Release v2.26.0 #284

Merged
TapTap merged 210 commits from dev into main 2026-09-18 19:05:52 +02:00
8 changed files with 210 additions and 168 deletions
Showing only changes of commit 317d5d081a - Show all commits
+1 -1
View File
@@ -551,7 +551,7 @@ before the module list, before authentication, and the connecting peer address
## Protocol and Security
FastSync protocol version `2.19.0` is shared by the client and server. The
FastSync protocol version `2.20.0` is shared by the client and server. The
current protocol is sender-driven and includes configuration negotiation,
including the maximum allocation limit, incremental checks, checksums,
manifests, keep-alives, abort handling, per-file remove-source results, and
+17 -2
View File
@@ -679,7 +679,7 @@ now transmits targets (the prior behavior was broken/partial); its status moved
| `--stop-after=MINS` | Stop after N minutes | ✅ Implemented | Client-only sender stop deadline (Phase 6): computing `--stop-after=MINS` (a positive minute count; 0/negative/garbage rejected) and `--stop-at=TIME` (`HH:MM`, `HH:MM:SS`, or `now+N[smhd]`; a past time stops immediately). The transfer stops ELEGANTLY at the next chunk boundary: everything already fully sent is kept and applied, the run returns 0, and --delete (late/delete-after timing) does NOT wipe the destination — when the scan is cut short the partial keep-set manifest is suppressed with a warning (the delete walk is skipped rather than acting on an incomplete keep-set, so unscanned source mirrors survive). `--delete-before`/`--delete-during` still run their complete pre-scan (which ignores the deadline). Local client-only fields: never serialized into the wire config frame, so no PROTOCOL_VERSION bump. `--stop-after` uses CLOCK_MONOTONIC; `--stop-at` uses the wall clock. Works single-threaded and under `-j`/`--threads` (multithreaded). Divergence: rsync computes `--stop-after` from the run start; FastSync likewise. When both are given, the earlier of the two deadlines wins (checked per iteration). See the Phase-6 stop notes below |
| `--stop-at=TIME` | Stop at specified time | ✅ Implemented | Same feature as `--stop-after` (deadline transfer stop), absolute wall-clock form (`HH:MM[:SS]` or `now+N[smhd]`). See the row above and the Phase-6 stop notes |
| `--fsync` | Fsync every written file before publication | ✅ Implemented | |
| `--protocol=NUM` | Force older protocol version | ✅ Implemented | Forces the wire protocol version for this transfer. FastSync has exactly ONE wire format (`PROTOCOL_VERSION`, currently 2.19.0) with no downgrade/backward-compat code paths, so `--protocol=2.19.0` is accepted (it sets the version claim the client sends, which the server already requires to match exactly) and **every other value is rejected up front** with a clear error before any connection — it does not and cannot speak an older or virtual wire format. Divergence from rsync (which negotiates a range and downgrades to an integer 0..31): FastSync's honest contract is force-to-the-one-supported-value; a genuine downgrade would require a per-version compatibility layer that does not exist. Client-only; the server-side exact-match check is unchanged. `--protocol=2.18.0`/`2.18`/`2.17.0`/`2.16.0`/`2.15.0`/`216`/`31`/garbage are all rejected. See the Phase-6 protocol note below |
| `--protocol=NUM` | Force older protocol version | ✅ Implemented | Forces the wire protocol version for this transfer. FastSync has exactly ONE wire format (`PROTOCOL_VERSION`, currently 2.20.0) with no downgrade/backward-compat code paths, so `--protocol=2.20.0` is accepted (it sets the version claim the client sends, which the server already requires to match exactly) and **every other value is rejected up front** with a clear error before any connection — it does not and cannot speak an older or virtual wire format. Divergence from rsync (which negotiates a range and downgrades to an integer 0..31): FastSync's honest contract is force-to-the-one-supported-value; a genuine downgrade would require a per-version compatibility layer that does not exist. Client-only; the server-side exact-match check is unchanged. `--protocol=2.19.0`/`2.18.0`/`2.18`/`2.17.0`/`2.16.0`/`2.15.0`/`216`/`31`/garbage are all rejected. See the Phase-6 protocol note below |
