diff --git a/net/rsync/Makefile b/net/rsync/Makefile index feaca9fb8113..83086fe1b538 100644 --- a/net/rsync/Makefile +++ b/net/rsync/Makefile @@ -1,100 +1,101 @@ PORTNAME= rsync DISTVERSION= 3.5.0 +PORTREVISION= 1 CATEGORIES= net MASTER_SITES= https://www.mirrorservice.org/sites/rsync.samba.org/src/ \ http://rsync.mirror.garr.it/src/ \ http://www.mirrorservice.org/sites/rsync.samba.org/src/ \ https://download.samba.org/pub/rsync/src/ MAINTAINER= rodrigo@FreeBSD.org COMMENT= Network file distribution/synchronization utility WWW= https://rsync.samba.org/ LICENSE= GPLv3+ LICENSE_FILE= ${WRKSRC}/COPYING LIB_DEPENDS= liblz4.so:archivers/liblz4 \ libxxhash.so:devel/xxhash \ libzstd.so:archivers/zstd TEST_DEPENDS= ${PYTHON_VERSION}:lang/python${PYTHON_SUFFIX} \ bash:shells/bash USES= autoreconf:build cpe python shebangfix ssl CPE_VENDOR= samba CPE_PRODUCT= rsync PYTHON_NO_DEPENDS= yes USE_RC_SUBR= rsyncd SHEBANG_FILES= runtests.py support/rrsync GNU_CONFIGURE= yes GNU_CONFIGURE_MANPREFIX= ${PREFIX}/share CONFIGURE_ARGS= --disable-debug \ --disable-md2man \ --enable-ipv6 \ --with-rsyncd-conf=${ETCDIR}/rsyncd.conf INSTALL_TARGET= install-strip TEST_TARGET= check CPPFLAGS+= -I${LOCALBASE}/include LDFLAGS+= -L${LOCALBASE}/lib SUB_LIST= NAME=rsyncd PORTDOCS= NEWS.md README.md csprotocol.txt tech_report.tex # define options OPTIONS_DEFINE= DOCS FLAGS ICONV POPT_PORT SSH ZLIB_BASE OPTIONS_DEFAULT= FLAGS ICONV SSH ZLIB_BASE # options provided upstream POPT_PORT_DESC= Use popt from devel/popt instead of bundled one SSH_DESC= Use SSH instead of RSH FLAGS_DESC= File system flags support patch, adds --file-flags FLAGS_EXTRA_PATCHES= ${FILESDIR}/extra-patch-file-flags.diff ZLIB_BASE_DESC= Use zlib from base instead of bundled one ICONV_USES= iconv:translit ICONV_CONFIGURE_ENABLE= iconv iconv-open POPT_PORT_LIB_DEPENDS= libpopt.so:devel/popt POPT_PORT_CONFIGURE_OFF= --with-included-popt SSH_CONFIGURE_ON= --with-rsh=ssh SSH_CONFIGURE_OFF= --with-rsh=rsh ZLIB_BASE_CONFIGURE_ON= --with-included-zlib=no .include .if empty(ICONV_LIB) || !${PORT_OPTIONS:MICONV} CONFIGURE_ARGS+= ac_cv_search_libiconv_open=no .endif post-patch: @${REINPLACE_CMD} -e 's:/etc/rsync/:${ETCDIR}/:g' \ -e 's:/etc/rsyncd:${ETCDIR}/rsyncd:g' \ -e 's:/etc/letsencrypt:${PREFIX}/etc/letsencrypt:g' \ ${WRKSRC}/rsync.1 ${WRKSRC}/rsyncd.conf.5 @${REINPLACE_CMD} -e 's|/usr/bin/rsync|${PREFIX}/bin/rsync|g' ${WRKSRC}/support/rrsync pre-configure: @(cd ${WRKSRC} && ${SETENVI} ${WRK_ENV} ${MAKE_CMD} -f prepare-source.mak) post-install: @${MKDIR} ${STAGEDIR}${ETCDIR} ${INSTALL_DATA} ${FILESDIR}/rsyncd.conf.sample ${STAGEDIR}${ETCDIR}/ ${INSTALL_SCRIPT} ${WRKSRC}/support/rrsync ${STAGEDIR}${PREFIX}/sbin post-install-DOCS-on: @${MKDIR} ${STAGEDIR}${DOCSDIR} ${INSTALL_DATA} ${PORTDOCS:S,^,${WRKSRC}/,} ${STAGEDIR}${DOCSDIR} ${INSTALL_DATA} ${WRKSRC}/support/rrsync.1.md ${STAGEDIR}${DOCSDIR} pre-test: ${FIND} ${WRKSRC}/testsuite/ -type f -name '*.py' -exec ${REINPLACE_CMD} -e 's/python3/${PYTHON_VERSION}/g' {} \; .include diff --git a/net/rsync/files/extra-patch-file-flags.diff b/net/rsync/files/extra-patch-file-flags.diff index d23cf839935f..e331b1ff3d1c 100644 --- a/net/rsync/files/extra-patch-file-flags.diff +++ b/net/rsync/files/extra-patch-file-flags.diff @@ -1,1978 +1,2034 @@ -Add support for preserving BSD file flags - -Original patch by Rolf Grossmann -Rsync 3.4.4 port by Dag-Erling Smørgrav -Rsync 3.5.0 port by Rodrigo Osorio , reviewed by Claude Code - --- backup.c.orig +++ backup.c @@ -246,7 +246,7 @@ return 0; } #endif - if (do_rename_at(from, to) == 0) { + if (do_rename_at(from, to, stp->st_mode, ST_FLAGS(*stp)) == 0) { if (stp->st_nlink > 1 && !S_ISDIR(stp->st_mode)) { /* If someone has hard-linked the file into the backup * dir, rename() might return success but do nothing! */ --- compat.c.orig +++ compat.c @@ -40,6 +40,7 @@ extern int basis_dir_cnt; extern int prune_empty_dirs; extern int protocol_version; +extern int force_change; extern int protect_args; extern int preserve_uid; extern int preserve_gid; @@ -47,6 +48,7 @@ extern int preserve_crtimes; extern int preserve_acls; extern int preserve_xattrs; +extern int preserve_file_flags; extern int xfer_flags_as_varint; extern int need_messages_from_generator; extern int delete_mode, delete_before, delete_during, delete_after; @@ -87,7 +89,7 @@ int xattr_sum_len = 0; /* These index values are for the file-list's extra-attribute array. */ -int pathname_ndx, depth_ndx, atimes_ndx, crtimes_ndx, uid_ndx, gid_ndx, acls_ndx, xattrs_ndx, unsort_ndx; +int pathname_ndx, depth_ndx, atimes_ndx, crtimes_ndx, uid_ndx, gid_ndx, file_flags_ndx, acls_ndx, xattrs_ndx, unsort_ndx; int receiver_symlink_times = 0; /* receiver can set the time on a symlink */ int sender_symlink_iconv = 0; /* sender should convert symlink content */ @@ -645,6 +647,8 @@ uid_ndx = ++file_extra_cnt; if (preserve_gid) gid_ndx = ++file_extra_cnt; + if (preserve_file_flags || (force_change && !am_sender)) + file_flags_ndx = ++file_extra_cnt; if (preserve_acls && !am_sender) acls_ndx = ++file_extra_cnt; if (preserve_xattrs) @@ -763,6 +767,10 @@ fprintf(stderr, "Both rsync versions must be at least 3.2.0 for --crtimes.\n"); exit_cleanup(RERR_PROTOCOL); } + if (!xfer_flags_as_varint && preserve_file_flags) { + fprintf(stderr, "Both rsync versions must be at least 3.2.0 for --file-flags.\n"); + exit_cleanup(RERR_PROTOCOL); + } if (am_sender) { receiver_symlink_times = am_server ? strchr(client_info, 'L') != NULL --- delete.c.orig +++ delete.c @@ -25,6 +25,7 @@ extern int am_root; extern int make_backups; extern int max_delete; +extern int force_change; extern char *backup_dir; extern char *backup_suffix; extern int backup_suffix_len; @@ -62,10 +63,19 @@ { const char *leaf; int dfd = del_held_dfd(fbuf, &leaf); - if (dfd >= 0) - do_chmod_atfd(dfd, leaf, mode); - else - do_chmod_at(fbuf, mode); + if (dfd >= 0) { + if (do_chmod_atfd(dfd, leaf, mode) == 0) + return; +#ifdef SUPPORT_FORCE_CHANGE + /* The fd-relative wrapper cannot chflags(); let the full-path + * wrapper's force-change logic have a go at an immutable target. */ + if (!