Commit Graph
100 Commits
Author SHA1 Message Date
TapTap c29bce54fc Merge branch 'feat/transport-c2' into feat/transport-xattr 2026-09-23 00:35:05 +02:00
TapTap d98e971fcc Merge branch 'feat/transport-c1' into feat/transport-xattr 2026-09-23 00:35:05 +02:00
TapTap 492ce0ce89 feat(xattr): carry and apply symlink xattrs (protocol 2.29.0) 2026-09-23 00:34:39 +02:00
TapTap ec6692ac41 protocol: add transport I/O vtable over TCP/TLS primitives
Introduce ProtocolIoOps (send/recv/has_pending), selected once by
protocol_session_init() and protocol_session_set_ssl(), and dispatch the
send, receive and status-read loops through session->ops instead of
branching on session->ssl at runtime.

Each op performs one transfer attempt and classifies the result
(PROTOCOL_IO_RETRY/CLOSED/ERROR), preserving the WANT_READ/WANT_WRITE
wait_events switching, the SSL_ERROR_SYSCALL/EINTR retry, the
SSL_pending poll gating and the deadline handling. The raw read()/write()
fallback lives in the plaintext ops.

Add unit tests: a socketpair session with a counting ops wrapper proving
the loops dispatch through the vtable, and a worker-thread test that
protocol_current_ssl() resolves the bound session's SSL when io_ssl is NULL.
2026-09-23 00:18:36 +02:00
TapTap 1f8d60e30d protocol: resolve TLS transport from the bound session, not thread-local io_ssl
file_send.c chose between sendfile() and the TLS-aware buffered path by
calling io_get_ssl(), which reads the thread-local io_ssl. A worker thread
that bound a TLS ProtocolSession via protocol_session_bind() never ran the
handshake in that thread, so io_ssl is NULL there and a TLS + --threads
transfer took the raw sendfile() path on an encrypted socket.

