fix(parity): receiver temp-dir confinement, server I/O floor, delete budget
Address review findings on feat/rsync-parity: - confine --temp-dir below the receive root (reject absolute/.. like backup-dir/partial-dir); keep EXDEV non-atomic fallback - floor server session I/O deadlines at SERVER_IO_TIMEOUT_SEC (60s) and install it on the socket layer at startup (slow-loris) - charge each --delete-missing-args directory removal once and clamp the extras-walk remaining budget so it can never underflow past --max-delete - normalize --compress-choice=auto to zstd client-side and accept it on receive so auto transfers no longer fail - map received --max-alloc=0 to MAX_SERVER_ALLOC (receive path only) - zero File.dest_state; include log-file-format in report_dest_info; add STATUS_DELETE_LIMIT name; recognize --skip-compress as a separate-value option; OOM-guard send_list_only root entry; drop the dead -M= branch; record the bare relative protected prefix for -R size-prunes in both scanners; refresh delete-manifest comment - pin the rsync tarball sha256 and bump integrator image to v11 Tests: temp-dir rejection/relative/cross-device, server timeout floor, delete-missing dir budget regression, compress-choice=auto e2e, max-alloc=0 receive mapping, dest_state, report_dest_info modes, skip-compress dash value, -M short forms, -R root size-prune mirror protection (rsync 3.4.1 confirmed).
This commit is contained in:
+14
-13
@@ -132,16 +132,20 @@ static int set_positive_int_option(int* dest, const char* value, const char* opt
|
||||
* zstd choice; any other rsync choice is rejected by name instead of being
|
||||
* silently accepted and ignored. */
|
||||
static int set_compression_choice(Config* config, const char* value) {
|
||||
if (strcmp(value, "zstd") != 0 && strcmp(value, "none") != 0 && strcmp(value, "auto") != 0) {
|
||||
/* rsync's "auto" is normalized to the canonical "zstd" at parse time (like
|
||||
--checksum-choice=auto), so the value that crosses the wire is always one
|
||||
the receiver accepts. */
|
||||
const char* canonical = strcmp(value, "auto") == 0 ? "zstd" : value;
|
||||
if (strcmp(canonical, "zstd") != 0 && strcmp(canonical, "none") != 0) {
|
||||
log_message(LOG_LEVEL_ERROR,
|
||||
"--compress-choice '%s' is not implemented; FastSync supports zstd, none or auto "
|
||||
"(rsync's lz4/zlib/zlibx are rejected, never silently ignored)",
|
||||
value);
|
||||
return -1;
|
||||
}
|
||||
if (set_string_option(&config->compress_choice, value, "--compress-choice") != 0)
|
||||
if (set_string_option(&config->compress_choice, canonical, "--compress-choice") != 0)
|
||||
return -1;
|
||||
config->use_compression = strcmp(value, "none") != 0;
|
||||
config->use_compression = strcmp(canonical, "none") != 0;
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -1992,11 +1996,6 @@ static bool cli_handle_remote_basis_options(CliParseCtx* ctx) {
|
||||
ctx->exit_code = -1;
|
||||
return true;
|
||||
}
|
||||
if (strncmp(arg, "-M=", 3) == 0) {
|
||||
if (config_add_remote_option(config, arg + 3, "-M") != 0)
|
||||
ctx->exit_code = -1;
|
||||
return true;
|
||||
}
|
||||
if (opt_is(arg, "--remote-option", "-M")) {
|
||||
if (ctx->i + 1 >= ctx->argc) {
|
||||
log_message(LOG_LEVEL_ERROR, "missing argument for --remote-option");
|
||||
@@ -2271,10 +2270,12 @@ static int cli_finalize_config(Config* config, bool verbose, bool no_delta, bool
|
||||
* --no-xattrs/--no-acls negation) so the sender's wire gate always matches
|
||||
* the flags the receiver will recompute from the received config. */
|
||||
config->use_xattrs = config->preserve_acls || config->preserve_xattrs;
|
||||
/* Output parity: -i/--itemize-changes and --out-format need the pre-transfer
|
||||
* destination snapshot (new vs modified and which attributes differ), so ask
|
||||
* the receiver to report it on every per-file check. This is a wire field. */
|
||||
config->report_dest_info = config->itemize_changes || config->out_format != NULL;
|
||||
/* Output parity: -i/--itemize-changes, --out-format and --log-file-format
|
||||
* need the pre-transfer destination snapshot (new vs modified and which
|
||||
* attributes differ), so ask the receiver to report it on every per-file
|
||||
* check. This is a wire field. */
|
||||
config->report_dest_info = config->itemize_changes || config->out_format != NULL ||
|
||||
(config->log_file != NULL && config->log_file_format != NULL);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -2306,7 +2307,7 @@ static bool cli_long_takes_separate_value(const char* arg) {
|
||||
"--checksum-choice", "--cc", "--checksum-seed", "--sockopts",
|
||||
"--remote-option", "--compare-dest", "--copy-dest", "--link-dest",
|
||||
"--usermap", "--groupmap", "--chown", "--copy-as",
|
||||
"--outbuf", "--debug", "--info",
|
||||
"--outbuf", "--debug", "--info", "--skip-compress",
|
||||
};
|
||||
for (size_t i = 0; i < sizeof(extra) / sizeof(extra[0]); i++)
|
||||
if (strcmp(arg, extra[i]) == 0)
|
||||
|
||||
+15
-10
@@ -908,8 +908,10 @@ static int send_list_only(const Config* config) {
|
||||
entries = calloc(capacity, sizeof(ListEntry));
|
||||
if (entries == NULL) {
|
||||
oom = true;
|
||||
} else if ((entries[0].name = str_dup("")) == NULL) {
|
||||
/* A NULL name would be dereferenced by qsort/render: fail the listing. */
|
||||
oom = true;
|
||||
} else {
|
||||
entries[0].name = str_dup("");
|
||||
entries[0].mode = st.st_mode;
|
||||
entries[0].mtime = st.st_mtime;
|
||||
entries[0].mtime_nsec = st.st_mtim.tv_nsec;
|
||||
@@ -1015,15 +1017,18 @@ static int send_list_only(const Config* config) {
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Send the delete manifest (keep-set paths plus the protected excluded
|
||||
prefixes and the --delete-missing-args exact-delete paths) to the server.