| `--iconv=CONVERT_SPEC` | Charset conversion | ✅ Implemented | Charset conversion of FILE NAMES (not content) at the protocol boundary via iconv(3): `--iconv=LOCAL[,REMOTE]` — the sender converts each local filename LOCAL→REMOTE before transmitting, and the receiver converts each wire filename REMOTE→LOCAL before creating/writing. The full CONVERT_SPEC is serialized into the config frame as a new trailing string field so the peer knows the wire charset; **PROTOCOL_VERSION bumped 2.15.0 → 2.16.0**. `LOCAL[,REMOTE]` parse: single charset ⇒ LOCAL==REMOTE (identity both ways); garbage rejected up front. Validation probes BOTH directions (a spec that only opens one way is refused, as is a NUL-emitting target charset like utf-16/utf-32/ucs-2, since filenames cannot contain NUL). An unrepresentable name (EILSEQ/EINVAL) fails that path cleanly with a logged `--iconv: cannot convert file name ...` and is never written mangled/truncated. Conversion is applied at EVERY wire-path site (regular/MKDIR/hardlink path+target/symlink path+target/SPECIAL, the delete manifest, the incremental-check path, and the `-s`/`chunk_serialize` embedded blob path), on both client and server (`--iconv` is also a server/daemon option). Zero overhead when unset. See the Phase-6 iconv notes below |
| `--checksum-seed=NUM` | Set checksum seed | ✅ Implemented | Sets the seed for FastSync's whole-file xxHash64 digest (full 64-bit seed) and for the delta path's per-block xxHash32 strong checksum (low 32 bits of the seed). An explicit seed deterministically changes every computed digest on BOTH endpoints (sender and receiver share the seed via the config frame, protocol 2.10.0), so identical runs with the same seed skip the same files and a changed seed changes the digests — the explicit-seed path that makes xxHash comparisons deterministic. `--checksum-choice=md5` has no seed and ignores it (documented). The value is a strict decimal 0..2⁶⁴-1 (blank, signed, or non-numeric values are rejected). Like rsync, a seed only matters where a digest is actually computed (`--checksum` or a basis-dir run, or a delta transfer); it does not by itself enable `--checksum`/`--delta`. Divergence from rsync: the default is seed 0, and FastSync never randomizes the seed (rsync uses a random per-transfer seed when `--checksum-seed` is unset); FastSync's unset default therefore reproduces its historical byte-for-byte behavior |
| `--secluded-args`, `-s` | Use protocol to send args | ⛔ Impossible/Divergence | Accepted for CLI compatibility (including the rsync short `-s`, Phase 7 Wave A) but a documented **no-op / divergence**. rsync's `-s` protects arguments from shell expansion by shipping them over the protocol; FastSync never passes remote arguments through a shell expansion boundary in the first place — its SSH transport builds the remote argv as **single-quote-escaped shell words** (`ssh_build_remote_command`), so the injection/leak that `-s` guards against does not exist and there is nothing to "seclude". Implementing a true arg-send protocol would mean replacing the argv-based SSH launch with an in-band argument channel, a large redesign of the transport that buys no security here. Chunk serialization remains the long-only `--chunk-serialization`. |
@@ -795,7 +795,7 @@ These are the hardest compatibility items because they require durable formats o
**Phase 6, Wave B (iconv) shipping note (PROTOCOL 2.15.0 → 2.16.0):** `--iconv=LOCAL[,REMOTE]` converts file NAMES at the wire boundary (never content). The full CONVERT_SPEC is serialized into the config frame as a new trailing string field (empty→NULL canonicalized), so both ends share the same wire charset interpretation; this required the PROTOCOL bump because the frame is a strict ordered sequence and a peer that does not parse the new trailing field would desynchronize. Each end derives LOCAL (its own charset) and REMOTE (the wire charset): the sender opens LOCAL→REMOTE and converts every transmitted filename; the receiver opens REMOTE→LOCAL and converts every received filename before creating/writing. Conversion is applied at every wire-path site (regular/MKDIR/hardlink path+target/symlink path+target/SPECIAL, the delete manifest keep/protected/missing entries, the incremental-check path, and the embedded `-s`/chunk-blob path). A name it cannot convert (EILSEQ/EINVAL) is failed cleanly with a logged `--iconv: cannot convert file name ...` and is never written truncated/mangled. Validation probes both directions up front (both the sender local→remote and the receiver remote→local, and, for a server/daemon with its own `--iconv`, the client-REMOTE→server-LOCAL pair) so an unusable spec is rejected before the connection rather than mid-transfer, and NUL-emitting target charsets (utf-16/utf-32/ucs-2) are refused because filenames cannot contain NUL. Divergence documented upstream: the receiver does NOT half-swap; the wire charset always comes from the sender's REMOTE half, so a server whose local charset differs from the client's LOCAL must declare it with its own `--iconv`. Conversion is process-global and runs on a single thread per process (sender thread / receiver-loop thread), initialized before worker threads start and freed after they join.
