Symlink: --safe-links/--copy-unsafe-links semantics inverted; --munge-links is a no-op #287

Closed
opened 2026-09-15 19:33:33 +02:00 by TapTap · 1 comment
Owner

Audit findings (src/client/scanner.c, src/shared/file.c, src/shared/file_receive.c).

  • --safe-links dereferences SAFE (in-tree relative) links and skips unsafe ones — inverted vs rsync, which keeps safe links as symlinks and skips unsafe/absolute ones.
  • --copy-unsafe-links drops every relative (safe) link and dereferences absolute (unsafe) ones — also inverted/lossy.
  • --munge-links: the sender prefixes #SYMLINK/ and the receiver strips it, so the stored link is identical to plain -l; the flag is a no-op.
  • -l silently drops absolute / ..-escaping link targets (documented containment divergence, but note it).

Fix:

  • --safe-links: preserve safe contained links as symlinks; skip unsafe.
  • --copy-unsafe-links: preserve safe links; dereference only unsafe (absolute or escaping) ones.
  • --munge-links: implement rsync's receiving-side munging (store /rsyncd-munged/-prefixed unusable links) instead of sender-prefix/receiver-strip.
  • Add behavior tests (none exist today).
Audit findings (`src/client/scanner.c`, `src/shared/file.c`, `src/shared/file_receive.c`). - `--safe-links` dereferences SAFE (in-tree relative) links and skips unsafe ones — inverted vs rsync, which keeps safe links as symlinks and skips unsafe/absolute ones. - `--copy-unsafe-links` drops every relative (safe) link and dereferences absolute (unsafe) ones — also inverted/lossy. - `--munge-links`: the sender prefixes `#SYMLINK/` and the receiver strips it, so the stored link is identical to plain `-l`; the flag is a no-op. - `-l` silently drops absolute / `..`-escaping link targets (documented containment divergence, but note it). Fix: - `--safe-links`: preserve safe contained links as symlinks; skip unsafe. - `--copy-unsafe-links`: preserve safe links; dereference only unsafe (absolute or escaping) ones. - `--munge-links`: implement rsync's receiving-side munging (store `/rsyncd-munged/`-prefixed unusable links) instead of sender-prefix/receiver-strip. - Add behavior tests (none exist today).
TapTap added the needs-triage label 2026-09-15 19:33:33 +02:00
Author
Owner

Fixed. --safe-links now keeps safe contained links as symlinks and skips unsafe ones; --copy-unsafe-links preserves safe links and dereferences only unsafe ones; --munge-links is receiver-munge/sender-unmunge (rsync's direction), not a no-op. Behavior tests added. RSYNC_COMPAT/README prose corrected. Closing as completed.

Fixed. `--safe-links` now keeps safe contained links as symlinks and skips unsafe ones; `--copy-unsafe-links` preserves safe links and dereferences only unsafe ones; `--munge-links` is receiver-munge/sender-unmunge (rsync's direction), not a no-op. Behavior tests added. RSYNC_COMPAT/README prose corrected. Closing as completed.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: TapTap/FastSync#287