New bounded STATUS_CLIENT_MSG (client→server) dispatched in all receiver loops; --stderr=client accepted, --no-msgs2stderr maps to it; client diagnostics queued (mutex-guarded, bounded, _Atomic activation) and flushed before the terminal handshake. Peer text is sanitized with output_escape and routed through the normal log destination/level (no log/terminal injection).
New STATUS_PARTIAL terminal; client exits 23 on partial and removes successfully-transferred --remove-source-files sources (rsync-verified). Clean=0, fatal≠23, --delete-limit=25 unchanged.
#314 — destination-state itemize for dirs/symlinks
STATUS_MKDIR/STATUS_SYMLINK now carry a destination-state probe (with target_matches on STATUS_DEST_INFO); -i/--out-format/--progress render rsync's .d..t....../cLc........ and suppress unchanged dirs/symlinks, including in the --threads path and the --chunk-serialization path.
Per-directory rules are carried on the delete carriers and evaluated deepest-first at the receiver under every delete timing; the merge-only e/n/w/- modifiers are implemented (rsync-verified).
A review caught a critical bug before merge: per-directory rules in a subdirectory were mirrored with a transfer-root-relative owner while the receiver walks receive-root-relative paths, so subdir rules never matched and rsync-protected extras were silently deleted. Fixed by using the destination-relative coordinate (scanner_dest_rel_path); new subdirectory differential cases (all timings, protect + exclude) fail on the pre-fix code and pass now. Also fixed: post-clear rule ownership, sender byte-budget/pattern-limit enforcement, a client_msg_active data race, a dangling deferred delete-observer context, and lost post-finalize diagnostics.
## Wire backlog cycle — closes #313, #314, #315, #316, #320
Wire-breaking: `PROTOCOL_VERSION` 2.29.0 → **2.30.0** (strict handshake). Config-frame layout unchanged (golden length 886; hash updated for the version string).
### #313 — `--stderr=client` client-message channel
New bounded `STATUS_CLIENT_MSG` (client→server) dispatched in all receiver loops; `--stderr=client` accepted, `--no-msgs2stderr` maps to it; client diagnostics queued (mutex-guarded, bounded, `_Atomic` activation) and flushed before the terminal handshake. Peer text is sanitized with `output_escape` and routed through the normal log destination/level (no log/terminal injection).
### #320 — rsync partial exit code 23
New `STATUS_PARTIAL` terminal; client exits 23 on partial and removes successfully-transferred `--remove-source-files` sources (rsync-verified). Clean=0, fatal≠23, `--delete-limit`=25 unchanged.
### #314 — destination-state itemize for dirs/symlinks
`STATUS_MKDIR`/`STATUS_SYMLINK` now carry a destination-state probe (with `target_matches` on `STATUS_DEST_INFO`); `-i`/`--out-format`/`--progress` render rsync's `.d..t......`/`cLc........` and suppress unchanged dirs/symlinks, including in the `--threads` path and the `--chunk-serialization` path.
### #316 — `--stats` deleted breakdown
`STATUS_STATS` grows `deleted_reg/dir/link/special`; `Number of deleted files: X (reg: A, dir: B, link: C, special: D)` matches rsync.
### #315 — receiver-side per-directory merge rules + `e/n/w/-` modifiers
Per-directory rules are carried on the delete carriers and evaluated deepest-first at the receiver under every delete timing; the merge-only `e/n/w/-` modifiers are implemented (rsync-verified).
**A review caught a critical bug before merge**: per-directory rules in a *subdirectory* were mirrored with a transfer-root-relative owner while the receiver walks receive-root-relative paths, so subdir rules never matched and rsync-protected extras were silently deleted. Fixed by using the destination-relative coordinate (`scanner_dest_rel_path`); new subdirectory differential cases (all timings, protect + exclude) fail on the pre-fix code and pass now. Also fixed: post-`clear` rule ownership, sender byte-budget/pattern-limit enforcement, a `client_msg_active` data race, a dangling deferred delete-observer context, and lost post-finalize diagnostics.
### Verification
Strict `-Werror`, clang-format 18, cppcheck clean; unit 45/45 (ASan with leak detection, UBSan, valgrind); integration **926 passed**; differential parity **82 passed**.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Wire backlog cycle — closes #313, #314, #315, #316, #320
Wire-breaking:
PROTOCOL_VERSION2.29.0 → 2.30.0 (strict handshake). Config-frame layout unchanged (golden length 886; hash updated for the version string).#313 —
--stderr=clientclient-message channelNew bounded
STATUS_CLIENT_MSG(client→server) dispatched in all receiver loops;--stderr=clientaccepted,--no-msgs2stderrmaps to it; client diagnostics queued (mutex-guarded, bounded,_Atomicactivation) and flushed before the terminal handshake. Peer text is sanitized withoutput_escapeand routed through the normal log destination/level (no log/terminal injection).#320 — rsync partial exit code 23
New
STATUS_PARTIALterminal; client exits 23 on partial and removes successfully-transferred--remove-source-filessources (rsync-verified). Clean=0, fatal≠23,--delete-limit=25 unchanged.#314 — destination-state itemize for dirs/symlinks
STATUS_MKDIR/STATUS_SYMLINKnow carry a destination-state probe (withtarget_matchesonSTATUS_DEST_INFO);-i/--out-format/--progressrender rsync's.d..t....../cLc........and suppress unchanged dirs/symlinks, including in the--threadspath and the--chunk-serializationpath.#316 —
--statsdeleted breakdownSTATUS_STATSgrowsdeleted_reg/dir/link/special;Number of deleted files: X (reg: A, dir: B, link: C, special: D)matches rsync.#315 — receiver-side per-directory merge rules +
e/n/w/-modifiersPer-directory rules are carried on the delete carriers and evaluated deepest-first at the receiver under every delete timing; the merge-only
e/n/w/-modifiers are implemented (rsync-verified).A review caught a critical bug before merge: per-directory rules in a subdirectory were mirrored with a transfer-root-relative owner while the receiver walks receive-root-relative paths, so subdir rules never matched and rsync-protected extras were silently deleted. Fixed by using the destination-relative coordinate (
scanner_dest_rel_path); new subdirectory differential cases (all timings, protect + exclude) fail on the pre-fix code and pass now. Also fixed: post-clearrule ownership, sender byte-budget/pattern-limit enforcement, aclient_msg_activedata race, a dangling deferred delete-observer context, and lost post-finalize diagnostics.Verification
Strict
-Werror, clang-format 18, cppcheck clean; unit 45/45 (ASan with leak detection, UBSan, valgrind); integration 926 passed; differential parity 82 passed.