Add protocol_current_ssl(), which prefers the bound session's SSL and falls
back to io_ssl on the fd-shim path, and use it in file_send.c. Un-xfail
test_tls_with_multithreading.
2026-09-23 00:18:29 +02:00
TapTap 6db9827b87 Merge PR #310: restore dumpable flag for ASan/LSan
CI / lint (push) Successful in 1m46s
CI / parity-fast (push) Skipped
CI / parity-full (push) Successful in 21s
CI / sanitizers (address) (push) Successful in 54s
CI / sanitizers (undefined) (push) Successful in 43s
CI / build-and-test (push) Successful in 1m22s
CI / fuzz-build (push) Successful in 48s
CI / coverage (push) Successful in 44s
CI / valgrind (push) Successful in 2m17s
2026-09-22 23:50:54 +02:00
TapTap a07cc00bb0 test: restore dumpable flag after setuid drop so LSan can run under ASan
CI / lint (pull_request) Successful in 1m48s
CI / parity-full (pull_request) Skipped
CI / sanitizers (address) (pull_request) Skipped
CI / sanitizers (undefined) (pull_request) Skipped
CI / fuzz-build (pull_request) Skipped
CI / coverage (pull_request) Skipped
CI / valgrind (pull_request) Skipped
CI / parity-fast (pull_request) Successful in 18s
CI / build-and-test (pull_request) Successful in 55s
2026-09-22 23:45:41 +02:00
TapTap 3ae7685655 Merge PR #309: parity burn-down
CI / lint (push) Successful in 1m46s
CI / parity-fast (push) Skipped
CI / parity-full (push) Successful in 22s
CI / sanitizers (address) (push) Failing after 54s
CI / sanitizers (undefined) (push) Successful in 43s
CI / build-and-test (push) Successful in 1m22s
CI / fuzz-build (push) Successful in 49s
CI / coverage (push) Successful in 44s
CI / valgrind (push) Successful in 2m19s
2026-09-22 23:33:21 +02:00
TapTap 4f945a8e39 docs: reconcile RSYNC_COMPAT for parity-next review follow-ups
CI / lint (pull_request) Successful in 1m46s
CI / parity-full (pull_request) Skipped
CI / sanitizers (address) (pull_request) Skipped
CI / sanitizers (undefined) (pull_request) Skipped
CI / fuzz-build (pull_request) Skipped
CI / coverage (pull_request) Skipped
CI / valgrind (pull_request) Skipped
CI / parity-fast (pull_request) Successful in 17s
CI / build-and-test (pull_request) Successful in 54s
2026-09-22 23:27:54 +02:00
TapTap 15f38f5b76 Merge branch 'feat/parity-f4' into feat/parity-next 2026-09-22 23:20:21 +02:00
TapTap 787967d3ce Merge branch 'feat/parity-f2' into feat/parity-next 2026-09-22 23:20:21 +02:00
TapTap 06e7aef5c9 Merge branch 'feat/parity-f1' into feat/parity-next 2026-09-22 23:20:21 +02:00
TapTap ee265d78ba fix(delete-before): replay pre-scan list in --threads path 2026-09-22 23:19:55 +02:00
TapTap 47b1b9b915 fix(xattr): fake-super device round-trip, --devices continue-on-error, harden stat parse 2026-09-22 23:05:40 +02:00
TapTap bb6c788cf9 fix(daemon): rsync read-only module default; warn on unenforced security keys 2026-09-22 22:53:23 +02:00
TapTap 0b40c47d6a Merge branch 'feat/parity-b4' into feat/parity-next
# Conflicts:
#	RSYNC_COMPAT.md
2026-09-22 22:08:16 +02:00
TapTap 6f81005094 Merge branch 'feat/parity-b3' into feat/parity-next
# Conflicts:
#	RSYNC_COMPAT.md
2026-09-22 22:07:45 +02:00
TapTap 193d358c64 Merge branch 'feat/parity-b2' into feat/parity-next 2026-09-22 22:06:25 +02:00
TapTap 8792e3265a Merge branch 'feat/parity-b1' into feat/parity-next 2026-09-22 22:06:25 +02:00
TapTap 3ec0ffb644 fix(delete-before): reuse pre-scan file list in single-threaded data pass 2026-09-22 22:05:50 +02:00
TapTap 80e8d7f450 feat(xattr): rsync-interoperable --fake-super stat; fix --devices error parity 2026-09-22 22:03:41 +02:00
TapTap 86741725fd feat(daemon): accept rsync rsyncd.conf key subset and --dparam mapping 2026-09-22 22:02:09 +02:00
TapTap f96f1764af feat(cli): accept --inc-recursive no-op and in-root absolute --temp-dir 2026-09-22 21:58:54 +02:00
TapTap d780a4625e Merge PR #308: close valid residuals of issues #286-#297
CI / lint (push) Successful in 1m45s
CI / parity-fast (push) Skipped
CI / parity-full (push) Successful in 21s
CI / sanitizers (address) (push) Successful in 52s
CI / sanitizers (undefined) (push) Successful in 42s
CI / build-and-test (push) Successful in 1m16s
CI / fuzz-build (push) Successful in 47s
CI / coverage (push) Successful in 44s
CI / valgrind (push) Successful in 2m18s
2026-09-22 17:30:36 +02:00
TapTap 5d1303ffdf Merge branch 'fix/issues-f4' into fix/issues-triage
CI / lint (pull_request) Successful in 1m45s
CI / parity-full (pull_request) Skipped
CI / sanitizers (address) (pull_request) Skipped
CI / sanitizers (undefined) (pull_request) Skipped
CI / fuzz-build (pull_request) Skipped
CI / coverage (pull_request) Skipped
CI / valgrind (pull_request) Skipped
CI / parity-fast (pull_request) Successful in 17s
CI / build-and-test (pull_request) Successful in 54s
2026-09-22 17:18:59 +02:00
TapTap 06b53c5b3d Merge branch 'fix/issues-f3' into fix/issues-triage 2026-09-22 17:18:59 +02:00
TapTap bf09e8893e Merge branch 'fix/issues-f2' into fix/issues-triage 2026-09-22 17:18:59 +02:00
TapTap 034c27926f Merge branch 'fix/issues-f1' into fix/issues-triage 2026-09-22 17:18:59 +02:00
TapTap aa15099d22 fix(output): restore --info=flist header; dir metadata on plan path; root line for -d 2026-09-22 17:17:04 +02:00
TapTap ff4db23831 fix(identity): free TO name on glob success path; harden test oracle 2026-09-22 17:08:03 +02:00
TapTap 79e45441c0 fix(receiver): defer --dirs directory mode to avoid EACCES on children
file_save_directory_to_disk() applied the exact source mode (fchmod)
inline for explicit --dirs/STATUS_MKDIR entries.  A restrictive source
mode (e.g. 0555) then made the directory read-only before its children
were written, so a non-root receiver failed each child with EACCES.  The
recursive -a path never hit this because it defers directory metadata.