**Phase 6, Wave C (protocol-version) shipping note (no PROTOCOL_VERSION change):** `--protocol=NUM` lets the client force the wire protocol version for a transfer. FastSync's protocol is a single lockstep format: the config frame is a strict ordered sequence and the server requires the client's version string to equal `PROTOCOL_VERSION` exactly (`config_receive_with_validate`, src/shared/config.c) — there are no older-format code paths and no downgrade/negotiation machinery, so a lower/higher/virtual version can never be spoken. The honest contract is therefore: `--protocol=2.19.0` (the current `PROTOCOL_VERSION`, as of the A7 auth redesign) is accepted and stored into the client's `version` claim (which `config_send` already transmits), and every other value — `2.18.0`, `2.18`, `2.17.0`, `2.16.0`, `2.15.0`, `3.0.0`, rsync-integer spellings like `216`/`31`, garbage, empty — is rejected up front in `validate_config()` before any connection, with a clear error that FastSync supports only its current wire protocol and cannot speak an older or virtual one. Implementation is client-only: a server-side `--protocol` is intentionally not added because the server has no negotiation (it only enforces exact match), and it could only ever be the current version. This preserves (and slightly tightens) existing validation: the client now also refuses to launch with a version it cannot actually speak, rather than only the server rejecting it later. A genuine downgrade would require a per-version compatibility layer for every frame/feature added since (append 2.10, preallocate 2.11, hardlinks 2.12, devices/specials/symlink-trust/xattr 2.13, remote-option 2.14, daemon module/auth 2.15, iconv 2.16, dir/symlink times 2.17, privilege flags --super/--copy-as 2.18, SCRAM daemon auth 2.19) and is intentionally out of scope — documented divergences from rsync's integer-negotiated downgrade remain.
**Phase 6, Wave C (protocol-version) shipping note (no PROTOCOL_VERSION change):** `--protocol=NUM` lets the client force the wire protocol version for a transfer. FastSync's protocol is a single lockstep format: the config frame is a strict ordered sequence and the server requires the client's version string to equal `PROTOCOL_VERSION` exactly (`config_receive_with_validate`, src/shared/config.c) — there are no older-format code paths and no downgrade/negotiation machinery, so a lower/higher/virtual version can never be spoken. The honest contract is therefore: `--protocol=2.20.0` (the current `PROTOCOL_VERSION`, as of the packed-metadata wave) is accepted and stored into the client's `version` claim (which `config_send` already transmits), and every other value — `2.19.0`, `2.18.0`, `2.18`, `2.17.0`, `2.16.0`, `2.15.0`, `3.0.0`, rsync-integer spellings like `216`/`31`, garbage, empty — is rejected up front in `validate_config()` before any connection, with a clear error that FastSync supports only its current wire protocol and cannot speak an older or virtual one. Implementation is client-only: a server-side `--protocol` is intentionally not added because the server has no negotiation (it only enforces exact match), and it could only ever be the current version. This preserves (and slightly tightens) existing validation: the client now also refuses to launch with a version it cannot actually speak, rather than only the server rejecting it later. A genuine downgrade would require a per-version compatibility layer for every frame/feature added since (append 2.10, preallocate 2.11, hardlinks 2.12, devices/specials/symlink-trust/xattr 2.13, remote-option 2.14, daemon module/auth 2.15, iconv 2.16, dir/symlink times 2.17, privilege flags --super/--copy-as 2.18, SCRAM daemon auth 2.19, packed metadata 2.20) and is intentionally out of scope — documented divergences from rsync's integer-negotiated downgrade remain.
**Phase-1/2 selection-and-update status correction (docs):** `-I/--ignore-times`, `--size-only`, `-@/--modify-window`, `--existing`, `--ignore-existing`, `-u/--update`, `-W/--whole-file`, and `--compress-threads` were previously listed as not-implemented in this document but are in fact fully implemented and tested on `dev`. This pass corrects the matrix to match the code. The realistic model of these is that FastSync is a *sender-driven* whole-tree copy, so the size+mtime quick-check and all three receiver-policy skips (`--existing`, `--ignore-existing`, `-u`) are evaluated against the **destination** on the receiver side, and their booleans cross the wire in the config frame. `-I`/`--size-only`/`--modify-window` modify the `--incremental` per-file `STATUS_CHECK` handshake's match predicate (`-I` disables the mtime leg and forces transfer; `--size-only` drops only the mtime leg; `--modify-window` adds tolerance to `metadata_mtime_matches`); they require `--incremental` (or a basis dir) to have a handshake to affect, mirroring how they only matter where a quick-check exists in rsync. `--existing`/`--ignore-existing`/`-u` are receiver write-time policies (skipping the write / newer-destination guard) applied across the regular-file, `--delay-updates`-staged, hardlink-sibling, and special/device paths; `-u` implies `-M` metadata and uses a second-then-nanosecond strict `>` newer check; both correctly influence `--remove-source-files` (a skipped source is not removed). `-W/--whole-file` disables block-level delta (opt-in via `--delta`), folded into the wire `use_delta` so no protocol bump was needed, and makes `--fuzzy` inert; `--append`/`--append-verify` are rejected with `-W`. `--compress-threads=NUM` (1..64, client-only, never crosses the wire) sizes the zstd compression worker pool. No code was changed by this correction; the implementation had landed in earlier merge waves (feat/ignore-times, feat/ignore-existing via the newer `file_to_disk_secure_no_replace`/`linkat EEXIST` path, feat/size-only, feat/modify-window, feat/whole-file, feat/update, compression-threads).
