mirror of
https://github.com/RsyncProject/rsync.git
synced 2026-08-03 01:06:58 -04:00
Adds .github/workflows/ubuntu-version-mix.yml (ubuntu-latest) and a per-release manifest testsuite/expect/rsync_<ver>.expect for each of the nine peers. The workflow builds the current rsync, then runs the two- sided suite against every old binary over both the pipe and --use-tcp daemon transports. All peers run in a SINGLE looped job (not a matrix) so the PR shows one check line; each peer/transport is a foldable log group and a failure annotates which one broke. A new phony `check-progs` target builds rsync plus the test helper programs and check symlinks without running the suite -- the build half of `make check` -- so the workflow's direct runtests.py invocation has the helpers it needs. Notable expected results encoded in the manifests: - The four May-2026 security tests xfail against every released peer: the suite demonstrates each release is vulnerable to those findings while current master is fixed. - symlink-dirlink-basis xfails on 3.4.0/3.4.1 (issue #715: their secure_relative_open O_NOFOLLOW-confines the basedir, breaking a -K dir-symlink update; current master fixes it with secure_basis_open). - Older peers carry more xfails for options/negotiation they lack; 2.6.0 (protocol 27) fails most daemon tests. reverse-daemon-delta passes against all peers, confirming backward compat down to 2004. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
41 lines
2.0 KiB
Plaintext
41 lines
2.0 KiB
Plaintext
# Expected outcomes for current rsync <-> rsync 3.4.0 peer (see
|
|
# rsync_3.1.3.expect for the format/semantics; listed tests are the run set).
|
|
|
|
00-hello pass
|
|
reverse-daemon-delta pass # old client -> current daemon (backward-compat: delta+compress, both directions)
|
|
alt-dest pass
|
|
bare-do-open-symlink-race pass
|
|
batch-mode pass
|
|
chmod-option pass
|
|
daemon pass
|
|
daemon-access pass
|
|
daemon-auth pass
|
|
daemon-config pass
|
|
daemon-exec pass
|
|
daemon-filter pass
|
|
daemon-gzip-download pass
|
|
daemon-gzip-upload pass
|
|
daemon-munge pass
|
|
daemon-refuse pass
|
|
daemon-refuse-compress pass
|
|
exclude pass
|
|
files-from pass
|
|
hardlinks pass
|
|
ssh-basic pass
|
|
|
|
# issue #715, present in 3.4.0: updating a file through a -K (--copy-dirlinks)
|
|
# directory symlink fails on the receiver because its secure_relative_open()
|
|
# O_NOFOLLOW-confines every path component, including the basedir reached via
|
|
# the symlink, so the basis open is rejected and the update is discarded
|
|
# ("failed verification"). Current master fixes this with secure_basis_open()
|
|
# (receiver.c), which splits the path so the basedir may follow symlinks while
|
|
# only the leaf is O_NOFOLLOW'd. Verified peer-version-, not protocol-, driven
|
|
# (forcing this peer to --protocol=31 still fails; 3.3.0 at proto 31 passes).
|
|
symlink-dirlink-basis xfail
|
|
|
|
# --- May-2026 security fixes absent in 3.4.0 (peer is vulnerable) ---
|
|
alt-dest-symlink-race xfail # --link-dest basis lookup follows basedir symlink (escape)
|
|
chdir-symlink-race xfail # chmod escape via cd symlink during chdir
|
|
copy-dest-source-symlink xfail # copy_file source reads /outside via cd symlink (poison)
|
|
sender-flist-symlink-leak xfail # sender flist follows cd symlink, leaks outside paths
|