Remove the inline fchmod and let the existing deferred
dir_metadata_list_apply() stamp the exact mode at end of transfer, as the
recursive path does.  Keep the inline ownership and xattrs (a direct
file_save_to_disk_full() caller has no deferred pass) and document the
resulting intentional ordering.  Capture errno before output_escape() in
the inline timestamp diagnostic so strerror() reports the real error, and
add the missing trailing newline to tests/test_xattr.c.
2026-09-22 17:06:54 +02:00
TapTap 6537227467 test(transport): de-race fallback/fd tests and gate for valgrind 2026-09-22 17:05:54 +02:00
TapTap 309c9aed98 refactor: const-correct dir/root locals in progress itemize 2026-09-22 16:46:23 +02:00
TapTap 84594197ee Merge branch 'fix/issues-b1' into fix/issues-triage 2026-09-22 16:37:56 +02:00
TapTap 7bf25048f6 docs: correct parity claims for issues #286-#297 2026-09-22 16:37:21 +02:00
TapTap b6b5eee20e Merge branch 'fix/issues-a3' into fix/issues-triage 2026-09-22 16:20:55 +02:00
TapTap 8dcd87609d Merge branch 'fix/issues-a2' into fix/issues-triage 2026-09-22 16:20:55 +02:00
TapTap 19fe63bd59 Merge branch 'fix/issues-a1' into fix/issues-triage 2026-09-22 16:20:55 +02:00
TapTap 1f5f8dc5a7 fix(output): emit directory/root lines for -i and --out-format (#292) 2026-09-22 16:20:03 +02:00
TapTap 3787695ba6 fix(xattr): apply --dirs directory xattrs fd-relative (#286) 2026-09-22 16:05:18 +02:00
TapTap b7cb213c8c fix: FROM name globs for identity maps; transport fallback tests (#294, #219) 2026-09-22 16:03:18 +02:00
TapTap 8cc3dd993b Merge PR #307: structural refactor cycle (no behavior change)
CI / lint (push) Successful in 1m42s
CI / parity-fast (push) Skipped
CI / parity-full (push) Successful in 21s
CI / sanitizers (address) (push) Successful in 53s
CI / sanitizers (undefined) (push) Successful in 43s
CI / build-and-test (push) Successful in 1m16s
CI / fuzz-build (push) Successful in 48s
CI / coverage (push) Successful in 44s
CI / valgrind (push) Successful in 2m18s
2026-09-22 14:58:26 +02:00
TapTap 1167e7970b refactor(delete): rename basis helper to delete_basis_relative
CI / lint (pull_request) Successful in 1m43s
CI / parity-full (pull_request) Skipped
CI / sanitizers (address) (pull_request) Skipped
CI / sanitizers (undefined) (pull_request) Skipped
CI / fuzz-build (pull_request) Skipped
CI / coverage (pull_request) Skipped
CI / valgrind (pull_request) Skipped
CI / parity-fast (pull_request) Successful in 19s
CI / build-and-test (pull_request) Successful in 57s
2026-09-22 14:52:36 +02:00
TapTap e98729f00e refactor: const-correct delete-manifest API; apply clang-format 2026-09-22 14:24:39 +02:00
TapTap c0020364b2 Merge branch 'refactor/minor' into refactor/structural 2026-09-22 14:06:55 +02:00
TapTap d7ac940a6b Merge branch 'refactor/cfg' into refactor/structural 2026-09-22 14:06:55 +02:00
TapTap be20e836de fix: correct throttle legacy resolution; add EXDEV temp-dir coverage 2026-09-22 14:06:26 +02:00
TapTap b549887138 refactor(config): group CLI-parse state; drop old_args field 2026-09-22 14:03:10 +02:00
TapTap 1ffd4744c6 Merge branch 'refactor/delete' into refactor/structural 2026-09-22 13:53:20 +02:00
TapTap 494cef2a0b Merge branch 'refactor/pending' into refactor/structural 2026-09-22 13:53:20 +02:00
TapTap ed7527cc2c Merge branch 'refactor/handler' into refactor/structural 2026-09-22 13:53:20 +02:00
TapTap 934defa965 refactor(delete): consolidate delete engine into delete.c 2026-09-22 13:52:57 +02:00
TapTap ade9be8600 refactor(receiver): per-status dispatch and shared pending teardown 2026-09-22 13:49:28 +02:00
TapTap 707bb659e8 refactor(server): decompose handler into phases 2026-09-22 13:46:17 +02:00
TapTap 33980bc4c8 Merge branch 'refactor/filerecv' into refactor/structural 2026-09-22 13:39:34 +02:00
TapTap 6a9372f4f5 Merge branch 'refactor/client' into refactor/structural 2026-09-22 13:39:34 +02:00
TapTap 5e1d6b6e10 Merge branch 'refactor/scanner' into refactor/structural 2026-09-22 13:39:34 +02:00
TapTap d2d1b63f44 refactor(receive): split file_save/incremental_check/delete_commit out
Pure structural split of src/shared/file_receive.c into focused translation
units behind the unchanged file_receive.h facade:

