--safe-links dereferences SAFE (in-tree relative) links and skips unsafe ones — inverted vs rsync, which keeps safe links as symlinks and skips unsafe/absolute ones.
--copy-unsafe-links drops every relative (safe) link and dereferences absolute (unsafe) ones — also inverted/lossy.
--munge-links: the sender prefixes #SYMLINK/ and the receiver strips it, so the stored link is identical to plain -l; the flag is a no-op.
-l silently drops absolute / ..-escaping link targets (documented containment divergence, but note it).
Fix:
--safe-links: preserve safe contained links as symlinks; skip unsafe.
--copy-unsafe-links: preserve safe links; dereference only unsafe (absolute or escaping) ones.
Audit findings (`src/client/scanner.c`, `src/shared/file.c`, `src/shared/file_receive.c`).
- `--safe-links` dereferences SAFE (in-tree relative) links and skips unsafe ones — inverted vs rsync, which keeps safe links as symlinks and skips unsafe/absolute ones.
- `--copy-unsafe-links` drops every relative (safe) link and dereferences absolute (unsafe) ones — also inverted/lossy.
- `--munge-links`: the sender prefixes `#SYMLINK/` and the receiver strips it, so the stored link is identical to plain `-l`; the flag is a no-op.
- `-l` silently drops absolute / `..`-escaping link targets (documented containment divergence, but note it).
Fix:
- `--safe-links`: preserve safe contained links as symlinks; skip unsafe.
- `--copy-unsafe-links`: preserve safe links; dereference only unsafe (absolute or escaping) ones.
- `--munge-links`: implement rsync's receiving-side munging (store `/rsyncd-munged/`-prefixed unusable links) instead of sender-prefix/receiver-strip.
- Add behavior tests (none exist today).
Fixed. --safe-links now keeps safe contained links as symlinks and skips unsafe ones; --copy-unsafe-links preserves safe links and dereferences only unsafe ones; --munge-links is receiver-munge/sender-unmunge (rsync's direction), not a no-op. Behavior tests added. RSYNC_COMPAT/README prose corrected. Closing as completed.
Fixed. `--safe-links` now keeps safe contained links as symlinks and skips unsafe ones; `--copy-unsafe-links` preserves safe links and dereferences only unsafe ones; `--munge-links` is receiver-munge/sender-unmunge (rsync's direction), not a no-op. Behavior tests added. RSYNC_COMPAT/README prose corrected. Closing as completed.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Audit findings (
src/client/scanner.c,src/shared/file.c,src/shared/file_receive.c).--safe-linksdereferences SAFE (in-tree relative) links and skips unsafe ones — inverted vs rsync, which keeps safe links as symlinks and skips unsafe/absolute ones.--copy-unsafe-linksdrops every relative (safe) link and dereferences absolute (unsafe) ones — also inverted/lossy.--munge-links: the sender prefixes#SYMLINK/and the receiver strips it, so the stored link is identical to plain-l; the flag is a no-op.-lsilently drops absolute /..-escaping link targets (documented containment divergence, but note it).Fix:
--safe-links: preserve safe contained links as symlinks; skip unsafe.--copy-unsafe-links: preserve safe links; dereference only unsafe (absolute or escaping) ones.--munge-links: implement rsync's receiving-side munging (store/rsyncd-munged/-prefixed unusable links) instead of sender-prefix/receiver-strip.Fixed.
--safe-linksnow keeps safe contained links as symlinks and skips unsafe ones;--copy-unsafe-linkspreserves safe links and dereferences only unsafe ones;--munge-linksis receiver-munge/sender-unmunge (rsync's direction), not a no-op. Behavior tests added. RSYNC_COMPAT/README prose corrected. Closing as completed.