fix: review pass — uninit stats, append crash, filter rollback, ASan leak
CI / lint (pull_request) Successful in 1m45s
CI / sanitizers (address) (pull_request) Skipped
CI / sanitizers (undefined) (pull_request) Skipped
CI / fuzz-build (pull_request) Skipped
CI / coverage (pull_request) Skipped
CI / valgrind (pull_request) Skipped
CI / build-and-test (pull_request) Successful in 45s
CI / lint (pull_request) Successful in 1m45s
CI / sanitizers (address) (pull_request) Skipped
CI / sanitizers (undefined) (pull_request) Skipped
CI / fuzz-build (pull_request) Skipped
CI / coverage (pull_request) Skipped
CI / valgrind (pull_request) Skipped
CI / build-and-test (pull_request) Successful in 45s
Address findings from the four-agent review of PR #298: - file_create: zero the new File.matched_bytes. It was uninitialized malloc memory, so the receiver could sum a garbage value into STATUS_STATS "Matched data" (nondeterministic --stats divergence and an uninitialized-heap disclosure on the wire). - send_append: load the source into memory before hashing/copying the prefix and tail. Files >64 MiB without compression (and --sendfile runs) are streamed without loading, so --append/--append-verify dereferenced a NULL data->data and crashed. - filter_file_append: clamp the rollback to the surviving rule count. A "clear" rule in a merge file frees every rule including the caller's; the old rollback rewound count to rules_before and resurrected freed pointers for a double free / UAF. Also roll back when set_rule_owner fails instead of leaving owner-less rules. - filter_rule_parse: reject the xattr-name filter modifier (x), which was parsed and silently reinterpreted as a filename rule (affecting what --delete protects). The p modifier stays accepted (existing grammar test). - Remove two dead functions: compression_default_algo and change_render_itemize_code. - tests: free ctx->would_delete in the two test_multiprocessing manual teardowns (ASan leak, 1648 bytes/run). - docs: correct the RSYNC_COMPAT/HANDOFF tally (156 rows: 106/27/23), downgrade --info/--debug to caveat with their silent categories, add %C-vs-xxh64 and --delete-delay count caveats, refresh stale xattr mode comments, and document -p special-bit (setuid/setgid/sticky) parity plus its mitigations.
This commit is contained in:
+4
-4
@@ -409,10 +409,10 @@ bool fake_super_restore_fd(int fd, FileAttrPolicy policy) {
|
||||
(void)ul_gid;
|
||||
/* Mode is applied only when the per-attribute policy asks for it, through the
|
||||
SAME shared helper the normal metadata path uses (metadata_mode_for_policy):
|
||||
group/other write bits are never granted, so a recorded source mode of 0666
|
||||
restores as 0644 — identical to a non-fake-super --preserve run, never a
|
||||
privilege-granting regression — and the -E rule derives exec bits from the
|
||||
destination's read bits exactly like file_restore_metadata_fd. */
|
||||
under --perms the recorded source mode is copied exactly, including
|
||||
group/other write and setuid/setgid/sticky bits (rsync parity), and the -E
|
||||
rule derives exec bits from the destination's read bits exactly like
|
||||
file_restore_metadata_fd. */
|
||||
if (policy.perms || policy.executability) {
|
||||
struct stat cur;
|
||||
mode_t want = 0;
|
||||
|
||||
Reference in New Issue
Block a user