- file_save.c   : save-to-disk, special nodes, --delay-updates staging
- incremental_check.c : xattr/delta/basis/fuzzy receive + check state machine
- delete_commit.c : manifest receive + delete budget walkers
- file_receive.c : wire receive dispatch + deferred dir metadata

The shared receive_file_xattrs helper and MAX_FILE_DATA_SIZE are declared in
incremental_check.h.  file_save_to_disk_full_ex is decomposed into static
helpers (validation, special dispatch, dir/symlink creation, path resolution,
pre-write policies, data install) routed through one cleanup epilogue.

No behavior change.
2026-09-22 13:38:54 +02:00
TapTap a6659472fe refactor(scanner): split into filter/sequential/parallel TUs
Move the filter rule-tree/context helpers and entry inspection into
scanner_filter.c, the parallel scanner into scanner_parallel.c, and keep
the sequential scanner in scanner.c.  Shared internal declarations live in
the new scanner_internal.h; scanner.h stays the public façade.

Decompose directory_scanner_next into static helpers (skipped-entry,
selection-protection, mount/-x, directory-finish and per-entry handlers)
with no semantic change.
2026-09-22 13:38:05 +02:00
TapTap 4638030288 refactor(client): split reporting/scan/manifest out of client_send
Move the stats/progress reporting, scanner-preparation/scan helpers and
manifest/list/dry-run senders out of the ~3.9k-line client_send.c into
client_report.c, client_scan.c and client_manifest.c, sharing declarations
through the new internal client_send_internal.h.  client_send.c keeps the
transfer orchestration and is now ~2.1k lines.

Decompose the monolithic send_files into static phase helpers
(send_files_prepare/_prepare_delete/_run/_finalize/_cleanup) driven by a
single SendFilesState; ownership, ordering and exit codes are unchanged.