(force_change && errno == EPERM)) + return; +#else + return; +#endif + } + do_chmod_at(fbuf, mode, NO_FFLAGS); } static int del_unlink(const char *fbuf) @@ -224,6 +234,12 @@ int dfd = del_held_dfd(fbuf, &leaf); what = "rmdir"; ok = (dfd >= 0 ? do_unlink_atfd(dfd, leaf, AT_REMOVEDIR) : do_rmdir_at(fbuf)) == 0; +#ifdef SUPPORT_FORCE_CHANGE + /* The fd-relative wrapper cannot chflags(); retry an immutable + * directory through the full-path wrapper. */ + if (!ok && dfd >= 0 && force_change && errno == EPERM) + ok = do_rmdir_at(fbuf) == 0; +#endif } else { if (make_backups > 0 && !(flags & DEL_FOR_BACKUP) && (backup_dir || !is_backup_file(fbuf))) { what = "make_backup"; --- testsuite/file-flags_test.py.orig +++ testsuite/file-flags_test.py -@@ -0,0 +1,274 @@ +@@ -0,0 +1,302 @@ +#!/usr/bin/env python3 +# Test the FreeBSD "File system flags" patch: --file-flags and the +# --force-change / --force-uchange / --force-schange family. +# +# --file-flags copies a file's BSD st_flags (chflags(2)) to the receiver. +# --force-change lets the receiver update or delete a file/dir whose +# immutable flag would otherwise make the operation fail with EPERM. +# +# Both need a chflags(2) platform AND a filesystem that actually stores the +# flag, so everything here is gated behind a set-then-clear probe: ZFS, for +# instance, keeps the system flags (schg/sappnd) but rejects the user ones +# (uchg/uappnd), and a non-root run or securelevel >= 1 can set neither. + +import atexit +import os +import stat + +from rsyncfns import ( + FROMDIR, SCRATCHDIR, TODIR, + makepath, run_rsync, test_fail, test_skipped, +) + + +if not hasattr(os, 'chflags'): + test_skipped("no chflags(2) on this platform") + +vv = run_rsync('-VV', check=True, capture_output=True).stdout +if '"file_flags": true' not in vv: + test_skipped("rsync is configured without file-flags support") + + +# --- flag probing ---------------------------------------------------------- + +def clear_flags_tree(top) -> None: + """Drop every st_flag under `top` so the tree can be rewritten/removed. + + Registered with atexit as well as called between sub-tests: an immutable + file left behind would defeat not just this test's cleanup but the + runner's removal of the whole scratch directory. + """ + for root, dirs, files in os.walk(top, topdown=False): + for name in files + dirs: + try: + os.chflags(os.path.join(root, name), 0) + except OSError: + pass + try: + os.chflags(top, 0) + except OSError: + pass + + +atexit.register(clear_flags_tree, SCRATCHDIR) + +makepath(FROMDIR, TODIR) + + +def probe_flag(): + """Return (flag_bit, name) for an immutable flag this filesystem stores, + or (None, None). Must survive a set *and* a clear: securelevel >= 1 + makes the system flags one-way, which would strand the scratch tree.""" + probe = SCRATCHDIR / '.flagprobe' + probe.write_text('x\n') + try: -+ for bit, name in ((stat.UF_IMMUTABLE, 'uchg'), -+ (stat.SF_IMMUTABLE, 'schg')): ++ for bit, name in (stat.SF_IMMUTABLE, 'schg'),(stat.UF_IMMUTABLE, 'uchg'): + try: + os.chflags(probe, bit) + except (OSError, AttributeError): + continue + if not os.lstat(probe).st_flags & bit: + continue + try: + os.chflags(probe, 0) + except OSError: + continue # cannot be cleared -- unusable for testing + return bit, name + return None, None + finally: + try: + os.chflags(probe, 0) + except OSError: + pass + probe.unlink(missing_ok=True) + + +IMMUTABLE, FLAGNAME = probe_flag() +if IMMUTABLE is None: + test_skipped("this filesystem does not store a settable/clearable " + "immutable flag (tried uchg and schg)") + +print(f"using the {FLAGNAME} flag") + + +def flags_of(path) -> int: + return os.lstat(path).st_flags + + +def reset() -> None: + """Empty from/ and to/ for the next sub-test.""" + for d in (FROMDIR, TODIR): + clear_flags_tree(d) + for root, dirs, files in os.walk(d, topdown=False): + for name in files: + os.unlink(os.path.join(root, name)) + for name in dirs: + os.rmdir(os.path.join(root, name)) + makepath(FROMDIR / 'sub', TODIR) + + +# --- 1: --file-flags propagates the flag to the receiver ------------------- + +reset() +(FROMDIR / 'sub' / 'f').write_text("hello\n") +os.chflags(FROMDIR / 'sub' / 'f', IMMUTABLE) + +run_rsync('-a', '--file-flags', f'{FROMDIR}/', f'{TODIR}/') +if not flags_of(TODIR / 'sub' / 'f') & IMMUTABLE: + test_fail(f"--file-flags did not copy the {FLAGNAME} flag to the receiver") +print("ok: --file-flags propagates the flag") + + +# --- 2: without --file-flags the receiver keeps no flag -------------------- + +reset() +(FROMDIR / 'sub' / 'f').write_text("hello\n") +os.chflags(FROMDIR / 'sub' / 'f', IMMUTABLE) + +run_rsync('-a', f'{FROMDIR}/', f'{TODIR}/') +if flags_of(TODIR / 'sub' / 'f') & IMMUTABLE: + test_fail("plain -a propagated a file flag; --file-flags is opt-in") +print("ok: plain -a leaves receiver flags alone") + + +# --- 3: an immutable destination blocks an update without --force-change --- + +reset() +(FROMDIR / 'sub' / 'f').write_text("new-content\n") +makepath(TODIR / 'sub') +(TODIR / 'sub' / 'f').write_text("old\n") +os.chflags(TODIR / 'sub' / 'f', IMMUTABLE) + +proc = run_rsync('-a', f'{FROMDIR}/', f'{TODIR}/', check=False, + capture_output=True) +kept = (TODIR / 'sub' / 'f').read_text() +clear_flags_tree(TODIR) +if kept != "old\n": + test_fail("an immutable destination file was updated without " + f"--force-change (content is now {kept!r})") +if proc.returncode == 0: + test_fail("rsync reported success while