@@ -840,6 +840,21 @@ These are the last compatibility items and the closing phase toward rsync flag p
**Post-Phase-7 Summary (after Waves A–E).** ✅143 / 🔀0 / ⛔4 / ⚠️0 / 🔄0 / ❌0 = 147. The 3 `🔀 Alt Arg` rows (`-a`, `-p`, `-z`) are ✅ (Wave A). All 10 prior `⚠️ Partial` rows are resolved to ✅ (`-S`, `-P`, `--block-size`, `--fake-super`, `--devices`, `--copy-devices`, `--write-devices`) or ⛔ (`--stderr=client`, `-N/--crtimes`, `--specials` for the impossible socket case). The 3 `🔄 Compatibility No-op` rows are resolved: `-O`/`-J` are now real ✅ (Wave D), `--secluded-args` is ⛔. The **Impossible/Divergence** bucket holds the 4 physically-impossible/divergent flags: `--stderr=client`, `-N/--crtimes`, `--specials` (sockets), `--secluded-args`. The last two `❌ Not Implemented` rows — `--super` and `--copy-as=USER[:GROUP]` — are now ✅ (Wave E). **No `❌ Not Implemented` rows remain.**
## Packed Metadata Frame (protocol 2.20.0)
A file's metadata used to cross the wire as up to 12 separate per-field framed
messages (a present flag followed by mode/uid/gid/mtime/atime/crtime writes),
which cost ~11 extra protocol frames per file on many-small-file trees. FastSync
now sends the metadata as ONE packed frame: a single `int32` present flag
(`0` = absent) followed, when present, by the fixed
`FILE_METADATA_WIRE_SIZE`-byte (68-byte) field record already emitted by the
shared `metadata_to_buf()`/`metadata_from_buf()` chunk codec. Absent metadata is
a lone `int32` zero. The encoded field layout is unchanged (only the framing
collapses), so chunk-serialized blobs remain byte-identical; `PROTOCOL_VERSION`
was bumped `2.19.0 → 2.20.0` because a 2.19 peer would desynchronize on the
removed frames. The strict same-version handshake rejects any mismatch before a
byte of the frame is parsed.
### Recommended Delivery Order
1. Resolve short-option conflicts (`-m`, `-M`, `-T`, `-f`, `-s`) and define the compatibility contract.
+18 -2
View File
@@ -642,8 +642,24 @@ typedef struct Config {
* anything else) is what keeps a 2.19 client and a 2.18 server from ever
* reaching that state. SECURITY: a 2.19 store holds a salted PBKDF2 verifier
* and cannot verify (and refuses to load) a legacy unsalted-SHA-256 store line,
* so an old bearer digest can never be replayed against a 2.19 daemon. */
#define PROTOCOL_VERSION "2.19.0"
* so an old bearer digest can never be replayed against a 2.19 daemon.
*
* Packed Metadata Wave: 2.19.0 -> 2.20.0.
*
* WHY the bump, grounded in the wire: metadata_send()/metadata_receive() no
* longer emit/consume the metadata as up to 12 separate per-field framed
* writes. A file's metadata now crosses the wire as ONE packed frame: a
* single int32 present flag (0 = absent, 1 = present) followed, when present,
* by the fixed FILE_METADATA_WIRE_SIZE-byte (68-byte) field record produced by
* metadata_to_buf(). A 2.19 peer would desynchronize on the removed frames
* (it would read the packed record's bytes as a stream of separate field
* frames), so the strict same-version handshake (config_receive rejects a
* mismatched version before parsing anything else) is what keeps a 2.20 client
* and a 2.19 server from ever reaching that state. The encoded field layout
* itself is unchanged (only its framing collapses), so the chunk codec, which
* already used the packed metadata_to_buf()/metadata_from_buf() codec, is
* byte-identical to before. */
#define PROTOCOL_VERSION "2.20.0"
#define DEFAULT_CHUNK_SIZE (10 * 1024 * 1024)
/* Upper bound on total basis-dir entries (rsync caps --link-dest at 20). */
#define MAX_BASIS_DIRS 64
+21 -124
View File
@@ -157,33 +157,17 @@ FileMetadata* metadata_from_buf(char** buf) {
bool metadata_send(int file_descriptor, const FileMetadata* m) {
if (m == NULL) {
int32_t zero = 0;
return send_n_data(file_descriptor, &zero, sizeof(zero));
int32_t absent = 0;
return send_n_data(file_descriptor, &absent, sizeof(absent));
}
int32_t present = 1;
int32_t mode = (int32_t)m->mode;
int32_t uid = (int32_t)m->uid;
int32_t gid = (int32_t)m->gid;
int64_t mtime_sec = (int64_t)m->mtime_sec;
int64_t mtime_nsec = (int64_t)m->mtime_nsec;
int32_t atime_valid = m->atime_valid ? 1 : 0;
int64_t atime_sec = (int64_t)m->atime_sec;
int64_t atime_nsec = (int64_t)m->atime_nsec;
int32_t crtime_valid = m->crtime_valid ? 1 : 0;
int64_t crtime_sec = (int64_t)m->crtime_sec;
int64_t crtime_nsec = (int64_t)m->crtime_nsec;
