fix: close valid residuals of issues #286-#297 (triage cycle) #308

Merged
TapTap merged 17 commits from fix/issues-triage into dev 2026-09-22 17:30:36 +02:00
Owner

Issue triage cycle — close the valid residuals of #286–#297

Triaged all 16 open issues against dev @ 8cc3dd9. Most were already fixed by the parity/audit/structural cycles; this PR lands the remaining valid work. No wire change (PROTOCOL_VERSION stays 2.28.0).

Code fixes

  • #286 — --dirs/STATUS_MKDIR directory ownership/xattrs applied inline on the direct save path; the restrictive-mode regression is fixed by deferring the final directory mode to the existing end-of-transfer pass (a -d --files-from dir with source mode 0555 no longer makes child creation fail with EACCES on non-root receivers — reproduced and fixed via setpriv). Symlink-xattr gap documented (needs a wire block + version bump).
  • #292 — directory/transfer-root lines now emitted for -i/--out-format (rsync-identical order/format); plan-dir path now carries real directory metadata (%M/%U/%G no longer zeros under --delete-during/--delete-delay); --info=flist header restored under -i; root/ancestor lines emitted for -d/--files-from. The -i row is reclassified ✅ → ⚠️ for the remaining destination-state residual.
  • #294 — FROM name globs for --usermap/--groupmap implemented (sender-side fnmatch over the passwd/group DB, deduped/sorted, range-collapsed, bounded by MAX_IDENTITY_MAP); fixed a TO-name leak found in review (ASan-verified).
  • #219 — added deterministic first-address fallback / fd-cleanup / timeout unit tests for plain+TLS; hardened them against TOCTOU and gated the /proc/self/fd checks under valgrind.

Docs

  • RSYNC_COMPAT/README corrected for #287 (munge direction), #289 (full codec sets), #291 (-f/sendfile note), #296 (native credentials/batch non-interoperability, --stop-at, --trust-sender), #297 (-F ✅→⚠️, --bwlimit, -p masking, output-summary prose). Tally now 117 ✅ / 13 ⚠️ / 27 ❌.

Already fixed (to be closed on Gitea)

#217 (unified receiver dispatch), #218 (Config wire X-macro table), #220 (explicit CMake source lists), #288 (sockets + --copy-devices), #290 (all 6 delete items), #293 (--chmod), #295 (timeouts/max-alloc/temp-dir), plus the fixed parts of #286/#287/#289/#291/#294/#296/#297.

Verification

Strict -Werror, clang-format 18, cppcheck clean; unit 45/45 (ASan/UBSan/valgrind); integration 890 passed; differential parity 62 passed. Two reviews found the identity leak and the --dirs mode regression — both fixed and re-verified.

## Issue triage cycle — close the valid residuals of #286–#297 Triaged all 16 open issues against `dev` @ 8cc3dd9. Most were already fixed by the parity/audit/structural cycles; this PR lands the remaining valid work. No wire change (`PROTOCOL_VERSION` stays 2.28.0). ### Code fixes - **#286** — `--dirs`/`STATUS_MKDIR` directory ownership/xattrs applied inline on the direct save path; the **restrictive-mode regression is fixed** by deferring the final directory mode to the existing end-of-transfer pass (a `-d --files-from` dir with source mode `0555` no longer makes child creation fail with `EACCES` on non-root receivers — reproduced and fixed via `setpriv`). Symlink-xattr gap documented (needs a wire block + version bump). - **#292** — directory/transfer-root lines now emitted for `-i`/`--out-format` (rsync-identical order/format); plan-dir path now carries real directory metadata (`%M/%U/%G` no longer zeros under `--delete-during/--delete-delay`); `--info=flist` header restored under `-i`; root/ancestor lines emitted for `-d`/`--files-from`. The `-i` row is reclassified ✅ → ⚠️ for the remaining destination-state residual. - **#294** — FROM **name globs** for `--usermap`/`--groupmap` implemented (sender-side `fnmatch` over the passwd/group DB, deduped/sorted, range-collapsed, bounded by `MAX_IDENTITY_MAP`); fixed a TO-name leak found in review (ASan-verified). - **#219** — added deterministic first-address fallback / fd-cleanup / timeout unit tests for plain+TLS; hardened them against TOCTOU and gated the `/proc/self/fd` checks under valgrind. ### Docs - RSYNC_COMPAT/README corrected for #287 (munge direction), #289 (full codec sets), #291 (`-f`/sendfile note), #296 (native credentials/batch non-interoperability, `--stop-at`, `--trust-sender`), #297 (`-F` ✅→⚠️, `--bwlimit`, `-p` masking, output-summary prose). Tally now **117 ✅ / 13 ⚠️ / 27 ❌**. ### Already fixed (to be closed on Gitea) #217 (unified receiver dispatch), #218 (Config wire X-macro table), #220 (explicit CMake source lists), #288 (sockets + `--copy-devices`), #290 (all 6 delete items), #293 (`--chmod`), #295 (timeouts/max-alloc/temp-dir), plus the fixed parts of #286/#287/#289/#291/#294/#296/#297. ### Verification Strict `-Werror`, clang-format 18, cppcheck clean; unit 45/45 (ASan/UBSan/valgrind); integration 890 passed; differential parity 62 passed. Two reviews found the identity leak and the `--dirs` mode regression — both fixed and re-verified.
TapTap added 17 commits 2026-09-22 17:25:17 +02:00
file_save_directory_to_disk() applied the exact source mode (fchmod)
inline for explicit --dirs/STATUS_MKDIR entries.  A restrictive source
mode (e.g. 0555) then made the directory read-only before its children
were written, so a non-root receiver failed each child with EACCES.  The
recursive -a path never hit this because it defers directory metadata.

Remove the inline fchmod and let the existing deferred
dir_metadata_list_apply() stamp the exact mode at end of transfer, as the
recursive path does.  Keep the inline ownership and xattrs (a direct
file_save_to_disk_full() caller has no deferred pass) and document the
resulting intentional ordering.  Capture errno before output_escape() in
the inline timestamp diagnostic so strerror() reports the real error, and
add the missing trailing newline to tests/test_xattr.c.
Merge branch 'fix/issues-f4' into fix/issues-triage
CI / lint (pull_request) Successful in 1m45s
CI / parity-full (pull_request) Skipped
CI / sanitizers (address) (pull_request) Skipped
CI / sanitizers (undefined) (pull_request) Skipped
CI / fuzz-build (pull_request) Skipped
CI / coverage (pull_request) Skipped
CI / valgrind (pull_request) Skipped
CI / parity-fast (pull_request) Successful in 17s
CI / build-and-test (pull_request) Successful in 54s
5d1303ffdf
TapTap merged commit d780a4625e into dev 2026-09-22 17:30:36 +02:00
TapTap deleted branch fix/issues-triage 2026-09-22 17:30:36 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: TapTap/FastSync#308