failing to update an " + "immutable destination file") +print(f"ok: immutable destination blocks the update (exit {proc.returncode})") + + +# --- 4: --force-change pushes the update through --------------------------- + +reset() +(FROMDIR / 'sub' / 'f').write_text("new-content\n") +makepath(TODIR / 'sub') +(TODIR / 'sub' / 'f').write_text("old\n") +os.chflags(TODIR / 'sub' / 'f', IMMUTABLE) + +proc = run_rsync('-a', '--force-change', f'{FROMDIR}/', f'{TODIR}/', + check=False, capture_output=True) +got = (TODIR / 'sub' / 'f').read_text() +clear_flags_tree(TODIR) +if got != "new-content\n": + test_fail("--force-change did not update the immutable destination file " + f"(content is {got!r}, rsync said: {proc.stderr.strip()})") +if proc.returncode != 0: + test_fail(f"--force-change exited {proc.returncode}: {proc.stderr.strip()}") +print("ok: --force-change updates an immutable destination file") + + +# --- 5: --delete needs --force-change to remove an immutable file ---------- + +reset() +(FROMDIR / 'sub' / 'f').write_text("keep\n") +makepath(TODIR / 'sub') +(TODIR / 'sub' / 'f').write_text("keep\n") +(TODIR / 'sub' / 'extra').write_text("gone\n") +os.chflags(TODIR / 'sub' / 'extra', IMMUTABLE) + +run_rsync('-a', '--delete', f'{FROMDIR}/', f'{TODIR}/', check=False) +survived = (TODIR / 'sub' / 'extra').exists() +if not survived: + clear_flags_tree(TODIR) + test_fail("--delete removed an immutable file without --force-change") +print("ok: --delete alone leaves an immutable file in place") + +# Same tree, now with --force-change: it must go. +proc = run_rsync('-a', '--delete', '--force-change', f'{FROMDIR}/', f'{TODIR}/', + check=False, capture_output=True) +still_there = (TODIR / 'sub' / 'extra').exists() +clear_flags_tree(TODIR) +if still_there: + test_fail("--force-change --delete did not remove the immutable file " + f"(rsync said: {proc.stderr.strip()})") +if proc.returncode != 0: + test_fail(f"--force-change --delete exited {proc.returncode}: " + f"{proc.stderr.strip()}") +print("ok: --force-change --delete removes an immutable file") + + +# --- 6: an immutable *directory* is a documented limitation ---------------- +# +# The patch clears the immutable flag on the object it is about to touch, but +# unlinking a file also needs write permission on its *parent*, and nothing +# makes an immutable parent directory mutable first. do_unlink() in syscall.c +# says so outright: +# +# /* TODO: handle immutable directories */ +# +# So --force-change does NOT descend into an immutable directory. This test +# pins that behaviour rather than wishing it away: if someone teaches the +# patch to handle immutable parents, this is the test that should fail and be +# rewritten into a positive assertion. + +reset() +(FROMDIR / 'sub' / 'f').write_text("keep\n") +makepath(TODIR / 'sub', TODIR / 'doomed') +(TODIR / 'sub' / 'f').write_text("keep\n") +(TODIR / 'doomed' / 'inner').write_text("x\n") +os.chflags(TODIR / 'doomed' / 'inner', IMMUTABLE) +os.chflags(TODIR / 'doomed', IMMUTABLE) + +proc = run_rsync('-a', '--delete', '--force-change', f'{FROMDIR}/', f'{TODIR}/', + check=False, capture_output=True) +still_there = (TODIR / 'doomed').exists() +clear_flags_tree(TODIR) +if not still_there: + test_fail("--force-change --delete removed a file under an immutable " + "directory -- immutable parents are now handled, so this " + "known-limitation test needs to become a positive assertion") +print("ok: immutable parent directory still blocks deletion " + "(known limitation, see do_unlink()'s TODO)") + + +# --- 7: the itemized output grows an 'f' column for a flag change ---------- + +reset() +(FROMDIR / 'sub' / 'f').write_text("hello\n") +run_rsync('-a', '--file-flags', f'{FROMDIR}/', f'{TODIR}/') + +# Change nothing but the source's flags. +os.chflags(FROMDIR / 'sub' / 'f', IMMUTABLE) +proc = run_rsync('-a', '--file-flags', '-i', f'{FROMDIR}/', f'{TODIR}/', + capture_output=True) +line = next((ln for ln in proc.stdout.splitlines() if ln.endswith('sub/f')), None) +clear_flags_tree(FROMDIR) +clear_flags_tree(TODIR) +if line is None: + test_fail("a flags-only change was not itemized at all:\n" + proc.stdout) +if 'f' not in line.split()[0]: + test_fail(f"itemized output has no 'f' flag column: {line!r}") +print(f"ok: itemize reports the flag change ({line})") + + +# --- 8: a second --file-flags pass is a no-op ------------------------------ + +reset() +(FROMDIR / 'sub' / 'f').write_text("hello\n") +os.chflags(FROMDIR / 'sub' / 'f', IMMUTABLE) +run_rsync('-a', '--file-flags', f'{FROMDIR}/', f'{TODIR}/') +proc = run_rsync('-a', '--file-flags', '-i', f'{FROMDIR}/', f'{TODIR}/', + capture_output=True) +changed = [ln for ln in proc.stdout.splitlines() if ln.strip()] +clear_flags_tree(FROMDIR) +clear_flags_tree(TODIR) +if changed: + test_fail("a second --file-flags pass was not a no-op:\n" + + '\n'.join(changed)) +print("ok: a second --file-flags pass is a no-op") ++ ++ ++# --- 9: --force-change can descend into an immutable directory ------------------------------ ++ ++reset() ++(FROMDIR / 'sub' / 'f').write_text("old\n") ++os.chflags(FROMDIR / 'sub' / 'f', IMMUTABLE) ++os.chflags(FROMDIR / 'sub', IMMUTABLE) ++run_rsync('-a', '--file-flags', '--force-schange', f'{FROMDIR}/', f'{TODIR}/') ++ ++copied = (TODIR / 'sub' / 'f').exists() ++if not copied: ++ test_fail("file not copied: \n") ++ ++os.chflags(FROMDIR / 'sub' / 'f', 0) ++(FROMDIR / 'sub' / 'f').write_text("new\n") ++os.chflags(FROMDIR / 'sub' / 'f', IMMUTABLE) ++ ++run_rsync('-a', '-c', '--file-flags', '--force-schange', f'{FROMDIR}/', f'{TODIR}/') ++ ++kept = (TODIR / 'sub' / 'f').read_text() ++if kept != "new\n": ++ test_fail("--force-change cannot descend into an immutable directory: \n" + kept) ++ ++clear_flags_tree(FROMDIR) ++clear_flags_tree(TODIR) ++ ++print("ok: --force-change descend into an immutable directory") ++ --- flist.c.orig +++ flist.c @@ -57,6 +57,7 @@ extern int preserve_hard_links; extern int preserve_devices; extern int preserve_specials; +extern int preserve_file_flags; extern int delete_during; extern int missing_args; extern int eol_nulls; @@ -483,6 +484,9 @@ static time_t crtime; #endif static mode_t mode; +#ifdef SUPPORT_FILE_FLAGS + static uint32 file_flags; +#endif #ifdef SUPPORT_HARD_LINKS static int64 dev; #endif @@ -526,6 +530,14 @@ xflags |= XMIT_SAME_MODE; else mode = file->mode; +#ifdef SUPPORT_FILE_FLAGS + if (preserve_file_flags) { + if (F_FFLAGS(file) == file_flags) + xflags |= XMIT_SAME_FLAGS; + else + file_flags = F_FFLAGS(file); + } +#endif if (preserve_devices && IS_DEVICE(mode)) { if (protocol_version < 28) { @@ -687,6 +699,10 @@ #endif if (!