return send_n_data(file_descriptor, &present, sizeof(present)) &&
send_n_data(file_descriptor, &mode, sizeof(mode)) &&
send_n_data(file_descriptor, &uid, sizeof(uid)) &&
send_n_data(file_descriptor, &gid, sizeof(gid)) &&
send_n_data(file_descriptor, &mtime_sec, sizeof(mtime_sec)) &&
send_n_data(file_descriptor, &mtime_nsec, sizeof(mtime_nsec)) &&
send_n_data(file_descriptor, &atime_valid, sizeof(atime_valid)) &&
send_n_data(file_descriptor, &atime_sec, sizeof(atime_sec)) &&
send_n_data(file_descriptor, &atime_nsec, sizeof(atime_nsec)) &&
send_n_data(file_descriptor, &crtime_valid, sizeof(crtime_valid)) &&
send_n_data(file_descriptor, &crtime_sec, sizeof(crtime_sec)) &&
send_n_data(file_descriptor, &crtime_nsec, sizeof(crtime_nsec));
/* One packed frame (protocol 2.20.0): the int32 present flag followed by the
fixed FILE_METADATA_WIRE_SIZE-byte field record. metadata_to_buf() emits
exactly that layout (present + fields), so build it once and write the
whole record in a single call instead of one frame per field. */
char packed[sizeof(int32_t) + FILE_METADATA_WIRE_SIZE];
char* cursor = packed;
metadata_to_buf(&cursor, m);
return send_n_data(file_descriptor, packed, sizeof(packed));
}
FileMetadata* metadata_receive(int file_descriptor, int* ok) {
@@ -203,109 +187,22 @@ FileMetadata* metadata_receive(int file_descriptor, int* ok) {
*ok = 0;
return NULL;
}
FileMetadata* m = protocol_alloc(sizeof(FileMetadata));
/* Rebuild the packed record metadata_from_buf() expects: the present flag we
just read, followed by exactly FILE_METADATA_WIRE_SIZE field bytes. */
char packed[sizeof(int32_t) + FILE_METADATA_WIRE_SIZE];
memcpy(packed, &present, sizeof(present));
if (!receive_n_data(file_descriptor, packed + sizeof(present), FILE_METADATA_WIRE_SIZE)) {
if (ok)
*ok = 0;
return NULL;
}
char* cursor = packed;
FileMetadata* m = metadata_from_buf(&cursor);
if (m == NULL) {
if (ok)
*ok = 0;
return NULL;
}
int32_t mode;
if (!receive_n_data(file_descriptor, &mode, sizeof(mode))) {
free(m);
if (ok)
*ok = 0;
return NULL;
}
m->mode = (mode_t)mode;
int32_t uid;
if (!receive_n_data(file_descriptor, &uid, sizeof(uid))) {
free(m);
if (ok)
*ok = 0;
return NULL;
}
m->uid = (uid_t)uid;
int32_t gid;
if (!receive_n_data(file_descriptor, &gid, sizeof(gid))) {
free(m);
if (ok)
*ok = 0;
return NULL;
}
m->gid = (gid_t)gid;
int64_t mtime_sec;
if (!receive_n_data(file_descriptor, &mtime_sec, sizeof(mtime_sec))) {
free(m);
if (ok)
*ok = 0;
return NULL;
}
m->mtime_sec = (time_t)mtime_sec;
int64_t mtime_nsec;
if (!receive_n_data(file_descriptor, &mtime_nsec, sizeof(mtime_nsec))) {
free(m);
if (ok)
*ok = 0;
return NULL;
}
m->mtime_nsec = (long)mtime_nsec;
int32_t atime_valid;
if (!receive_n_data(file_descriptor, &atime_valid, sizeof(atime_valid))) {
free(m);
if (ok)
*ok = 0;
return NULL;
}
int64_t atime_sec;
if (!receive_n_data(file_descriptor, &atime_sec, sizeof(atime_sec))) {
free(m);
if (ok)
*ok = 0;
return NULL;
}
int64_t atime_nsec;
if (!receive_n_data(file_descriptor, &atime_nsec, sizeof(atime_nsec))) {
free(m);
if (ok)
*ok = 0;
return NULL;
}
int32_t crtime_valid;
if (!receive_n_data(file_descriptor, &crtime_valid, sizeof(crtime_valid))) {
free(m);
if (ok)
*ok = 0;
return NULL;
}
int64_t crtime_sec;
if (!receive_n_data(file_descriptor, &crtime_sec, sizeof(crtime_sec))) {
free(m);
if (ok)
*ok = 0;
return NULL;
}
int64_t crtime_nsec;
if (!receive_n_data(file_descriptor, &crtime_nsec, sizeof(crtime_nsec))) {
free(m);
if (ok)
*ok = 0;
return NULL;
}
m->atime_valid = atime_valid != 0;
m->atime_sec = (time_t)atime_sec;
m->atime_nsec = (long)atime_nsec;
m->crtime_valid = crtime_valid != 0;
m->crtime_sec = (time_t)crtime_sec;
m->crtime_nsec = (long)crtime_nsec;
if (mtime_nsec < 0 || mtime_nsec >= 1000000000LL || mode < 0 || uid < 0 || gid < 0 ||
atime_valid < 0 || atime_valid > 1 || crtime_valid < 0 || crtime_valid > 1 ||
(atime_valid && (atime_nsec < 0 || atime_nsec >= 1000000000LL)) ||
(crtime_valid && (crtime_nsec < 0 || crtime_nsec >= 1000000000LL))) {
free(m);
if (ok)
*ok = 0;
return NULL;
}
if (ok)
*ok = 1;
return m;
+7 -1
View File
@@ -29,7 +29,13 @@
/* Size of metadata fields on wire, excluding the int32_t `present` field that
* is always sent first. The total wire size for present metadata is
* sizeof(int32_t) + FILE_METADATA_WIRE_SIZE (68 bytes on most platforms). */
* sizeof(int32_t) + FILE_METADATA_WIRE_SIZE (68 bytes on most platforms).
