Commit Graph
1115 Commits
Author SHA1 Message Date
TapTap be20e836de fix: correct throttle legacy resolution; add EXDEV temp-dir coverage 2026-09-22 14:06:26 +02:00
TapTap b549887138 refactor(config): group CLI-parse state; drop old_args field 2026-09-22 14:03:10 +02:00
TapTap 1ffd4744c6 Merge branch 'refactor/delete' into refactor/structural 2026-09-22 13:53:20 +02:00
TapTap 494cef2a0b Merge branch 'refactor/pending' into refactor/structural 2026-09-22 13:53:20 +02:00
TapTap ed7527cc2c Merge branch 'refactor/handler' into refactor/structural 2026-09-22 13:53:20 +02:00
TapTap 934defa965 refactor(delete): consolidate delete engine into delete.c 2026-09-22 13:52:57 +02:00
TapTap ade9be8600 refactor(receiver): per-status dispatch and shared pending teardown 2026-09-22 13:49:28 +02:00
TapTap 707bb659e8 refactor(server): decompose handler into phases 2026-09-22 13:46:17 +02:00
TapTap 33980bc4c8 Merge branch 'refactor/filerecv' into refactor/structural 2026-09-22 13:39:34 +02:00
TapTap 6a9372f4f5 Merge branch 'refactor/client' into refactor/structural 2026-09-22 13:39:34 +02:00
TapTap 5e1d6b6e10 Merge branch 'refactor/scanner' into refactor/structural 2026-09-22 13:39:34 +02:00
TapTap d2d1b63f44 refactor(receive): split file_save/incremental_check/delete_commit out
Pure structural split of src/shared/file_receive.c into focused translation
units behind the unchanged file_receive.h facade:

- file_save.c   : save-to-disk, special nodes, --delay-updates staging
- incremental_check.c : xattr/delta/basis/fuzzy receive + check state machine
- delete_commit.c : manifest receive + delete budget walkers
- file_receive.c : wire receive dispatch + deferred dir metadata

The shared receive_file_xattrs helper and MAX_FILE_DATA_SIZE are declared in
incremental_check.h.  file_save_to_disk_full_ex is decomposed into static
helpers (validation, special dispatch, dir/symlink creation, path resolution,
pre-write policies, data install) routed through one cleanup epilogue.

No behavior change.
2026-09-22 13:38:54 +02:00
TapTap a6659472fe refactor(scanner): split into filter/sequential/parallel TUs
Move the filter rule-tree/context helpers and entry inspection into
scanner_filter.c, the parallel scanner into scanner_parallel.c, and keep
the sequential scanner in scanner.c.  Shared internal declarations live in
the new scanner_internal.h; scanner.h stays the public façade.

Decompose directory_scanner_next into static helpers (skipped-entry,
selection-protection, mount/-x, directory-finish and per-entry handlers)
with no semantic change.
2026-09-22 13:38:05 +02:00
TapTap 4638030288 refactor(client): split reporting/scan/manifest out of client_send
Move the stats/progress reporting, scanner-preparation/scan helpers and
manifest/list/dry-run senders out of the ~3.9k-line client_send.c into
client_report.c, client_scan.c and client_manifest.c, sharing declarations
through the new internal client_send_internal.h.  client_send.c keeps the
transfer orchestration and is now ~2.1k lines.

Decompose the monolithic send_files into static phase helpers
(send_files_prepare/_prepare_delete/_run/_finalize/_cleanup) driven by a
single SendFilesState; ownership, ordering and exit codes are unchanged.

No behavior change.
2026-09-22 13:34:55 +02:00
TapTap 07dfec629f Merge PR #306: codebase audit cycle (security, correctness, refactors, docs)
CI / lint (push) Successful in 2m31s
CI / parity-fast (push) Skipped
CI / parity-full (push) Successful in 23s
CI / sanitizers (undefined) (push) Successful in 47s
CI / sanitizers (address) (push) Successful in 1m13s
CI / build-and-test (push) Successful in 1m19s
CI / fuzz-build (push) Successful in 49s
CI / coverage (push) Successful in 44s
CI / valgrind (push) Successful in 2m18s
2026-09-21 22:23:33 +02:00
TapTap c062a0762e Merge branch 'fix/audit-docs3' into fix/audit-cycle
CI / lint (pull_request) Successful in 2m46s
CI / parity-full (pull_request) Skipped
CI / sanitizers (address) (pull_request) Skipped
CI / sanitizers (undefined) (pull_request) Skipped
CI / fuzz-build (pull_request) Skipped
CI / coverage (pull_request) Skipped
CI / valgrind (pull_request) Skipped
CI / parity-fast (pull_request) Successful in 31s
CI / build-and-test (pull_request) Successful in 54s
2026-09-21 22:11:53 +02:00
TapTap 283f9f0823 docs: reflect filter modifiers, inplace+partial-dir, credentials hardening
Update the docs for the audit follow-up fixes:
- --filter merge modifiers e/n/w/- are now accepted-and-consumed on
  merge/dir-merge rules (rejected on non-merge, x rejected everywhere);
  their semantics stay unimplemented, so the --filter row moves to Caveat
  and the tally becomes 119/11/27 = 157.
- --inplace + --partial-dir is rejected with rsync's message.
- secret_file_open() O_NOFOLLOW (symlinked credential paths fail closed;
  fd-backed paths exempt) and ~3 s bound-wait on FIFO reads.
- AGENTS setpriv wording corrected to the collected instance count.
- CHANGELOG [Unreleased] audit section extended with the follow-ups.
2026-09-21 22:11:19 +02:00
TapTap 5754b9a952 Merge branch 'fix/audit-misc2' into fix/audit-cycle 2026-09-21 22:02:05 +02:00
TapTap b8a0efef7b Merge branch 'fix/audit-filter2' into fix/audit-cycle 2026-09-21 22:02:05 +02:00
TapTap 2e77c09447 Merge branch 'fix/audit-creds2' into fix/audit-cycle 2026-09-21 22:02:05 +02:00
TapTap 06c4026b74 fix(filter): accept e/n/w/- merge modifiers on merge/dir-merge rules
The earlier modifier-rejection change rejected e/n/w on all rules, but rsync
3.4.1 accepts them (plus the '-' merge-only modifier) on merge and dir-merge
rules.  Restrict the rejection to non-merge rules and consume the merge-file
modifiers (e/n/w/-) so they no longer leak into the merge filename.

