fix(p8h): restore daemon --super refusal, race-free secret-file check, remaining log escapes

- server_module_gate: refuse client-chosen ownership against the ORIGINAL config
  so an explicit --super is still refused under an operator --no-super veto
  (the veto must not turn a refusal into an accept).
- credentials: open-then-fstat the exact secret inode, require current-user
  ownership and no group/other bits, but continue to allow process-substitution
  FIFOs; removes the stat->fopen TOCTOU.
- file.c preallocate + protocol.c send-string debug logs escape attacker paths.
- usage/RSYNC_COMPAT updated for --old-args no-op and secret-file rules.
This commit is contained in:
2026-09-12 15:50:14 +02:00
parent e1bb2e9233
commit 108fee1e41
6 changed files with 69 additions and 43 deletions
+7 -3
View File
@@ -430,10 +430,14 @@ static bool protocol_send_str_impl(ProtocolSession* session, const char* data, b
return false;
if (!protocol_send_n_data(session, data, size))
return false;
if (redact)
if (redact) {
log_debug_message(LOG_DEBUG_PROTO, "Send String: <redacted>");
else
log_debug_message(LOG_DEBUG_PROTO, "Send String: %s", data);
} else {
char* escaped_data = output_escape(data, log_get_8_bit_output());
log_debug_message(LOG_DEBUG_PROTO, "Send String: %s",
escaped_data ? escaped_data : "<allocation failed>");
free(escaped_data);
}
return true;
}