*
* metadata_send()/metadata_receive() (protocol 2.20.0) frame the metadata as a
* single packed record: one int32 present flag (0 = absent) followed, when
* present, by exactly FILE_METADATA_WIRE_SIZE bytes of field data. This is the
* same present+fields byte layout metadata_to_buf()/metadata_from_buf() use, so
* the wire metadata is now one frame instead of one frame per field. */
#define FILE_METADATA_WIRE_SIZE (sizeof(int32_t) * 5 + sizeof(int64_t) * 6)
void metadata_to_buf(char** buf, const FileMetadata* m);
+3 -3
View File
@@ -94,14 +94,14 @@ def _seed_protocol_source(source):
class TestProtocol:
@pytest.mark.ci
def test_protocol_current_version_accepted(self, shared_server):
"""--protocol=2.19.0 (the current PROTOCOL_VERSION) is accepted and the
"""--protocol=2.20.0 (the current PROTOCOL_VERSION) is accepted and the
transfer completes normally."""
source = os.path.join(TEST_DATA_DIR, "proto_ok_src")
dest = os.path.join(TEST_DATA_DIR, "proto_ok_dst")
shutil.rmtree(dest, ignore_errors=True)
os.makedirs(dest)
_seed_protocol_source(source)
result, _ = run_client(source, dest, flags=["--protocol=2.19.0"],
result, _ = run_client(source, dest, flags=["--protocol=2.20.0"],
port=shared_server.port)
assert result.returncode == 0, \
f"--protocol current run failed: {(result.stderr or result.stdout)[:400]}"
@@ -118,7 +118,7 @@ class TestProtocol:
shutil.rmtree(dest, ignore_errors=True)
os.makedirs(dest)
_seed_protocol_source(source)
for bad in ("2.18.0", "2.17.0", "2.15.0", "2.16.0", "216", "31"):
for bad in ("2.19.0", "2.18.0", "2.17.0", "2.15.0", "2.16.0", "216", "31"):
result, _ = run_client(source, dest, flags=[f"--protocol={bad}"],
port=shared_server.port)
assert result.returncode != 0, f"--protocol={bad} should be rejected"
+4 -4
View File
@@ -259,7 +259,7 @@ static void test_parse_args_protocol_accept_current() {
Config* cfg = valid_client_config();
EXPECT_NOT_NULL(cfg);
char* argv_equals[] = {"fastsync", "--source-dir", "/src",
"--dest-dir", "/dst", "--protocol=2.19.0"};
"--dest-dir", "/dst", "--protocol=2.20.0"};
int positional_args[2];
int positional_count = 0;
EXPECT_EQ_INT(parse_args(cfg, 6, argv_equals, positional_args, &positional_count), 0);
@@ -269,7 +269,7 @@ static void test_parse_args_protocol_accept_current() {
cfg = valid_client_config();
EXPECT_NOT_NULL(cfg);
char* argv_space[] = {"fastsync", "--source-dir", "/src", "--dest-dir",
"/dst", "--protocol", "2.19.0"};
"/dst", "--protocol", "2.20.0"};
positional_count = 0;
EXPECT_EQ_INT(parse_args(cfg, 7, argv_space, positional_args, &positional_count), 0);
EXPECT_EQ_STR(cfg->version, PROTOCOL_VERSION);
@@ -279,8 +279,8 @@ static void test_parse_args_protocol_accept_current() {
/* Any --protocol value other than the current PROTOCOL_VERSION must end in
* failure (parse_args simply stores it; validate_config rejects it up front). */
static void test_parse_args_protocol_rejects_other_versions() {
static const char* const bad_versions[] = {"2.17", "2.16", "2.15.0", "2.16.0", "2.17.0",
"2.18.0", "216", "31", "abc", ""};
static const char* const bad_versions[] = {
"2.17", "2.16", "2.15.0", "2.16.0", "2.17.0", "2.18.0", "2.19.0", "216", "31", "abc", ""};
for (size_t i = 0; i < sizeof(bad_versions) / sizeof(bad_versions[0]); i++) {
Config* cfg = valid_client_config();
EXPECT_NOT_NULL(cfg);
+139 -31
View File
@@ -5,6 +5,8 @@
#include "test_utils.h"
#include <stdlib.h>
#include <string.h>
#include <sys/ioctl.h>
#include <sys/socket.h>
#include <sys/stat.h>
#include <unistd.h>
@@ -134,6 +136,115 @@ static void test_metadata_send_null() {
close(p[1]);
}