- is_merge_rule()/is_merge_modifier_char() gate the merge-only modifiers.
- scan vs consume sets: e/n/w still count as modifier-run chars on every rule
  (pure tokens like -new/-press stay rejected), but are only consumed on merge
  rules, preserving mixed-token parsing such as H,!secret -> ecret.
- '-' is accepted/consumed only on merge/dir-merge (e.g. dir-merge,- .rules).
- x remains rejected everywhere with its dedicated message.
- e/n/w/- semantics remain unimplemented and are documented as accepted-but-
  ignored in filter.h.

Tests: split the merge forms out of the rejection test into a new acceptance
test asserting the merge file is read and dir_merge_names keeps the modifier-
free basename; non-merge pure-modifier forms still rejected.
2026-09-21 22:01:44 +02:00
TapTap 9f47b13712 fix(credentials): bound-wait on FIFO reads so slow process substitution works
secret_file_open() opened secret files with O_NONBLOCK and only cleared it
for S_ISREG, so on a FIFO/process-substitution source (--password-file
<(...), --early-input <(...)) fgets() failed immediately with EAGAIN when
the writer had not yet produced data, breaking slow producers.

Keep O_NONBLOCK at open() (a writer-less FIFO must not block the open) and
route all three readers through a new secret_read_line() helper.  It
accumulates a line across reads and, on EAGAIN/EWOULDBLOCK (or a partial
line) with no newline and no EOF, clearerr()s and polls for readability
against one overall CLOCK_MONOTONIC deadline of
CREDENTIAL_FIFO_READ_TIMEOUT_MS (3000 ms); on timeout or a real read error
it fails with a clear message.  EOF finishes normally.  Regular files are
left blocking and read exactly as before.

Handles a line split across several write()s and keeps the owner/mode
fstat gate, O_NOFOLLOW and the /dev/fd/N exception unchanged.
2026-09-21 22:01:18 +02:00
TapTap b1eddf0133 fix: config leak, compression log, inplace+partial-dir rejection, umask/root test fixes 2026-09-21 21:59:58 +02:00
TapTap 338c27db73 fix: resolve cppcheck shadow/always-true findings 2026-09-21 21:28:36 +02:00
TapTap 8d46a26c04 Merge branch 'fix/audit-docs2' into fix/audit-cycle 2026-09-21 21:18:48 +02:00
TapTap 707ba272df Merge branch 'fix/audit-docs1' into fix/audit-cycle 2026-09-21 21:18:48 +02:00
TapTap bc71a3c0a5 docs: correct README build deps, delete defaults, scanner, flags; AGENTS deps/CI 2026-09-21 21:18:26 +02:00
TapTap cee9b7647c docs: fix parity tally, compat rows, changelog, handoff for audit cycle 2026-09-21 21:14:37 +02:00
TapTap 3adb6dddb5 chore: drop tracked scratch data and extend .gitignore 2026-09-21 21:11:04 +02:00
TapTap d77849774e Merge branch 'fix/audit-refb' into fix/audit-cycle 2026-09-21 21:09:20 +02:00
TapTap b5c6f8b60f Merge branch 'fix/audit-refa' into fix/audit-cycle 2026-09-21 21:09:20 +02:00
TapTap 134dcd74cc refactor: drop dead filter_rules_apply, unify set_error, dedup path_is_within 2026-09-21 21:09:05 +02:00
TapTap 42f2f845ac refactor: drop Config**, dead old-args plumbing, dedup constants, -Wformat-signedness 2026-09-21 19:50:33 +02:00
TapTap 0669335ca5 Merge branch 'fix/audit-logfmt' into fix/audit-cycle 2026-09-21 19:43:17 +02:00
TapTap 391f76cd56 fix(log): add printf format attributes and fix format mismatches 2026-09-21 19:42:44 +02:00
TapTap 2021afe613 Merge branch 'fix/audit-fdpaths' into fix/audit-cycle 2026-09-21 19:30:21 +02:00
TapTap ba914e8ab3 fix(credentials): allow fd-backed store paths without O_NOFOLLOW 2026-09-21 19:30:01 +02:00
TapTap df8fe1ae4e Merge branch 'fix/audit-signal' into fix/audit-cycle 2026-09-21 19:27:03 +02:00
TapTap 2c490d58b7 Merge branch 'fix/audit-creds' into fix/audit-cycle 2026-09-21 19:27:03 +02:00
TapTap d55dabff2e Merge branch 'fix/audit-help' into fix/audit-cycle 2026-09-21 19:27:03 +02:00
TapTap b478a59a81 fix(cli): correct help text, per-codec compression default, and stale test 2026-09-21 19:26:42 +02:00
TapTap 865941f850 fix(credentials): open secret files with O_NOFOLLOW|O_NONBLOCK; drop dup includes
secret_file_open() previously opened --password-file/--early-input with
plain O_RDONLY, so a symlinked path was followed before the owner/mode
fstat gate ran, and an empty/planted FIFO could block fgets forever.
Open with O_NOFOLLOW|O_NONBLOCK|O_CLOEXEC (mirroring the dummy-key
sidecar): ELOOP now fails closed, and a writer-less FIFO yields EOF/EAGAIN
instead of hanging. Clear O_NONBLOCK again for regular files, where it is
a no-op, so their stdio read path is unchanged.