No behavior change.
2026-09-22 13:34:55 +02:00
TapTap 07dfec629f Merge PR #306: codebase audit cycle (security, correctness, refactors, docs)
CI / lint (push) Successful in 2m31s
CI / parity-fast (push) Skipped
CI / parity-full (push) Successful in 23s
CI / sanitizers (undefined) (push) Successful in 47s
CI / sanitizers (address) (push) Successful in 1m13s
CI / build-and-test (push) Successful in 1m19s
CI / fuzz-build (push) Successful in 49s
CI / coverage (push) Successful in 44s
CI / valgrind (push) Successful in 2m18s
2026-09-21 22:23:33 +02:00
TapTap c062a0762e Merge branch 'fix/audit-docs3' into fix/audit-cycle
CI / lint (pull_request) Successful in 2m46s
CI / parity-full (pull_request) Skipped
CI / sanitizers (address) (pull_request) Skipped
CI / sanitizers (undefined) (pull_request) Skipped
CI / fuzz-build (pull_request) Skipped
CI / coverage (pull_request) Skipped
CI / valgrind (pull_request) Skipped
CI / parity-fast (pull_request) Successful in 31s
CI / build-and-test (pull_request) Successful in 54s
2026-09-21 22:11:53 +02:00
TapTap 283f9f0823 docs: reflect filter modifiers, inplace+partial-dir, credentials hardening
Update the docs for the audit follow-up fixes:
- --filter merge modifiers e/n/w/- are now accepted-and-consumed on
  merge/dir-merge rules (rejected on non-merge, x rejected everywhere);
  their semantics stay unimplemented, so the --filter row moves to Caveat
  and the tally becomes 119/11/27 = 157.
- --inplace + --partial-dir is rejected with rsync's message.
- secret_file_open() O_NOFOLLOW (symlinked credential paths fail closed;
  fd-backed paths exempt) and ~3 s bound-wait on FIFO reads.
- AGENTS setpriv wording corrected to the collected instance count.
- CHANGELOG [Unreleased] audit section extended with the follow-ups.
2026-09-21 22:11:19 +02:00
TapTap 5754b9a952 Merge branch 'fix/audit-misc2' into fix/audit-cycle 2026-09-21 22:02:05 +02:00
TapTap b8a0efef7b Merge branch 'fix/audit-filter2' into fix/audit-cycle 2026-09-21 22:02:05 +02:00
TapTap 2e77c09447 Merge branch 'fix/audit-creds2' into fix/audit-cycle 2026-09-21 22:02:05 +02:00
TapTap 06c4026b74 fix(filter): accept e/n/w/- merge modifiers on merge/dir-merge rules
The earlier modifier-rejection change rejected e/n/w on all rules, but rsync
3.4.1 accepts them (plus the '-' merge-only modifier) on merge and dir-merge
rules.  Restrict the rejection to non-merge rules and consume the merge-file
modifiers (e/n/w/-) so they no longer leak into the merge filename.

- is_merge_rule()/is_merge_modifier_char() gate the merge-only modifiers.
- scan vs consume sets: e/n/w still count as modifier-run chars on every rule
  (pure tokens like -new/-press stay rejected), but are only consumed on merge
  rules, preserving mixed-token parsing such as H,!secret -> ecret.
- '-' is accepted/consumed only on merge/dir-merge (e.g. dir-merge,- .rules).
- x remains rejected everywhere with its dedicated message.
- e/n/w/- semantics remain unimplemented and are documented as accepted-but-
  ignored in filter.h.

Tests: split the merge forms out of the rejection test into a new acceptance
test asserting the merge file is read and dir_merge_names keeps the modifier-
free basename; non-merge pure-modifier forms still rejected.
2026-09-21 22:01:44 +02:00
TapTap 9f47b13712 fix(credentials): bound-wait on FIFO reads so slow process substitution works
secret_file_open() opened secret files with O_NONBLOCK and only cleared it
for S_ISREG, so on a FIFO/process-substitution source (--password-file
<(...), --early-input <(...)) fgets() failed immediately with EAGAIN when
the writer had not yet produced data, breaking slow producers.