(xflags & XMIT_SAME_MODE)) write_int(f, to_wire_mode(mode)); +#ifdef SUPPORT_FILE_FLAGS + if (preserve_file_flags && !(xflags & XMIT_SAME_FLAGS)) + write_int(f, (int)file_flags); +#endif if (atimes_ndx && !S_ISDIR(mode) && !(xflags & XMIT_SAME_ATIME)) write_varlong(f, atime, 4); if (preserve_uid && !(xflags & XMIT_SAME_UID)) { @@ -781,6 +797,9 @@ static time_t crtime; #endif static mode_t mode; +#ifdef SUPPORT_FILE_FLAGS + static uint32 file_flags; +#endif #ifdef SUPPORT_HARD_LINKS static int64 dev; #endif @@ -899,6 +918,10 @@ if (crtimes_ndx) crtime = F_CRTIME(first); #endif +#ifdef SUPPORT_FILE_FLAGS + if (preserve_file_flags) + file_flags = F_FFLAGS(first); +#endif if (preserve_uid) uid = F_OWNER(first); if (preserve_gid) @@ -995,6 +1018,10 @@ if (chmod_modes && !S_ISLNK(mode) && mode) mode = tweak_mode(mode, chmod_modes); +#ifdef SUPPORT_FILE_FLAGS + if (preserve_file_flags && !(xflags & XMIT_SAME_FLAGS)) + file_flags = (uint32)read_int(f); +#endif if (preserve_uid && !(xflags & XMIT_SAME_UID)) { if (protocol_version < 30) @@ -1203,6 +1230,10 @@ } #endif file->mode = mode; +#ifdef SUPPORT_FILE_FLAGS + if (preserve_file_flags) + F_FFLAGS(file) = file_flags; +#endif if (preserve_uid) F_OWNER(file) = uid; if (preserve_gid) { @@ -1667,6 +1698,10 @@ } #endif file->mode = st.st_mode; +#if defined SUPPORT_FILE_FLAGS || defined SUPPORT_FORCE_CHANGE + if (file_flags_ndx) + F_FFLAGS(file) = st.st_flags; +#endif if (preserve_uid) F_OWNER(file) = st.st_uid; if (preserve_gid) --- generator.c.orig +++ generator.c @@ -46,6 +46,8 @@ extern int preserve_hard_links; extern int preserve_executability; extern int preserve_perms; +extern int preserve_file_flags; +extern int force_change; extern int preserve_mtimes; extern int omit_dir_times; extern int omit_link_times; @@ -499,6 +501,10 @@ return 0; if (perms_differ(file, sxp)) return 0; +#ifdef SUPPORT_FILE_FLAGS + if (preserve_file_flags && sxp->st.st_flags != F_FFLAGS(file)) + return 0; +#endif if (ownership_differs(file, sxp)) return 0; #ifdef SUPPORT_ACLS @@ -560,6 +566,11 @@ iflags |= ITEM_REPORT_OWNER; if (gid_ndx && !(file->flags & FLAG_SKIP_GROUP) && sxp->st.st_gid != (gid_t)F_GROUP(file)) iflags |= ITEM_REPORT_GROUP; +#ifdef SUPPORT_FILE_FLAGS + if (preserve_file_flags && !S_ISLNK(file->mode) + && sxp->st.st_flags != F_FFLAGS(file)) + iflags |= ITEM_REPORT_FFLAGS; +#endif #ifdef SUPPORT_ACLS if (preserve_acls && !S_ISLNK(file->mode)) { if (!ACL_READY(*sxp)) @@ -1414,9 +1425,16 @@ int dfd = held_dfd_for(fname, file); if (dfd >= 0) { const char *slash = strrchr(fname, '/'); - return do_chmod_atfd(dfd, slash ? slash + 1 : fname, mode); + int ret = do_chmod_atfd(dfd, slash ? slash + 1 : fname, mode); +#ifdef SUPPORT_FORCE_CHANGE + /* The fd-relative wrapper cannot chflags(); let the full-path + * wrapper's force-change logic have a go at an immutable target. */ + if (ret < 0 && force_change && errno == EPERM) + ret = do_chmod_at(fname, mode, NO_FFLAGS); +#endif + return ret; } - return do_chmod_at(fname, mode); + return do_chmod_at(fname, mode, NO_FFLAGS); } static void gen_entry_set_times(const char *fname, struct file_struct *file, STRUCT_STAT *stp) @@ -1424,7 +1442,14 @@ int dfd = held_dfd_for(fname, file); if (dfd >= 0) { const char *slash = strrchr(fname, '/'); - if (set_times_at(dfd, slash ? slash + 1 : fname, stp) != -2) + int ret = set_times_at(dfd, slash ? slash + 1 : fname, stp); +#ifdef SUPPORT_FORCE_CHANGE + /* set_times_at() has no force-change tier; fall through to the + * full-path set_times(), which does. */ + if (ret < 0 && force_change && errno == EPERM) + ret = -2; +#endif + if (ret != -2) return; /* handled (success or error) by the at-on-dfd tier */ } set_times(fname, stp); @@ -1493,7 +1518,12 @@ int dfd = held_dfd_for(path, file); if (dfd >= 0) { const char *slash = strrchr(path, '/'); - return do_unlink_atfd(dfd, slash ? slash + 1 : path, 0); + int ret = do_unlink_atfd(dfd, slash ? slash + 1 : path, 0); +#ifdef SUPPORT_FORCE_CHANGE + if (ret < 0 && force_change && errno == EPERM) + ret = do_unlink_at(path); +#endif + return ret; } return do_unlink_at(path); } @@ -1508,9 +1538,14 @@ if (odfd >= 0 && ndfd >= 0) { const char *os = strrchr(opath, '/'); const char *ns = strrchr(npath, '/'); - return do_rename_atfd(odfd, os ? os + 1 : opath, ndfd, ns ? ns + 1 : npath); + int ret = do_rename_atfd(odfd, os ? os + 1 : opath, ndfd, ns ? ns + 1 : npath); +#ifdef SUPPORT_FORCE_CHANGE + if (ret < 0 && force_change && errno == EPERM) + ret = do_rename_at(opath, npath, 0, NO_FFLAGS); +#endif + return ret; } - return do_rename_at(opath, npath); + return do_rename_at(opath, npath, 0, NO_FFLAGS); } #ifdef SUPPORT_XATTRS +@@ -1855,6 +1890,10 @@ + if (!preserve_perms) { /* See comment in non-dir code below. */ + file->mode = dest_mode(file->mode, sx.st.st_mode, dflt_perms, statret == 0); + } ++#ifdef SUPPORT_FORCE_CHANGE ++ if (force_change && !preserve_file_flags && statret == 