions
+5 -4
View File
@@ -257,10 +257,11 @@ static const char* server_module_gate(const Config* config, void* context) {
standalone/SSH server has a single operator-authorized root and keeps
honoring these. */
if (!module->client_owner) {
/* Ownership: refuse the whole transfer up front (a clear failure). Evaluated
against the effective copy (so an operator --no-super has already
neutralized an explicit --super), exactly as before. */
if (identity_ownership_requested(&effective)) {
/* Ownership: refuse the whole transfer up front (a clear failure).
Evaluated against the ORIGINAL config so an explicit --super is refused
even when an operator --no-super veto already forced the effective copy
to OFF (the veto must not silently convert a refusal into an accept). */
if (identity_ownership_requested(config)) {
log_message(LOG_LEVEL_ERROR,
"daemon module '%s' refuses client-chosen ownership/super-user activities "
"(no `client owner = yes` opt-in); refusing",