Keep O_NONBLOCK at open() (a writer-less FIFO must not block the open) and
route all three readers through a new secret_read_line() helper.  It
accumulates a line across reads and, on EAGAIN/EWOULDBLOCK (or a partial
line) with no newline and no EOF, clearerr()s and polls for readability
against one overall CLOCK_MONOTONIC deadline of
CREDENTIAL_FIFO_READ_TIMEOUT_MS (3000 ms); on timeout or a real read error
it fails with a clear message.  EOF finishes normally.  Regular files are
left blocking and read exactly as before.

Handles a line split across several write()s and keeps the owner/mode
fstat gate, O_NOFOLLOW and the /dev/fd/N exception unchanged.
2026-09-21 22:01:18 +02:00
TapTap b1eddf0133 fix: config leak, compression log, inplace+partial-dir rejection, umask/root test fixes 2026-09-21 21:59:58 +02:00
TapTap 338c27db73 fix: resolve cppcheck shadow/always-true findings 2026-09-21 21:28:36 +02:00
TapTap 8d46a26c04 Merge branch 'fix/audit-docs2' into fix/audit-cycle 2026-09-21 21:18:48 +02:00
TapTap 707ba272df Merge branch 'fix/audit-docs1' into fix/audit-cycle 2026-09-21 21:18:48 +02:00
TapTap bc71a3c0a5 docs: correct README build deps, delete defaults, scanner, flags; AGENTS deps/CI 2026-09-21 21:18:26 +02:00
TapTap cee9b7647c docs: fix parity tally, compat rows, changelog, handoff for audit cycle 2026-09-21 21:14:37 +02:00
TapTap 3adb6dddb5 chore: drop tracked scratch data and extend .gitignore 2026-09-21 21:11:04 +02:00
TapTap d77849774e Merge branch 'fix/audit-refb' into fix/audit-cycle 2026-09-21 21:09:20 +02:00
TapTap b5c6f8b60f Merge branch 'fix/audit-refa' into fix/audit-cycle 2026-09-21 21:09:20 +02:00
TapTap 134dcd74cc refactor: drop dead filter_rules_apply, unify set_error, dedup path_is_within 2026-09-21 21:09:05 +02:00
TapTap 42f2f845ac refactor: drop Config**, dead old-args plumbing, dedup constants, -Wformat-signedness 2026-09-21 19:50:33 +02:00
TapTap 0669335ca5 Merge branch 'fix/audit-logfmt' into fix/audit-cycle 2026-09-21 19:43:17 +02:00
TapTap 391f76cd56 fix(log): add printf format attributes and fix format mismatches 2026-09-21 19:42:44 +02:00
TapTap 2021afe613 Merge branch 'fix/audit-fdpaths' into fix/audit-cycle 2026-09-21 19:30:21 +02:00
TapTap ba914e8ab3 fix(credentials): allow fd-backed store paths without O_NOFOLLOW 2026-09-21 19:30:01 +02:00
TapTap df8fe1ae4e Merge branch 'fix/audit-signal' into fix/audit-cycle 2026-09-21 19:27:03 +02:00
TapTap 2c490d58b7 Merge branch 'fix/audit-creds' into fix/audit-cycle 2026-09-21 19:27:03 +02:00
TapTap d55dabff2e Merge branch 'fix/audit-help' into fix/audit-cycle 2026-09-21 19:27:03 +02:00
TapTap b478a59a81 fix(cli): correct help text, per-codec compression default, and stale test 2026-09-21 19:26:42 +02:00
TapTap 865941f850 fix(credentials): open secret files with O_NOFOLLOW|O_NONBLOCK; drop dup includes
secret_file_open() previously opened --password-file/--early-input with
plain O_RDONLY, so a symlinked path was followed before the owner/mode
fstat gate ran, and an empty/planted FIFO could block fgets forever.
Open with O_NOFOLLOW|O_NONBLOCK|O_CLOEXEC (mirroring the dummy-key
sidecar): ELOOP now fails closed, and a writer-less FIFO yields EOF/EAGAIN
instead of hanging. Clear O_NONBLOCK again for regular files, where it is
a no-op, so their stdio read path is unchanged.

file.c: drop the duplicate <fcntl.h>/<unistd.h> includes (kept the first
occurrences).

