file_restore_metadata() in src/shared/metadata.c:100 calls chown(path, metadata->uid, metadata->gid) but explicitly casts away the return value. If chown() fails (e.g., insufficient privileges, invalid uid/gid), the failure is silently ignored, and the caller believes metadata was fully restored. When the server runs as an unprivileged user, it may also unintentionally apply a uid/gid from a different machine that has no meaning locally.
Location
src/shared/metadata.c:100-101 — int chown_ret = chown(...); (void)chown_ret;
Suggested fix
Check chown_ret and log/return an error on failure.
Consider whether restoring uid/gid from a remote peer is appropriate at all; at minimum, it should only be attempted when the receiver is running as root and the caller has opted in.
Severity
Low
Category
bug, security
This issue was automatically generated by the issue-creator agent.
## Description
`file_restore_metadata()` in `src/shared/metadata.c:100` calls `chown(path, metadata->uid, metadata->gid)` but explicitly casts away the return value. If `chown()` fails (e.g., insufficient privileges, invalid uid/gid), the failure is silently ignored, and the caller believes metadata was fully restored. When the server runs as an unprivileged user, it may also unintentionally apply a `uid`/`gid` from a different machine that has no meaning locally.
## Location
- `src/shared/metadata.c:100-101` — `int chown_ret = chown(...); (void)chown_ret;`
## Suggested fix
1. Check `chown_ret` and log/return an error on failure.
2. Consider whether restoring `uid`/`gid` from a remote peer is appropriate at all; at minimum, it should only be attempted when the receiver is running as root and the caller has opted in.
## Severity
Low
## Category
bug, security
---
_This issue was automatically generated by the issue-creator agent._
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
file_restore_metadata()insrc/shared/metadata.c:100callschown(path, metadata->uid, metadata->gid)but explicitly casts away the return value. Ifchown()fails (e.g., insufficient privileges, invalid uid/gid), the failure is silently ignored, and the caller believes metadata was fully restored. When the server runs as an unprivileged user, it may also unintentionally apply auid/gidfrom a different machine that has no meaning locally.Location
src/shared/metadata.c:100-101—int chown_ret = chown(...); (void)chown_ret;Suggested fix
chown_retand log/return an error on failure.uid/gidfrom a remote peer is appropriate at all; at minimum, it should only be attempted when the receiver is running as root and the caller has opted in.Severity
Low
Category
bug, security
This issue was automatically generated by the issue-creator agent.