fix(server): gate --force by --allow-delete and secure root super default
C2: --force is deletion authority (an incoming regular file may remove a non-empty destination directory tree, and --delete-missing-args may remove a non-empty directory mirror), but it was not masked by the operator --allow-delete policy. The handler now clears config->force_delete unless --allow-delete was given, exactly like --delete and --delete-missing-args. C3: a standalone TCP / --stdio server running as root defaulted to SUPER_MODE_AUTO, so an untrusted client --devices/--write-devices/ --super could make it create device nodes, write raw devices, or apply client-chosen ownership. A privileged standalone receiver now forces SUPER_MODE_OFF unless the operator opts in with the new server-only --allow-super flag. Non-root receivers are unchanged, and the daemon path keeps its per-module `client owner = yes` gate. --allow-super is rejected with --no-super or --daemon. C6: tls_client_identity_allowed now rejects a CN whose reported length reached the buffer bound, so a truncated over-long CN cannot be matched by a required --client-cn prefix. Tests: an integration regression proving --force cannot replace a destination directory without --allow-delete; standalone-default tests for --copy-as refusal and (root-only) skipped device creation; a CLI unit test for the new flag. The integration shared_server fixture opts in with --allow-super so the existing root-only ownership/device/copy-as tests continue to exercise the opted-in configuration. README and RSYNC_COMPAT document the flag and the force/delete gating.
This commit is contained in:
+7
-1
@@ -16,7 +16,13 @@ def shared_server():
|
||||
Under pytest-xdist this session fixture is instantiated once per worker
|
||||
process, so each worker gets its own server on an ephemeral port."""
|
||||
server = ServerManager()
|
||||
server.start()
|
||||
# --allow-super keeps the historical permissive super mode for a root
|
||||
# receiver: the integration suite's root-only ownership/device/copy-as tests
|
||||
# exercise that opted-in configuration. The secure default (a root
|
||||
# standalone server without --allow-super forces SUPER_MODE_OFF) is covered
|
||||
# explicitly by TestStandaloneSuperDefault in test_features.py. Non-root
|
||||
# runs are unaffected by the flag.
|
||||
server.start(extra_args=["--allow-super"])
|
||||
yield server
|
||||
server.stop()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user