0) ++ F_FFLAGS(file) = ST_FLAGS(sx.st); ++#endif + if (statret != 0 && basis_dir[0] != NULL) { + int j = try_dests_non(file, fname, ndx, fnamecmpbuf, &sx, itemizing, code); + if (j == -2) { +@@ -1900,6 +1939,11 @@ + * readable and writable permissions during the time we are + * putting files within them. This is then restored to the + * former permissions after the transfer is done. */ ++#ifdef SUPPORT_FORCE_CHANGE ++ if (force_change && F_FFLAGS(file) & force_change ++ && make_mutable(fname, file->mode, F_FFLAGS(file), force_change) > 0) ++ need_retouch_dir_perms = 1; ++#endif + #ifdef HAVE_CHMOD + if (!am_root && (file->mode & S_IRWXU) != S_IRWXU && dir_tweaking) { + mode_t mode = file->mode | S_IRWXU; +@@ -2607,6 +2651,10 @@ + gen_entry_set_times(fname, file, &st); + } + } ++#ifdef SUPPORT_FORCE_CHANGE ++ if (force_change && F_FFLAGS(file) & force_change) ++ undo_make_mutable(fname, F_FFLAGS(file)); ++#endif + if (counter >= loopchk_limit) { + if (allowed_lull) + maybe_send_keepalive(time(NULL), MSK_ALLOW_FLUSH); --- log.c.orig +++ log.c @@ -763,7 +763,8 @@ : iflags & ITEM_REPORT_ATIME ? 'u' : 'n'; c[9] = !(iflags & ITEM_REPORT_ACL) ? '.' : 'a'; c[10] = !(iflags & ITEM_REPORT_XATTR) ? '.' : 'x'; - c[11] = '\0'; + c[11] = !(iflags & ITEM_REPORT_FFLAGS) ? '.' : 'f'; + c[12] = '\0'; if (iflags & (ITEM_IS_NEW|ITEM_MISSING_DATA)) { char ch = iflags & ITEM_IS_NEW ? '+' : '?'; --- main.c.orig +++ main.c @@ -34,6 +34,9 @@ #ifdef HAVE_SYS_RESOURCE_H #include #endif +#ifdef SUPPORT_FORCE_CHANGE +#include +#endif extern int dry_run; extern int list_only; @@ -53,6 +56,7 @@ extern int got_xfer_error; extern volatile sig_atomic_t got_sigusr2; extern int old_style_args; +extern int force_change; extern int msgs2stderr; extern int module_id; extern int read_only; @@ -1010,6 +1014,22 @@ * points to an identical file won't be replaced by the referent. */ copy_links = copy_dirlinks = copy_unsafe_links = 0; +#ifdef SUPPORT_FORCE_CHANGE + if (force_change & SYS_IMMUTABLE) { + /* Determine whether we'll be able to unlock a system immutable item. */ + int mib[2]; + int securityLevel = 0; + size_t len = sizeof securityLevel; + + mib[0] = CTL_KERN; + mib[1] = KERN_SECURELVL; + if (sysctl(mib, 2, &securityLevel, &len, NULL, 0) == 0 && securityLevel > 0) { + rprintf(FERROR, "System security level is too high to force mutability on system immutable files and directories.\n"); + exit_cleanup(RERR_UNSUPPORTED); + } + } +#endif + #ifdef SUPPORT_HARD_LINKS if (preserve_hard_links && !inc_recurse) match_hard_links(first_flist); --- options.c.orig +++ options.c @@ -57,6 +57,7 @@ int preserve_acls = 0; int preserve_xattrs = 0; int preserve_perms = 0; +int preserve_file_flags = 0; int preserve_executability = 0; int preserve_devices = 0; int preserve_specials = 0; @@ -104,6 +105,7 @@ int saw_stderr_opt = 0; int allow_8bit_chars = 0; int force_delete = 0; +int force_change = 0; int io_timeout = 0; int prune_empty_dirs = 0; int use_qsort = 0; @@ -642,6 +644,10 @@ {"perms", 'p', POPT_ARG_VAL, &preserve_perms, 1, 0, 0 }, {"no-perms", 0, POPT_ARG_VAL, &preserve_perms, 0, 0, 0 }, {"no-p", 0, POPT_ARG_VAL, &preserve_perms, 0, 0, 0 }, + {"file-flags", 0, POPT_ARG_VAL, &preserve_file_flags, 1, 0, 0 }, + {"fileflags", 0, POPT_ARG_VAL, &preserve_file_flags, 1, 0, 0 }, + {"no-file-flags", 0, POPT_ARG_VAL, &preserve_file_flags, 0, 0, 0 }, + {"no-fileflags", 0, POPT_ARG_VAL, &preserve_file_flags, 0, 0, 0 }, {"executability", 'E', POPT_ARG_NONE, &preserve_executability, 0, 0, 0 }, {"acls", 'A', POPT_ARG_NONE, 0, 'A', 0, 0 }, {"no-acls", 0, POPT_ARG_VAL, &preserve_acls, 0, 0, 0 }, @@ -745,6 +751,12 @@ {"remove-source-files",0,POPT_ARG_VAL, &remove_source_files, 1, 0, 0 }, {"force", 0, POPT_ARG_VAL, &force_delete, 1, 0, 0 }, {"no-force", 0, POPT_ARG_VAL, &force_delete, 0, 0, 0 }, + {"force-delete", 0, POPT_ARG_VAL, &force_delete, 1, 0, 0 }, + {"no-force-delete", 0, POPT_ARG_VAL, &force_delete, 0, 0, 0 }, + {"force-change", 0, POPT_ARG_VAL, &force_change, ALL_IMMUTABLE, 0, 0 }, + {"no-force-change", 0, POPT_ARG_VAL, &force_change, 0, 0, 0 }, + {"force-uchange", 0, POPT_ARG_VAL, &force_change, USR_IMMUTABLE, 0, 0 }, + {"force-schange", 0, POPT_ARG_VAL, &force_change, SYS_IMMUTABLE, 0, 0 }, {"ignore-errors", 0, POPT_ARG_VAL, &ignore_errors, 1, 0, 0 }, {"no-ignore-errors", 0, POPT_ARG_VAL, &ignore_errors, 0, 0, 0 }, {"max-delete", 0, POPT_ARG_INT, &max_delete, 0, 0, 0 }, @@ -1105,6 +1117,15 @@ #ifndef SUPPORT_CRTIMES parse_one_refuse_match(0, "crtimes", list_end); #endif +#ifndef SUPPORT_FILE_FLAGS + parse_one_refuse_match(0, "file-flags", list_end); + parse_one_refuse_match(0, "fileflags", list_end); +#endif +#ifndef SUPPORT_FORCE_CHANGE + parse_one_refuse_match(0, "force-change", list_end); + parse_one_refuse_match(0, "force-uchange", list_end); + parse_one_refuse_match(0, "force-schange", list_end); +#endif /* Now we use the descrip values to actually mark the options for refusal. */ for (op = long_options; op != list_end; op++) { @@ -2918,6 +2939,9 @@ if (xfer_dirs && !recurse && delete_mode && am_sender) args[ac++] = "--no-r"; + if (preserve_file_flags) + args[ac++] = "--fileflags"; + if (do_compression && do_compression_level != CLVL_NOT_SPECIFIED) { if (asprintf(&arg, "--compress-level=%d", do_compression_level) < 0) goto oom; @@ -3013,6 +3037,16 @@ args[ac++] = "--delete-excluded"; if (force_delete) args[ac++] = "--force"; +#ifdef SUPPORT_FORCE_CHANGE + if (force_change) { + if (force_change == ALL_IMMUTABLE) + args[ac++] = "--force-change"; + else if (force_change == USR_IMMUTABLE) + args[ac++] = "--force-uchange"; + else if (force_change == SYS_IMMUTABLE) + args[ac++] = "--force-schange"; + } +#endif if (write_batch < 0) args[ac++] = "--only-write-batch=X"; if (am_root > 1) --- receiver.c.orig +++ receiver.c @@ -264,11 +264,11 @@ return -1; } prior_mode = cst.st_mode & CHMOD_BITS; - if (do_chmod_at(fname, prior_mode | S_IWUSR) < 0) + if (do_chmod_at(fname, prior_mode | S_IWUSR, NO_FFLAGS) < 0) return -1; fd = do_open(fname, O_WRONLY, 0600); open_errno = errno; - if (do_chmod_at(fname, prior_mode) < 0) { + if (do_chmod_at(fname, prior_mode, NO_FFLAGS) < 0) { restore_errno = errno; if (fd >= 0) close(fd); @@ -704,7 +704,7 @@ * an excluded subtree. */ int rret; operator_path_resolve = 1; - rret = do_rename_at(partialptr, fname); + rret = do_rename_at(partialptr, fname, 0, NO_FFLAGS); operator_path_resolve = 0; if (rret < 0) { rsyserr(FERROR_XFER, errno, --- rsync.1.md.orig 2026-08-02 21:10:00.000000000 +0000 +++ rsync.1.md 2026-08-21 20:48:04.173090000 +0000 @@ -558,6 +558,7 @@ --chmod=CHMOD affect file and/or directory permissions --acls, -A preserve ACLs (implies --perms) --xattrs, -X preserve extended attributes +--file-flags preserve file flags (aka chflags) --owner, -o preserve owner (super-user only) --group, -g preserve group --devices preserve device files (super-user only) @@ -598,7 +599,10 @@ --ignore-missing-args ignore missing source arguments without error --delete-missing-args delete missing source arguments from destination --ignore-errors delete even if there are I/O errors ---force force deletion of directories even if not empty +--force, --force-delete force deletion of directories even if not empty +--force-change affect user-/system-immutable files/dirs +--force-uchange affect user-immutable files/dirs +--force-schange affect system-immutable files/dirs --max-delete=NUM don't delete more than NUM files --max-size=SIZE don't transfer any file larger than SIZE --min-size=SIZE don't transfer any file smaller than SIZE @@ -945,6 +949,7 @@ recursion and want to preserve almost everything. Be aware that it does **not** include preserving ACLs (`-A`), xattrs (`-X`), atimes (`-U`), crtimes (`-N`), nor the finding and preserving of hardlinks (`-H`). + It also does **not** imply [`--file-flags`](#opt). The only exception to the above equivalence is when [`--files-from`](#opt) is specified, in which case [`-r`](#opt) is not implied. @@ -2246,8 +2251,8 @@ [`--ignore-missing-args`](#opt) option a step farther: each missing argument will become a deletion request of the corresponding destination file on the receiving side (should it exist). If the destination file is a non-empty - directory, it will only be successfully deleted if [`--force`](#opt) or - [`--delete`](#opt) are in effect. Other than that, this option is + directory, it will only be successfully deleted if [`--force-delete`](#opt) + or [`--delete`](#opt) are in effect. Other than that, this option is independent of any other type of delete processing. The missing source files are represented by special file-list entries which @@ -2258,7 +2263,38 @@ Tells [`--delete`](#opt) to go ahead and delete files even when there are I/O errors. -0. `--force` +0. `--file-flags` + + This option causes rsync to update the file flags to be the same as the + source files and directories (if your OS supports the **chflags**(2) system + call). Some flags can only be altered by the super-user and some might + only be unset below a certain secure-level (usually single-user mode). It + will not make files alterable that are set to immutable on the receiver. + To do that, see [`--force-change`](#opt), [`--force-uchange`](#opt), and + [`--force-schange`](#opt). + +0. `--force-change` + + This option causes rsync to disable both user-immutable and + system-immutable flags on files and directories that are being updated or + deleted on the receiving side. This option overrides + [`--force-uchange`](#opt) and [`--force-schange`](#opt) + +0. `--force-uchange` + + This option causes rsync to disable user-immutable flags on files and + directories that are being updated or deleted on the receiving side. It + does not try to affect system flags. This option overrides + [`--force-change`](#opt) and [`--force-schange`](#opt). + +0. `--force-schange` + + This option causes rsync to disable system-immutable flags on files and + directories that are being updated or deleted on the receiving side. It + does not try to affect user flags. This option overrides + [`--force-change`](#opt) and [`--force-uchange`](#opt). + +0. `--force`, `--force-delete` This option tells rsync to delete a non-empty directory when it is to be replaced by a non-directory. This is only relevant if deletions are not @@ -3365,7 +3401,7 @@ but that also turns on the output of other verbose messages. The "%i" escape has a cryptic output that is 11 letters long. The general - format is like the string `YXcstpoguax`, where **Y** is replaced by the type + format is like the string `YXcstpoguaxf`, where **Y** is replaced by the type of update being done, **X** is replaced by the file-type, and the other letters represent attributes that may be output if they are being modified. --- rsync.1.orig 2026-08-13 00:05:31.000000000 +0000 +++ rsync.1 2026-08-21 21:22:19.276574000 +0000 @@ -1,5 +1,5 @@ -.TH "rsync" "1" "13 Aug 2026" "rsync 3.5.0" "User Commands" -.\" prefix=/usr +.TH "rsync" "1" "7 Aug 2026" "rsync 3.5.0" "User Commands" +.