file.c: drop the duplicate <fcntl.h>/<unistd.h> includes (kept the first
occurrences).

Tests: a symlinked password file is rejected, and a writer-less named
FIFO fails cleanly without hanging.
2026-09-21 19:25:58 +02:00
TapTap 221cefa7cc fix(signal): use sigaction and async-signal-safe handlers
Client: replace the non-async-signal-safe signal(3) call inside
client_signal_handler() with a precomputed SIG_DFL sigaction(2), which is
on the POSIX async-signal-safe list.  The handler stays installed while a
transfer is armed so a repeated Ctrl-C still leads to a graceful abort
rather than a hard kill mid-cleanup.

Server: cleanup() now only calls _exit(2) (async-signal-safe).  The former
server_delete()/daemon_conf_free()/credentials_free() teardown called
free()/close()/SSL_CTX_free() from signal context, which can deadlock or
corrupt the heap if the signal lands inside malloc/free.  Handlers are
installed with sigaction(2) instead of signal(3).  The normal shutdown
path in main() still performs the full teardown; the signal path relies on
process exit to reclaim the parent daemon's socket, anonymous shared
mapping and heap (no named/persistent parent resource is left behind).
2026-09-21 19:25:24 +02:00
TapTap bb9b59024a Merge branch 'fix/audit-tests' into fix/audit-cycle 2026-09-21 19:19:36 +02:00
TapTap 5baf120243 Merge branch 'fix/audit-misc' into fix/audit-cycle 2026-09-21 19:19:36 +02:00
TapTap 84b7e1fd2f Merge branch 'fix/audit-filterx' into fix/audit-cycle 2026-09-21 19:19:36 +02:00
TapTap 800a978e15 Merge branch 'fix/audit-config' into fix/audit-cycle 2026-09-21 19:19:36 +02:00
TapTap 0f40e747f0 fix(filter): reject the x modifier in the --filter list parser
The standalone filter_rule_parse() already rejected the rsync xattr-name
'x' modifier, but the list parser used by --filter/-f silently dropped the
flag for merge/dir-merge rules (and relied on a second parse for plain
rules).  Reject it explicitly in filter_list_parse_append_depth() with the
same diagnostic, so '-x', 'merge,x' and 'dir-merge,x' all fail cleanly.

Also reject the unimplemented rsync merge modifiers 'e', 'n' and 'w'
instead of folding them into the pattern, which previously produced
misleading errors such as "could not read merge file 'n file'".  Only a
token made up solely of modifier characters is treated as a modifier run,
so glued patterns ('-newfile', '-e2e') and mixed tokens ("H,!secret")
keep their historical parsing.

Adds tests/test_filter.c with focused rejection and supported-syntax
cases.
2026-09-21 19:19:06 +02:00
TapTap b07306d5bc fix(config): check ssh-dest allocation and enforce MAX_FILTER_RULES client-side 2026-09-21 18:53:07 +02:00
TapTap f2c89b6e7c fix: mutex leak, errno-after-free, log_perror misuse, status validation
- multiprocessing: destroy mutex_progress on the dir_entries_mutex
  init-failure path (init >= 7); drop bogus log_perror
- delete_plan: capture errno before free() in apply_deferred_path
- queue/array_list: log_message instead of log_perror for non-errno
  conditions
- protocol: reject unknown wire Status values via status_is_valid() in
  receive_status, receive_status_timed and the keepalive reader; declare
  protocol_receive_status_timed in protocol.h
- protocol: %llu for unsigned long long debug counters
- tests: out-of-range status rejection test
2026-09-21 18:52:46 +02:00