fix(client): route explicit remote dry-run targets, fail closed on stray status
--dry-run --server-host=H (or TLS / source-bind --address) silently ran the client-side manifest even though a real run contacts the server. Add a client-only, never-serialized server_host_set bit (alongside the existing server_port_set) and extend dry_run_targets_server so every explicit remote target contacts the receiver. Also make incremental_check return the dry-run code (4) only when the session actually requested dry-run; a stray STATUS_DRY_RUN_TRANSFER from a hostile/buggy peer is now a logged protocol error (STATUS_ERROR) instead of falling through to send file data and desync. Both normal send_single_file callers handle rc == 4 explicitly as an abort.
This commit is contained in:
@@ -42,6 +42,7 @@ static void config_set_defaults(Config* config) {
|
||||
config->server_host = str_dup("127.0.0.1");
|
||||
config->server_port = 8080;
|
||||
config->server_port_set = false;
|
||||
config->server_host_set = false;
|
||||
/* 0 means "--timeout not given": the transport keeps its own built-in 30 s
|
||||
* socket timeout (tcp_set_timeouts ignores non-positive values) and the
|
||||
* protocol layer keeps its built-in 60 s per-message deadline. A positive
|
||||
|
||||
@@ -292,6 +292,12 @@ typedef struct Config {
|
||||
* existing client-side dry-run behavior instead of dialing the default
|
||||
* 127.0.0.1:8080. */
|
||||
bool server_port_set;
|
||||
/* True when --server-host was explicitly given. CLIENT-ONLY (never
|
||||
* serialized), and distinct from the "127.0.0.1" default: --dry-run uses it
|
||||
* to route an explicit remote target to the server so it reports receiver
|
||||
* state exactly like a real run, instead of silently running the client-side
|
||||
* manifest. */
|
||||
bool server_host_set;
|
||||
char* tls_cert;
|
||||
char* tls_key;
|
||||
char* tls_ca;
|
||||
|
||||
Reference in New Issue
Block a user