|
||||
Returns 0 on success, -1 on failure. When --delete-excluded is given
|
||||
`protected` is empty: excluded destination mirrors are then ordinary extras
|
||||
and are removed. When --delete-missing-args is active `missing_args` holds
|
||||
the destination mirrors of missing --files-from entries: each is an explicit
|
||||
receiver-side deletion request, independent of the extras walk. A NULL
|
||||
keep-set / protected / missing list transmits an empty section. All three
|
||||
sections are unbounded on the sender; the receiver enforces
|
||||
/* Send the delete manifest to the server. Returns 0 on success, -1 on
|
||||
failure. It carries FOUR sections: the keep-set paths, the protected
|
||||
excluded prefixes, the --delete-missing-args exact-delete paths, and the
|
||||
destination-relative directories the sender synchronized this run.
|
||||
When --delete-excluded is given `protected` is empty: excluded destination
|
||||
mirrors are then ordinary extras and are removed. When
|
||||
--delete-missing-args is active `missing_args` holds the destination mirrors
|
||||
of missing --files-from entries: each is an explicit receiver-side deletion
|
||||
request, independent of the extras walk. `synced_dirs` confines the extras
|
||||
walk to entries directly inside a synchronized directory. A NULL
|
||||
keep-set / protected / missing / dirs list transmits an empty section. All
|
||||
four sections are unbounded on the sender; the receiver enforces
|
||||
MAX_MANIFEST_ENTRIES per section and a single MAX_MANIFEST_BYTES budget
|
||||
shared across the sections, rejecting (with STATUS_ERROR) an over-budget
|
||||
frame. A heavily filtered source whose exclusion list is large therefore
|
||||
|
||||
+27
-16
@@ -1120,18 +1120,23 @@ Chunk* directory_scanner_next(DirectoryScanner* scanner) {
|
||||
if (inspection == 0) {
|
||||
/* A user-selection exclude protects its destination mirror from --delete
|
||||
unless --delete-excluded; a size prune is always protected. Other
|
||||
skips (unreadable, symlink policy) protect nothing. */
|
||||
skips (unreadable, symlink policy) protect nothing. Under -R +
|
||||
--files-from the protected prefix must be the entry's bare relative
|
||||
wire path, not its source path (which would not match the destination
|
||||
layout and would leave the mirror deletable). */
|
||||
if (inspected.excluded) {
|
||||
char* abs_path = path_cat(scanner->current_path, entry->d_name);
|
||||
if (!abs_path) {
|
||||
char* protected_path = scanner->relative_mode
|
||||
? child_rel_path(scanner->current_rel, entry->d_name)
|
||||
: path_cat(scanner->current_path, entry->d_name);
|
||||
if (!protected_path) {
|
||||
scanner->failed = true;
|
||||
break;
|
||||
}
|
||||
if (inspected.size_excluded)
|
||||
scanner_record_size_skipped(scanner, abs_path);
|
||||
scanner_record_size_skipped(scanner, protected_path);
|
||||
else
|
||||
scanner_record_excluded(scanner, abs_path);
|
||||
free(abs_path);
|
||||
scanner_record_excluded(scanner, protected_path);
|
||||
free(protected_path);
|
||||
}
|
||||
continue;
|
||||
}
|
||||
@@ -1510,17 +1515,23 @@ static void scan_root_entry(const ScannerOptions* options, const FilterNode* roo
|
||||
if (inspected.excluded)
|
||||
sink = inspected.size_excluded ? options->size_skipped_paths : options->excluded_paths;
|
||||
if (sink) {
|
||||
/* A root-level prune protects the destination mirror of the same-named
|
||||
wire path (at the root the bare name is the wire path in every
|
||||
layout). */
|
||||
char* abs_path = path_cat(root_directory, entry->d_name);
|
||||
if (!abs_path) {
|
||||
ps->failed = true;
|
||||
} else {
|
||||
const char* rel = *abs_path == '/' ? abs_path + 1 : abs_path;
|
||||
if (!excluded_sink_append(sink, options->excluded_mutex, rel))
|
||||
/* A root-level prune protects the destination mirror of the entry's wire
|
||||
path: under -R + --files-from that is the bare relative name, otherwise
|
||||
it is the full source path with a leading '/' removed (matching the
|
||||
send_path/file_wire_path the scanner hands the sender). */
|
||||
if (options->relative && options->file_list != NULL) {
|
||||
if (!excluded_sink_append(sink, options->excluded_mutex, entry->d_name))
|
||||
ps->failed = true;
|
||||
free(abs_path);
|
||||
} else {
|
||||
char* abs_path = path_cat(root_directory, entry->d_name);
|
||||
if (!abs_path) {
|
||||
ps->failed = true;
|
||||
} else {
|
||||
const char* rel = *abs_path == '/' ? abs_path + 1 : abs_path;
|
||||
if (!excluded_sink_append(sink, options->excluded_mutex, rel))
|
||||
ps->failed = true;
|
||||
free(abs_path);
|
||||
}
|
||||
}
|
||||
}
|
||||
return;
|
||||
|
||||
Reference in New Issue
Block a user