mirror of
https://github.com/RsyncProject/rsync.git
synced 2026-09-17 07:38:57 -04:00
The hardened receiver confined the destination side of an xattr/ACL copy (the fsetxattr/acl_set_fd through a held O_NOFOLLOW fd) but still read the SOURCE side by path: copy_xattrs() did get_xattr_names/get_xattr_data on the source path, and make_backup() cached the backed-up file's ACL/xattr via get_acl()/get_xattr() by path. A local module writer could race the source/basis parent to a symlink after the confined content/stat open and before that path-based metadata read, so out-of-module xattrs/ACLs got copied onto an in-module destination or backup. Thread a source fd through the read side, mirroring the existing dest-fd plumbing: - get_xattr_data(), get_xattr() and get_xattr_acl() gain an fd arg (get_xattr_names already had one) and use sys_fgetxattr/sys_flistxattr when fd >= 0; this also covers the --fake-super ACL-as-xattr read in get_rsync_acl(). - copy_xattrs() gains a source_fd; copy_file() passes its held source fd (ifd) and keeps it open across the xattr copy (closing it on the fsync error path too); gen_entry_copy_xattrs() O_NOFOLLOW-opens the basis leaf under the confined resolver (with O_DIRECTORY for a directory basis) and passes it. - make_backup() pins the source leaf with a confined O_NOFOLLOW fd (backup_source_fd, like set_file_attrs's op_leaf_fd) and reads its ACL via get_acl_fdat() and its xattrs via get_xattr(fd); the in-place delta-backup in the generator pins fname the same way. On a hardened receiver a raced/absent leaf skips the cache rather than reading through a flippable path. Non-hardened receivers (fd < 0) keep the path-based behaviour unchanged. The basis COMPARE reads (the generator deciding a match) stay path-based: they never copy out-of-module metadata onto a file, so they are not part of this sink.
128 lines
3.0 KiB
C
128 lines
3.0 KiB
C
/*
|
|
* This file contains really simple implementations for rsync global
|
|
* functions, so that module test harnesses can run standalone.
|
|
*
|
|
* Copyright (C) 2001, 2002 Martin Pool <mbp@samba.org>
|
|
* Copyright (C) 2003-2022 Wayne Davison
|
|
*
|
|
* This program is free software; you can redistribute it and/or modify
|
|
* it under the terms of the GNU General Public License as published by
|
|
* the Free Software Foundation; either version 3 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* This program is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License along
|
|
* with this program; if not, visit the http://fsf.org website.
|
|
*/
|
|
|
|
#include "rsync.h"
|
|
|
|
int do_fsync = 0;
|
|
int inplace = 0;
|
|
int am_daemon = 0;
|
|
int am_chrooted = 0;
|
|
int insecure_links = 0;
|
|
int modify_window = 0;
|
|
int preallocate_files = 0;
|
|
int protect_args = 0;
|
|
int module_id = -1;
|
|
int relative_paths = 0;
|
|
unsigned int module_dirlen = 0;
|
|
int preserve_xattrs = 0;
|
|
int preserve_perms = 0;
|
|
int preserve_executability = 0;
|
|
int omit_link_times = 0;
|
|
int open_noatime = 0;
|
|
size_t max_alloc = (size_t)-1; /* unlimited: helpers link util2.o, where 0 makes
|
|
* every my_alloc()/my_strdup() abort with
|
|
* "exceeded --max-alloc=0" (hit on the
|
|
* secure_relative_open() fallback path). */
|
|
char *partial_dir;
|
|
char *module_dir;
|
|
int module_dirfd = -1;
|
|
/* curr_dir[]/curr_dir_len (read by secure_relative_open) are defined in
|
|
* syscall.c, which every helper links -- no stub needed here. */
|
|
filter_rule_list daemon_filter_list;
|
|
|
|
void rprintf(UNUSED(enum logcode code), const char *format, ...)
|
|
{
|
|
va_list ap;
|
|
va_start(ap, format);
|
|
vfprintf(stderr, format, ap);
|
|
va_end(ap);
|
|
}
|
|
|
|
void rsyserr(UNUSED(enum logcode code), int errcode, const char *format, ...)
|
|
{
|
|
va_list ap;
|
|
fputs(RSYNC_NAME ": ", stderr);
|
|
va_start(ap, format);
|
|
vfprintf(stderr, format, ap);
|
|
va_end(ap);
|
|
fprintf(stderr, ": %s (%d)\n", strerror(errcode), errcode);
|
|
}
|
|
|
|
void _exit_cleanup(int code, const char *file, int line)
|
|
{
|
|
fprintf(stderr, "exit(%d): %s(%d)\n",
|
|
code, file, line);
|
|
exit(code);
|
|
}
|
|
|
|
int check_filter(UNUSED(filter_rule_list *listp), UNUSED(enum logcode code),
|
|
UNUSED(const char *name), UNUSED(int name_is_dir))
|
|
{
|
|
/* This function doesn't really get called in this test context, so
|
|
* just return 0. */
|
|
return 0;
|
|
}
|
|
|
|
int copy_xattrs(UNUSED(const char *source), UNUSED(int source_fd), UNUSED(const char *dest), UNUSED(int dest_fd))
|
|
{
|
|
return -1;
|
|
}
|
|
|
|
void free_xattr(UNUSED(stat_x *sxp))
|
|
{
|
|
return;
|
|
}
|
|
|
|
void free_acl(UNUSED(stat_x *sxp))
|
|
{
|
|
return;
|
|
}
|
|
|
|
char *lp_name(UNUSED(int mod))
|
|
{
|
|
return NULL;
|
|
}
|
|
|
|
BOOL lp_insecure_links(UNUSED(int mod))
|
|
{
|
|
return 0;
|
|
}
|
|
|
|
BOOL lp_use_chroot(UNUSED(int mod))
|
|
{
|
|
return 0;
|
|
}
|
|
|
|
const char *who_am_i(void)
|
|
{
|
|
return "tester";
|
|
}
|
|
|
|
int csum_len_for_type(int cst, int flg)
|
|
{
|
|
return cst || !flg ? 16 : 1;
|
|
}
|
|
|
|
int canonical_checksum(int cst)
|
|
{
|
|
return cst ? 0 : 0;
|
|
}
|