Tests: a symlinked password file is rejected, and a writer-less named
FIFO fails cleanly without hanging.
2026-09-21 19:25:58 +02:00
TapTap 221cefa7cc fix(signal): use sigaction and async-signal-safe handlers
Client: replace the non-async-signal-safe signal(3) call inside
client_signal_handler() with a precomputed SIG_DFL sigaction(2), which is
on the POSIX async-signal-safe list.  The handler stays installed while a
transfer is armed so a repeated Ctrl-C still leads to a graceful abort
rather than a hard kill mid-cleanup.

Server: cleanup() now only calls _exit(2) (async-signal-safe).  The former
server_delete()/daemon_conf_free()/credentials_free() teardown called
free()/close()/SSL_CTX_free() from signal context, which can deadlock or
corrupt the heap if the signal lands inside malloc/free.  Handlers are
installed with sigaction(2) instead of signal(3).  The normal shutdown
path in main() still performs the full teardown; the signal path relies on
process exit to reclaim the parent daemon's socket, anonymous shared
mapping and heap (no named/persistent parent resource is left behind).
2026-09-21 19:25:24 +02:00
TapTap bb9b59024a Merge branch 'fix/audit-tests' into fix/audit-cycle 2026-09-21 19:19:36 +02:00
TapTap 5baf120243 Merge branch 'fix/audit-misc' into fix/audit-cycle 2026-09-21 19:19:36 +02:00
TapTap 84b7e1fd2f Merge branch 'fix/audit-filterx' into fix/audit-cycle 2026-09-21 19:19:36 +02:00
TapTap 800a978e15 Merge branch 'fix/audit-config' into fix/audit-cycle 2026-09-21 19:19:36 +02:00
TapTap 0f40e747f0 fix(filter): reject the x modifier in the --filter list parser
The standalone filter_rule_parse() already rejected the rsync xattr-name
'x' modifier, but the list parser used by --filter/-f silently dropped the
flag for merge/dir-merge rules (and relied on a second parse for plain
rules).  Reject it explicitly in filter_list_parse_append_depth() with the
same diagnostic, so '-x', 'merge,x' and 'dir-merge,x' all fail cleanly.

Also reject the unimplemented rsync merge modifiers 'e', 'n' and 'w'
instead of folding them into the pattern, which previously produced
misleading errors such as "could not read merge file 'n file'".  Only a
token made up solely of modifier characters is treated as a modifier run,
so glued patterns ('-newfile', '-e2e') and mixed tokens ("H,!secret")
keep their historical parsing.

Adds tests/test_filter.c with focused rejection and supported-syntax
cases.
2026-09-21 19:19:06 +02:00
TapTap b07306d5bc fix(config): check ssh-dest allocation and enforce MAX_FILTER_RULES client-side 2026-09-21 18:53:07 +02:00
TapTap f2c89b6e7c fix: mutex leak, errno-after-free, log_perror misuse, status validation
- multiprocessing: destroy mutex_progress on the dir_entries_mutex
  init-failure path (init >= 7); drop bogus log_perror
- delete_plan: capture errno before free() in apply_deferred_path
- queue/array_list: log_message instead of log_perror for non-errno
  conditions
- protocol: reject unknown wire Status values via status_is_valid() in
  receive_status, receive_status_timed and the keepalive reader; declare
  protocol_receive_status_timed in protocol.h
- protocol: %llu for unsigned long long debug counters
- tests: out-of-range status rejection test
2026-09-21 18:52:46 +02:00
TapTap 379f127859 test: add client timeouts and de-flake default-port test 2026-09-21 18:50:55 +02:00
TapTap 3799200f71 Merge branch 'fix/audit-partial' into fix/audit-cycle 2026-09-21 18:45:48 +02:00
TapTap 91c4a967e6 Merge branch 'fix/audit-receiver' into fix/audit-cycle 2026-09-21 18:45:48 +02:00
TapTap 88c8968b4c Merge branch 'fix/audit-transport' into fix/audit-cycle 2026-09-21 18:45:48 +02:00