chmod: match rsync 3.4.1 --chmod and remove mode masking (#293)
- --chmod no longer implies --preserve-perms; repeated --chmod options accumulate, and D/F/X selectors plus s/t special bits are supported with rsync's exact parse_chmod/tweak_mode semantics. - Stop masking group/other write and setuid/setgid/sticky: -p copies the source mode exactly, no-p new entries use source&~umask, directories keep setgid/sticky, and special nodes follow the same rules. - Apply ownership before mode on the fd path so a chown cannot clear the setuid/setgid bits -p just restored (rsync order). - Update unit and integration tests, including differential checks against rsync 3.4.1.
This commit is contained in:
+5
-10
@@ -112,21 +112,16 @@ unsigned file_process_umask(void) {
|
||||
|
||||
/* Base mode applied when the policy does not take the source mode wholesale
|
||||
* (i.e. --perms is off). A pre-existing destination keeps its own mode; a
|
||||
* brand-new file is created like rsync: source_mode & 0777 & ~umask, with
|
||||
* S_IWGRP|S_IWOTH always cleared so a client mode can never grant group/other
|
||||
* write (the daemon runs with umask(0)). Only when no metadata is available at
|
||||
* all does the historical fixed 0644 default apply. The -E rule (and no-op for
|
||||
* a plain -t) is layered on top of this base. */
|
||||
* brand-new file is created like rsync: source_mode & 0777 & ~umask (special
|
||||
* bits are not part of a mode-preserving transfer without -p). Only when no
|
||||
* metadata is available at all does the historical fixed 0644 default apply.
|
||||
* The -E rule (and no-op for a plain -t) is layered on top of this base. */
|
||||
static mode_t file_mode_base(const FileMetadata* metadata, bool existing_known,
|
||||
mode_t existing_mode) {
|
||||
if (existing_known)
|
||||
return existing_mode;
|
||||
if (metadata)
|
||||
/* A brand-new file follows rsync's source_mode & ~umask base, but a
|
||||
* client-supplied source mode must never grant group/other write (the
|
||||
* daemon runs with umask(0), so an unmasked 0666 would otherwise create a
|
||||
* world-writable file). S_IWGRP|S_IWOTH are always cleared. */
|
||||
return metadata->mode & 0777 & ~(mode_t)file_process_umask() & ~(S_IWGRP | S_IWOTH);
|
||||
return metadata->mode & 0777 & ~(mode_t)file_process_umask();
|
||||
return S_IRUSR | S_IWUSR | S_IRGRP | S_IROTH;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user