identity mapping: --numeric-ids / --usermap / --groupmap / --chown
CI / lint (pull_request) Failing after 3s
CI / build-and-test (pull_request) Skipped
CI / sanitizers (address) (pull_request) Skipped
CI / sanitizers (undefined) (pull_request) Skipped
CI / fuzz-build (pull_request) Skipped
CI / coverage (pull_request) Skipped
CI / valgrind (pull_request) Skipped

Receiver-side ownership application, opt-in and privilege-gated:
- OFF for every existing transfer (plain -M/--preserve still never applies
  ownership); only triggers on an explicit identity flag + receiver permission.
- EPERM/EACCES warn-and-continue (never aborts); other fchown errors escalate.
- fd-relative fchown after the file is written (symlink-safe, confined).
- New src/shared/identity.{c,h}; config fields numeric_ids / chown uid/gid /
  usermap + groupmap id-pair tables cross the wire; PROTOCOL_VERSION 2.10.0
  -> 2.11.0. CLI in client_cli.c; per-connection snapshot in server.c.
- Review fixes: EPERM/EACCES-only warn-and-continue, prominent root-receiver
  notice, identity_clear_active on early server error paths, --numeric-ids
  kept inert standalone (removed from activation trigger set).
This commit is contained in:
2026-09-08 18:23:43 +02:00
parent 829e760086
commit 53ce00b830
12 changed files with 1094 additions and 8 deletions
+8
View File
@@ -1,6 +1,7 @@
#include "config.h"
#include "delay_updates.h"
#include "file.h"
#include "identity.h"
#include "log.h"
#include "multiprocessing.h"
#include "protocol.h"
@@ -210,6 +211,10 @@ void handler(int file_descriptor) {
return;
}
}
/* Preserve the negotiated identity policy for the fd-relative ownership
apply path. Each connection is its own forked process, so this
per-process snapshot never races another connection. */
identity_set_active(config);
if (config->use_multithreading) {
Queue* q = queue_create(100, file_destroy);
if (q == NULL) {
@@ -225,6 +230,7 @@ void handler(int file_descriptor) {
config_delete(config);
close(file_descriptor);
protocol_session_unbind();
identity_clear_active();
return;
}
protocol_session_set_max_alloc(&context->session, config->max_alloc);
@@ -253,6 +259,7 @@ void handler(int file_descriptor) {
thrd_join(writer, NULL);
pipeline_context_receiver_destroy(context);
protocol_session_unbind();
identity_clear_active();
return;
}
int receiver_result;
@@ -303,6 +310,7 @@ void handler(int file_descriptor) {
config_delete(config);
}
protocol_session_unbind();
identity_clear_active();
close(file_descriptor);
}