src/client/scanner.c: When the scanner encounters a symlink, stat() follows the link and treats it as a regular file or directory. The symlink nature is lost. Line 103: stat(cur_path, &stats) — should use lstat() and handle symlinks specially.
src/shared/metadata.c: file_restore_metadata() calls chmod() and chown() which follow symlinks, potentially modifying the target instead of the link itself.
src/shared/file.c: No code path to handle symlink creation on the receiver side.
This means:
Symlinks are silently converted to regular files/directories containing the same content as the target
This can cause data duplication or unexpected behavior
Rsync securely copies symlinks as symlinks by default
Suggested Fix:
Use lstat() in the scanner and detect S_ISLNK()
Add a SYMLINK status code to the protocol
Store the link target path and recreate as a symlink on the receiver
Severity: medium
FastSync has no handling for symbolic links:
1. **`src/client/scanner.c`**: When the scanner encounters a symlink, `stat()` follows the link and treats it as a regular file or directory. The symlink nature is lost. Line 103: `stat(cur_path, &stats)` — should use `lstat()` and handle symlinks specially.
2. **`src/shared/metadata.c`**: `file_restore_metadata()` calls `chmod()` and `chown()` which follow symlinks, potentially modifying the target instead of the link itself.
3. **`src/shared/file.c`**: No code path to handle symlink creation on the receiver side.
This means:
- Symlinks are silently converted to regular files/directories containing the same content as the target
- This can cause data duplication or unexpected behavior
- Rsync securely copies symlinks as symlinks by default
**Suggested Fix:**
1. Use `lstat()` in the scanner and detect `S_ISLNK()`
2. Add a `SYMLINK` status code to the protocol
3. Store the link target path and recreate as a symlink on the receiver
**Severity:** medium
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
FastSync has no handling for symbolic links:
src/client/scanner.c: When the scanner encounters a symlink,stat()follows the link and treats it as a regular file or directory. The symlink nature is lost. Line 103:stat(cur_path, &stats)— should uselstat()and handle symlinks specially.src/shared/metadata.c:file_restore_metadata()callschmod()andchown()which follow symlinks, potentially modifying the target instead of the link itself.src/shared/file.c: No code path to handle symlink creation on the receiver side.This means:
Suggested Fix:
lstat()in the scanner and detectS_ISLNK()SYMLINKstatus code to the protocolSeverity: medium