fix(p8h): restore daemon --super refusal, race-free secret-file check, remaining log escapes

- server_module_gate: refuse client-chosen ownership against the ORIGINAL config
  so an explicit --super is still refused under an operator --no-super veto
  (the veto must not turn a refusal into an accept).
- credentials: open-then-fstat the exact secret inode, require current-user
  ownership and no group/other bits, but continue to allow process-substitution
  FIFOs; removes the stat->fopen TOCTOU.
- file.c preallocate + protocol.c send-string debug logs escape attacker paths.
- usage/RSYNC_COMPAT updated for --old-args no-op and secret-file rules.
This commit is contained in:
2026-09-12 15:50:14 +02:00
parent e1bb2e9233
commit 108fee1e41
6 changed files with 69 additions and 43 deletions
+12 -6
View File
@@ -930,9 +930,12 @@ static bool file_to_disk_secure_impl(const char* path, const void* data,
int prealloc_rc = 0;
if (preallocate && !sparse && data_size > 0) {
prealloc_rc = preallocate_fd(fd, data_size);
if (prealloc_rc != 0)
log_message(LOG_LEVEL_ERROR, "preallocate failed for '%s' (%s); transfer aborted", path,
strerror(prealloc_rc));
if (prealloc_rc != 0) {
char* escaped_path = output_escape(path, log_get_8_bit_output());
log_message(LOG_LEVEL_ERROR, "preallocate failed for '%s' (%s); transfer aborted",
escaped_path ? escaped_path : "<allocation failed>", strerror(prealloc_rc));
free(escaped_path);
}
}
if (prealloc_rc == 0) {
/* posix_fallocate does not guarantee the fd's file offset is left
@@ -1037,9 +1040,12 @@ static bool file_to_disk_secure_impl(const char* path, const void* data,
int prealloc_rc = 0;
if (preallocate && !sparse && data_size > 0) {
prealloc_rc = preallocate_fd(fd, data_size);
if (prealloc_rc != 0)
log_message(LOG_LEVEL_ERROR, "preallocate failed for '%s' (%s); transfer aborted", path,
strerror(prealloc_rc));
if (prealloc_rc != 0) {
char* escaped_path = output_escape(path, log_get_8_bit_output());
log_message(LOG_LEVEL_ERROR, "preallocate failed for '%s' (%s); transfer aborted",
escaped_path ? escaped_path : "<allocation failed>", strerror(prealloc_rc));
free(escaped_path);
}
}
if (prealloc_rc == 0) {
lseek(fd, 0, SEEK_SET);