fix(p7-privilege): harden copy-as/super gates, own dirs/specials
- fake-super owner replay honors --no-super and an active --copy-as - copy-as/identity ownership now applied to directories and special nodes - reject copy_as_set && !use_metadata (receiver + client --no-preserve) - daemon refuses --copy-as; add server-side --no-super operator veto - implement identity_copy_as_refused/identity_copy_as_active - reject copy-as ids that overflow int32; escape spec in log errors - copy-as chown EPERM/EACCES logged at ERROR (still non-fatal) - identity_wire_valid copy-as bounds; CLI help and RSYNC_COMPAT docs - add unit tests and root-gated integration coverage
This commit is contained in:
@@ -23,8 +23,13 @@
|
||||
* server's --destination-root: the daemon confines every connection that
|
||||
* selects this module to this path (file_open_secure_parent /
|
||||
* has_path_traversal / path_is_within all keep the existing confinement, just
|
||||
* per-module). There is never any client-chosen root and no --super /
|
||||
* --copy-as: a module path always stays confined.
|
||||
* per-module). There is never any client-chosen root: a module path always
|
||||
* stays confined. A daemon also REFUSES a client --copy-as outright, because
|
||||
* there is no per-module opt-in for client-chosen ownership (unlike the
|
||||
* standalone/SSH server, which honors it for its single operator-authorized
|
||||
* root); the operator-level --no-super veto additionally forces super-user
|
||||
* activities off for every daemon connection. See server_module_gate in
|
||||
* server.c and RSYNC_COMPAT.md.
|
||||
*
|
||||
* `auth_users` is honored by Wave B daemon authentication: a module that
|
||||
* declares auth users accepts a connection only when the presented username is
|
||||
|
||||
Reference in New Issue
Block a user