/* protocol 2.20.0: metadata is one packed frame. With metadata present the
* wire record is exactly sizeof(int32_t) + FILE_METADATA_WIRE_SIZE bytes (the
* present flag followed by the fixed field record); absent metadata is a lone
* int32 zero. */
static void test_metadata_wire_is_one_packed_frame() {
io_set_bwlimit(0);
int p[2];
EXPECT_EQ_INT(pipe(p), 0);
io_set_fds(p[0], p[1]);
FileMetadata original = {.mode = 0640,
.uid = 42,
.gid = 43,
.mtime_sec = 111,
.mtime_nsec = 222,
.atime_valid = true,
.atime_sec = 333,
.atime_nsec = 444,
.crtime_valid = false,
.crtime_sec = 0,
.crtime_nsec = 0};
EXPECT_TRUE(metadata_send(p[1], &original));
unsigned char wire[sizeof(int32_t) + FILE_METADATA_WIRE_SIZE];
EXPECT_EQ_INT((int)read(p[0], wire, sizeof(wire)), (int)sizeof(wire));
int32_t flag;
memcpy(&flag, wire, sizeof(flag));
EXPECT_EQ_INT(flag, 1);
int avail = -1;
EXPECT_EQ_INT(ioctl(p[0], FIONREAD, &avail), 0);
EXPECT_EQ_INT(avail, 0);
/* The present frame decodes in one shot with the shared codec. */
char* cursor = (char*)wire;
FileMetadata* decoded = metadata_from_buf(&cursor);
EXPECT_NOT_NULL(decoded);
EXPECT_EQ_INT((int)(cursor - (char*)wire), (int)sizeof(wire));
EXPECT_EQ_INT(decoded->mode, 0640);
EXPECT_EQ_INT(decoded->uid, 42);
EXPECT_EQ_INT(decoded->gid, 43);
EXPECT_EQ_INT(decoded->mtime_sec, 111);
EXPECT_EQ_INT(decoded->mtime_nsec, 222);
EXPECT_TRUE(decoded->atime_valid);
EXPECT_EQ_INT(decoded->atime_sec, 333);
EXPECT_EQ_INT(decoded->atime_nsec, 444);
EXPECT_FALSE(decoded->crtime_valid);
free(decoded);
/* Absent metadata is a lone int32 zero (4 bytes). */
EXPECT_TRUE(metadata_send(p[1], NULL));
EXPECT_EQ_INT((int)read(p[0], wire, sizeof(int32_t)), (int)sizeof(int32_t));
memcpy(&flag, wire, sizeof(flag));
EXPECT_EQ_INT(flag, 0);
avail = -1;
EXPECT_EQ_INT(ioctl(p[0], FIONREAD, &avail), 0);
EXPECT_EQ_INT(avail, 0);
close(p[0]);
close(p[1]);
}
/* Round-trip over a socketpair (not just a pipe): present metadata compares
* equal field-by-field and absent metadata yields NULL with ok == 1. */
static void test_metadata_send_receive_socketpair() {
io_set_bwlimit(0);
int sv[2];
EXPECT_EQ_INT(socketpair(AF_UNIX, SOCK_STREAM, 0, sv), 0);
io_set_fds(sv[0], sv[1]);
FileMetadata original = {.mode = 0600,
.uid = 7,
.gid = 8,
.mtime_sec = 1000,
.mtime_nsec = 1,
.atime_valid = true,
.atime_sec = 2000,
.atime_nsec = 2,
.crtime_valid = true,
.crtime_sec = 3000,
.crtime_nsec = 3};
EXPECT_TRUE(metadata_send(sv[1], &original));
int ok = 0;
FileMetadata* received = metadata_receive(sv[0], &ok);
EXPECT_NOT_NULL(received);
EXPECT_EQ_INT(ok, 1);
EXPECT_EQ_INT(received->mode, 0600);
EXPECT_EQ_INT(received->uid, 7);
EXPECT_EQ_INT(received->gid, 8);
EXPECT_EQ_INT(received->mtime_sec, 1000);
EXPECT_EQ_INT(received->mtime_nsec, 1);
EXPECT_TRUE(received->atime_valid);
EXPECT_EQ_INT(received->atime_sec, 2000);
EXPECT_EQ_INT(received->atime_nsec, 2);
EXPECT_TRUE(received->crtime_valid);
EXPECT_EQ_INT(received->crtime_sec, 3000);
EXPECT_EQ_INT(received->crtime_nsec, 3);
free(received);
EXPECT_TRUE(metadata_send(sv[1], NULL));
ok = 0;
received = metadata_receive(sv[0], &ok);
EXPECT_NULL(received);
EXPECT_EQ_INT(ok, 1);
close(sv[0]);
close(sv[1]);
}
static void test_metadata_rejects_invalid_values() {
int p[2];
EXPECT_EQ_INT(pipe(p), 0);
@@ -148,36 +259,30 @@ static void test_metadata_rejects_invalid_values() {
}
/* metadata_receive must reject an out-of-range atime/crtime nsec even when the
* flag would otherwise be valid (defense-in-depth on the -U/-N wire fields). */
* flag would otherwise be valid (defense-in-depth on the -U/-N wire fields).
