Phase-4 identity-mapping row. Receiver-side ownership application, opt-in and privilege-gated: OFF for every existing transfer (plain -M still never applies ownership); only triggers when the client passes an identity flag and the receiver has permission; EPERM/EACCES warn+continue (never aborts); fd-relative fchown (symlink-safe), applied after the file is written. Adds src/shared/identity.{c,h}; new config fields (numeric_ids, chown uid/gid, usermap/groupmap id-pair tables) cross the wire; PROTOCOL_VERSION 2.10.0 -> 2.11.0. CLI parsing in client_cli.c, per-connection snapshot in server.c. Verified: STRICT_WARNINGS build clean, unit 28/28, full integration 291 passed / 10 skipped / 1 xpassed. Independent c-review REQUEST CHANGES (no blockers); applied fixes: EPERM/EACCES-only warn-and-continue, prominent root-receiver notice, identity_clear_active on early server error returns, --numeric-ids consistency.
Phase-4 identity-mapping row. Receiver-side ownership application, opt-in and privilege-gated: OFF for every existing transfer (plain -M still never applies ownership); only triggers when the client passes an identity flag and the receiver has permission; EPERM/EACCES warn+continue (never aborts); fd-relative fchown (symlink-safe), applied after the file is written. Adds src/shared/identity.{c,h}; new config fields (numeric_ids, chown uid/gid, usermap/groupmap id-pair tables) cross the wire; PROTOCOL_VERSION 2.10.0 -> 2.11.0. CLI parsing in client_cli.c, per-connection snapshot in server.c. Verified: STRICT_WARNINGS build clean, unit 28/28, full integration 291 passed / 10 skipped / 1 xpassed. Independent c-review REQUEST CHANGES (no blockers); applied fixes: EPERM/EACCES-only warn-and-continue, prominent root-receiver notice, identity_clear_active on early server error returns, --numeric-ids consistency.
Receiver-side ownership application, opt-in and privilege-gated:
- OFF for every existing transfer (plain -M/--preserve still never applies
ownership); only triggers on an explicit identity flag + receiver permission.
- EPERM/EACCES warn-and-continue (never aborts); other fchown errors escalate.
- fd-relative fchown after the file is written (symlink-safe, confined).
- New src/shared/identity.{c,h}; config fields numeric_ids / chown uid/gid /
usermap + groupmap id-pair tables cross the wire; PROTOCOL_VERSION 2.10.0
-> 2.11.0. CLI in client_cli.c; per-connection snapshot in server.c.
- Review fixes: EPERM/EACCES-only warn-and-continue, prominent root-receiver
notice, identity_clear_active on early server error paths, --numeric-ids
kept inert standalone (removed from activation trigger set).
Merged locally into dev (279fc84). Feature verified: STRICT_WARNINGS build clean, unit 28/28, full integration 291 passed/10 skipped/1 xpassed. Independent c-review REQUEST CHANGES (no blockers); fixes applied (EPERM/EACCES warn-only, root-receiver notice, server.c early-return cleanup, and --numeric-ids reinstated in the activate set so -M --numeric-ids applies).
Merged locally into dev (279fc84). Feature verified: STRICT_WARNINGS build clean, unit 28/28, full integration 291 passed/10 skipped/1 xpassed. Independent c-review REQUEST CHANGES (no blockers); fixes applied (EPERM/EACCES warn-only, root-receiver notice, server.c early-return cleanup, and --numeric-ids reinstated in the activate set so -M --numeric-ids applies).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Phase-4 identity-mapping row. Receiver-side ownership application, opt-in and privilege-gated: OFF for every existing transfer (plain -M still never applies ownership); only triggers when the client passes an identity flag and the receiver has permission; EPERM/EACCES warn+continue (never aborts); fd-relative fchown (symlink-safe), applied after the file is written. Adds src/shared/identity.{c,h}; new config fields (numeric_ids, chown uid/gid, usermap/groupmap id-pair tables) cross the wire; PROTOCOL_VERSION 2.10.0 -> 2.11.0. CLI parsing in client_cli.c, per-connection snapshot in server.c. Verified: STRICT_WARNINGS build clean, unit 28/28, full integration 291 passed / 10 skipped / 1 xpassed. Independent c-review REQUEST CHANGES (no blockers); applied fixes: EPERM/EACCES-only warn-and-continue, prominent root-receiver notice, identity_clear_active on early server error returns, --numeric-ids consistency.
Receiver-side ownership application, opt-in and privilege-gated: - OFF for every existing transfer (plain -M/--preserve still never applies ownership); only triggers on an explicit identity flag + receiver permission. - EPERM/EACCES warn-and-continue (never aborts); other fchown errors escalate. - fd-relative fchown after the file is written (symlink-safe, confined). - New src/shared/identity.{c,h}; config fields numeric_ids / chown uid/gid / usermap + groupmap id-pair tables cross the wire; PROTOCOL_VERSION 2.10.0 -> 2.11.0. CLI in client_cli.c; per-connection snapshot in server.c. - Review fixes: EPERM/EACCES-only warn-and-continue, prominent root-receiver notice, identity_clear_active on early server error paths, --numeric-ids kept inert standalone (removed from activation trigger set).Merged locally into dev (
279fc84). Feature verified: STRICT_WARNINGS build clean, unit 28/28, full integration 291 passed/10 skipped/1 xpassed. Independent c-review REQUEST CHANGES (no blockers); fixes applied (EPERM/EACCES warn-only, root-receiver notice, server.c early-return cleanup, and --numeric-ids reinstated in the activate set so -M --numeric-ids applies).Pull request closed