* The packed record is built by the shared codec so the out-of-range value
* actually reaches the wire. */
static void test_metadata_receive_rejects_bad_optional_times() {
int p[2];
EXPECT_EQ_INT(pipe(p), 0);
io_set_fds(p[0], p[1]);
int32_t present = 1;
int32_t mode = 0644;
int32_t uid = 1000;
int32_t gid = 1000;
int64_t mtime_sec = 1;
int64_t mtime_nsec = 0;
int32_t atime_valid = 1;
int64_t atime_sec = 1;
int64_t atime_nsec = 2000000000; /* invalid: >= 1e9 */
EXPECT_TRUE(send_n_data(p[1], &present, sizeof(present)));
EXPECT_TRUE(send_n_data(p[1], &mode, sizeof(mode)));
EXPECT_TRUE(send_n_data(p[1], &uid, sizeof(uid)));
EXPECT_TRUE(send_n_data(p[1], &gid, sizeof(gid)));
EXPECT_TRUE(send_n_data(p[1], &mtime_sec, sizeof(mtime_sec)));
EXPECT_TRUE(send_n_data(p[1], &mtime_nsec, sizeof(mtime_nsec)));
EXPECT_TRUE(send_n_data(p[1], &atime_valid, sizeof(atime_valid)));
EXPECT_TRUE(send_n_data(p[1], &atime_sec, sizeof(atime_sec)));
EXPECT_TRUE(send_n_data(p[1], &atime_nsec, sizeof(atime_nsec)));
int32_t crtime_valid = 0;
int64_t crtime_sec = 0;
int64_t crtime_nsec = 0;
EXPECT_TRUE(send_n_data(p[1], &crtime_valid, sizeof(crtime_valid)));
EXPECT_TRUE(send_n_data(p[1], &crtime_sec, sizeof(crtime_sec)));
EXPECT_TRUE(send_n_data(p[1], &crtime_nsec, sizeof(crtime_nsec)));
FileMetadata bad = {.mode = 0644,
.uid = 1000,
.gid = 1000,
.mtime_sec = 1,
.mtime_nsec = 0,
.atime_valid = true,
.atime_sec = 1,
.atime_nsec = 2000000000, /* invalid: >= 1e9 */
.crtime_valid = false,
.crtime_sec = 0,
.crtime_nsec = 0};
char packed[sizeof(int32_t) + FILE_METADATA_WIRE_SIZE];
char* write_ptr = packed;
metadata_to_buf(&write_ptr, &bad);
EXPECT_TRUE(send_n_data(p[1], packed, sizeof(packed)));
int ok = 1;
EXPECT_NULL(metadata_receive(p[0], &ok));
EXPECT_EQ_INT(ok, 0);
@@ -235,12 +340,13 @@ static void test_file_restore_metadata() {
const char* content = "test content";
EXPECT_TRUE(file_write_to_disk(path, content, strlen(content), false, false));
FileMetadata m;
m.mode = 0644;
m.uid = getuid();
m.gid = getgid();
m.mtime_sec = 1234567890;
m.mtime_nsec = 0;
FileMetadata m = {.mode = 0644,
.uid = getuid(),
.gid = getgid(),
.mtime_sec = 1234567890,
.mtime_nsec = 0,
.atime_valid = false,
.crtime_valid = false};
file_restore_metadata(path, &m, false);
@@ -347,6 +453,8 @@ void test_metadata() {
test_metadata_from_buf_null();
test_metadata_send_receive_roundtrip();
test_metadata_send_null();
test_metadata_wire_is_one_packed_frame();
test_metadata_send_receive_socketpair();
test_metadata_rejects_invalid_values();
test_metadata_receive_rejects_bad_optional_times();
test_metadata_mtime_window();