\" prefix=/usr/local .P .SH "NAME" .P @@ -661,6 +661,7 @@ --chmod=CHMOD affect file and/or directory permissions --acls, -A preserve ACLs (implies --perms) --xattrs, -X preserve extended attributes +--file-flags preserve file flags (aka chflags) --owner, -o preserve owner (super-user only) --group, -g preserve group --devices preserve device files (super-user only) @@ -701,7 +702,10 @@ --ignore-missing-args ignore missing source arguments without error --delete-missing-args delete missing source arguments from destination --ignore-errors delete even if there are I/O errors ---force force deletion of directories even if not empty +--force, --force-delete force deletion of directories even if not empty +--force-change affect user-/system-immutable files/dirs +--force-uchange affect user-immutable files/dirs +--force-schange affect system-immutable files/dirs --max-delete=NUM don't delete more than NUM files --max-size=SIZE don't transfer any file larger than SIZE --min-size=SIZE don't transfer any file smaller than SIZE @@ -1035,6 +1039,7 @@ recursion and want to preserve almost everything. Be aware that it does \fBnot\fP include preserving ACLs (\fB\-A\fP), xattrs (\fB\-X\fP), atimes (\fB\-U\fP), crtimes (\fB\-N\fP), nor the finding and preserving of hardlinks (\fB\-H\fP). +It also does \fBnot\fP imply \fB\-\-file\-flags\fP. .IP The only exception to the above equivalence is when \fB\-\-files\-from\fP is specified, in which case \fB\-r\fP is not implied. @@ -2309,8 +2314,8 @@ \fB\-\-ignore\-missing\-args\fP option a step farther: each missing argument will become a deletion request of the corresponding destination file on the receiving side (should it exist). If the destination file is a non-empty -directory, it will only be successfully deleted if \fB\-\-force\fP or -\fB\-\-delete\fP are in effect. Other than that, this option is +directory, it will only be successfully deleted if \fB\-\-force\-delete\fP +or \fB\-\-delete\fP are in effect. Other than that, this option is independent of any other type of delete processing. .IP The missing source files are represented by special file-list entries which @@ -2318,7 +2323,30 @@ .IP "\fB\-\-ignore\-errors\fP" Tells \fB\-\-delete\fP to go ahead and delete files even when there are I/O errors. -.IP "\fB\-\-force\fP" +.IP "\fB\-\-file\-flags\fP" +This option causes rsync to update the file flags to be the same as the +source files and directories (if your OS supports the \fBchflags\fP(2) system +call). Some flags can only be altered by the super-user and some might +only be unset below a certain secure-level (usually single-user mode). It +will not make files alterable that are set to immutable on the receiver. +To do that, see \fB\-\-force\-change\fP, \fB\-\-force\-uchange\fP, and +\fB\-\-force\-schange\fP. +.IP "\fB\-\-force\-change\fP" +This option causes rsync to disable both user-immutable and +system-immutable flags on files and directories that are being updated or +deleted on the receiving side. This option overrides +\fB\-\-force\-uchange\fP and \fB\-\-force\-schange\fP +.IP "\fB\-\-force\-uchange\fP" +This option causes rsync to disable user-immutable flags on files and +directories that are being updated or deleted on the receiving side. It +does not try to affect system flags. This option overrides +\fB\-\-force\-change\fP and \fB\-\-force\-schange\fP. +.IP "\fB\-\-force\-schange\fP" +This option causes rsync to disable system-immutable flags on files and +directories that are being updated or deleted on the receiving side. It +does not try to affect user flags. This option overrides +\fB\-\-force\-change\fP and \fB\-\-force\-uchange\fP. +.IP "\fB\-\-force\fP, \fB\-\-force\-delete\fP" This option tells rsync to delete a non-empty directory when it is to be replaced by a non-directory. This is only relevant if deletions are not active (see \fB\-\-delete\fP for details). @@ -3425,7 +3453,7 @@ but that also turns on the output of other verbose messages. .IP The "%i" escape has a cryptic output that is 11 letters long. The general -format is like the string \fBYXcstpoguax\fP, where \fBY\fP is replaced by the type +format is like the string \fBYXcstpoguaxf\fP, where \fBY\fP is replaced by the type of update being done, \fBX\fP is replaced by the file-type, and the other letters represent attributes that may be output if they are being modified. .IP --- rsync.c.orig +++ rsync.c @@ -31,6 +31,8 @@ extern int preserve_acls; extern int preserve_xattrs; extern int preserve_perms; +extern int preserve_file_flags; +extern int force_change; extern int preserve_executability; extern int preserve_mtimes; extern int omit_dir_times; @@ -486,6 +488,39 @@ return new_mode; } +#if defined SUPPORT_FILE_FLAGS || defined SUPPORT_FORCE_CHANGE +/* Set a file's st_flags. */ +static int set_file_flags(const char *fname, uint32 file_flags) +{ + if (do_chflags(fname, file_flags) != 0) { + rsyserr(FERROR_XFER, errno, + "failed to set file flags on %s", + full_fname(fname)); + return 0; + } + + return 1; +} + +/* Remove immutable flags from an object, so it can be altered/removed. */ +int make_mutable(const char *fname, mode_t mode, uint32 file_flags, uint32 iflags) +{ + if (S_ISLNK(mode) || !(file_flags & iflags)) + return 0; + if (!set_file_flags(fname, file_flags & ~iflags)) + return -1; + return 1; +} + +/* Undo a prior make_mutable() call that returned a 1. */ +int undo_make_mutable(const char *fname, uint32 file_flags) +{ + if (!set_file_flags(fname, file_flags)) + return -1; + return 1; +} +#endif + static int same_mtime(struct file_struct *file, STRUCT_STAT *st, int extra_accuracy) { #ifdef ST_MTIME_NSEC @@ -676,10 +711,19 @@ if (am_root >= 0) { uid_t uid = change_uid ? (uid_t)F_OWNER(file) : sxp->st.st_uid; gid_t gid = change_gid ? (gid_t)F_GROUP(file) : sxp->st.st_gid; - if ((op_leaf_fd >= 0 ? do_fchown(op_leaf_fd, uid, gid) - : op_refuse ? (errno = ELOOP, -1) - : dfd >= 0 ? do_lchown_atfd(dfd, leaf, uid, gid) - : do_lchown_at(fname, uid, gid)) != 0) { + int own_ret = op_leaf_fd >= 0 ? do_fchown(op_leaf_fd, uid, gid) + : op_refuse ? (errno = ELOOP, -1) + : dfd >= 0 ? do_lchown_atfd(dfd, leaf, uid, gid) + : do_lchown_at(fname, uid, gid, sxp->st.st_mode, ST_FLAGS(sxp->st)); +#ifdef SUPPORT_FORCE_CHANGE + /* The fd-relative wrappers have no path to chflags(), so an + * immutable target fails there with EPERM. Retry through the + * full-path wrapper, which carries the force-change logic. */ + if (own_ret != 0 && force_change && errno == EPERM + && !op_refuse && (op_leaf_fd >= 0 || dfd >= 0)) + own_ret = do_lchown_at(fname, uid, gid, sxp->st.st_mode, ST_FLAGS(sxp->st)); +#endif + if (own_ret != 0) { /* We shouldn't have attempted to change uid * or gid unless have the privilege. */ rsyserr(FERROR_XFER, errno, "%s %s failed", @@ -809,7 +853,14 @@ : op_leaf_fd >= 0 ? do_fchmod(op_leaf_fd, new_mode) : op_refuse ? (errno = ELOOP, -1) : dfd >= 0 && !S_ISLNK(new_mode) ? do_chmod_atfd(dfd, leaf, new_mode) - : do_chmod_at(fname, new_mode); + : do_chmod_at(fname, new_mode, ST_FLAGS(sxp->st)); +#ifdef SUPPORT_FORCE_CHANGE + /* See the chown comment above: retry an fd-relative EPERM through + * the full-path wrapper so --force-change can clear the flags. */ + if (ret < 0 && force_change && errno == EPERM && am_root >= 0 + && !op_refuse && (op_leaf_fd >= 0 || (dfd >= 0 && !S_ISLNK(new_mode)))) + ret = do_chmod_at(fname, new_mode, ST_FLAGS(sxp->st)); +#endif if (ret < 0) { rsyserr(FERROR_XFER, errno, "failed to set permissions on %s", @@ -821,6 +872,19 @@ } #endif +#ifdef SUPPORT_FILE_FLAGS + if (preserve_file_flags && !S_ISLNK(sxp->st.st_mode) + && sxp->st.st_flags != F_FFLAGS(file)) { + uint32 file_flags = F_FFLAGS(file); + if (flags & ATTRS_DELAY_IMMUTABLE) + file_flags &= ~ALL_IMMUTABLE; + if (sxp->st.st_flags != file_flags + && !set_file_flags(fname, file_flags)) + goto cleanup; + updated = 1; + } +#endif + if (INFO_GTE(NAME, 2) && flags & ATTRS_REPORT) { if (updated) rprintf(FCLIENT, "%s\n", fname); @@ -909,7 +973,8 @@ * (in-tree temps keep their held dirfd, so op_pin stays off there). */ operator_path_resolve = 1; set_file_attrs(fnametmp, file, NULL, fnamecmp, - ok_to_set_time ? ATTRS_ACCURATE_TIME : ATTRS_SKIP_MTIME | ATTRS_SKIP_ATIME | ATTRS_SKIP_CRTIME); + ATTRS_DELAY_IMMUTABLE + | (ok_to_set_time ? ATTRS_ACCURATE_TIME : ATTRS_SKIP_MTIME | ATTRS_SKIP_ATIME | ATTRS_SKIP_CRTIME)); operator_path_resolve = 0; /* move tmp file over real file */ @@ -927,6 +992,10 @@ } if (ret == 0) { /* The file was moved into place (not copied), so it's done. */ +#ifdef SUPPORT_FILE_FLAGS + if (preserve_file_flags && F_FFLAGS(file) & ALL_IMMUTABLE) + set_file_flags(fname, F_FFLAGS(file)); +#endif return 1; } /* The file was copied, so tweak the perms of the copied file. If it @@ -938,7 +1007,7 @@ ok_to_set_time ? ATTRS_ACCURATE_TIME : ATTRS_SKIP_MTIME | ATTRS_SKIP_ATIME | ATTRS_SKIP_CRTIME); if (temp_copy_name) { - if (do_rename_at(fnametmp, fname) < 0) { + if (do_rename_at(fnametmp, fname, file->mode, NO_FFLAGS) < 0) { rsyserr(FERROR_XFER, errno, "rename %s -> \"%s\"", full_fname(fnametmp), fname); return 0; --- rsync.h.orig +++ rsync.h @@ -69,7 +69,7 @@ /* The following XMIT flags require an rsync that uses a varint for the flag values */ -#define XMIT_RESERVED_16 (1<<16) /* reserved for future fileflags use */ +#define XMIT_SAME_FLAGS (1<<16) /* any protocol - restricted by command-line option */ #define XMIT_CRTIME_EQ_MTIME (1<<17) /* any protocol - restricted by command-line option */ /* These flags are used in the live flist data. */ @@ -223,6 +223,7 @@ #define ATTRS_SKIP_MTIME (1<<1) #define ATTRS_ACCURATE_TIME (1<<2) #define ATTRS_SKIP_ATIME (1<<3) +#define ATTRS_DELAY_IMMUTABLE (1<<4) #define ATTRS_SKIP_CRTIME (1<<5) #define MSG_FLUSH 2 @@ -251,6 +252,7 @@ #define ITEM_REPORT_GROUP (1<<6) #define ITEM_REPORT_ACL (1<<7) #define ITEM_REPORT_XATTR (1<<8) +#define ITEM_REPORT_FFLAGS (1<<9) #define ITEM_REPORT_CRTIME (1<<10) #define ITEM_BASIS_TYPE_FOLLOWS (1<<11) #define ITEM_XNAME_FOLLOWS (1<<12) @@ -628,6 +630,31 @@ #define SUPPORT_CRTIMES 1 #endif +#define NO_FFLAGS ((uint32)-1) + +#ifdef HAVE_CHFLAGS +#define SUPPORT_FILE_FLAGS 1 +#define SUPPORT_FORCE_CHANGE 1 +#endif + +#if defined SUPPORT_FILE_FLAGS || defined SUPPORT_FORCE_CHANGE +#ifndef UF_NOUNLINK +#define UF_NOUNLINK 0 +#endif +#ifndef SF_NOUNLINK +#define SF_NOUNLINK 0 +#endif +#define USR_IMMUTABLE (UF_IMMUTABLE|UF_NOUNLINK|UF_APPEND) +#define SYS_IMMUTABLE (SF_IMMUTABLE|SF_NOUNLINK|SF_APPEND) +#define ALL_IMMUTABLE (USR_IMMUTABLE|SYS_IMMUTABLE) +#define ST_FLAGS(st) ((st).st_flags) +#else +#define USR_IMMUTABLE 0 +#define SYS_IMMUTABLE 0 +#define ALL_IMMUTABLE 0 +#define ST_FLAGS(st) NO_FFLAGS +#endif + /* Find a variable that is either exactly 32-bits or longer. * If some code depends on 32-bit truncation, it will need to * take special action in a "#if SIZEOF_INT32 > 4" section. */ @@ -861,6 +888,7 @@ extern int depth_ndx; extern int uid_ndx; extern int gid_ndx; +extern int file_flags_ndx; extern int acls_ndx; extern int xattrs_ndx; extern int file_sum_extra_cnt; @@ -916,6 +944,11 @@ /* When the associated option is on, all entries will have these present: */ #define F_OWNER(f) REQ_EXTRA(f, uid_ndx)->unum #define F_GROUP(f) REQ_EXTRA(f, gid_ndx)->unum +#if defined SUPPORT_FILE_FLAGS || defined SUPPORT_FORCE_CHANGE +#define F_FFLAGS(f) REQ_EXTRA(f, file_flags_ndx)->unum +#else +#define F_FFLAGS(f) NO_FFLAGS +#endif #define F_ACL(f) REQ_EXTRA(f, acls_ndx)->num #define F_XATTR(f) REQ_EXTRA(f, xattrs_ndx)->num #define F_NDX(f) REQ_EXTRA(f, unsort_ndx)->num --- testsuite/rsyncfns.py.orig +++ testsuite/rsyncfns.py @@ -176,9 +176,9 @@ # all_plus -> +++++++++ every attribute changed (an additive create) # allspace -> every attribute unchanged # dots -> ..... trailing dots after the change columns -all_plus = '+++++++++' -allspace = ' ' -dots = '.....' +all_plus = '++++++++++' +allspace = ' ' +dots = '......' # The "$tmpdir/from", "$tmpdir/to", "$tmpdir/chk" layout from rsync.fns. TMPDIR = SCRATCHDIR --- sender.c.orig +++ sender.c @@ -25,6 +25,7 @@ extern int do_xfers; extern int open_noatime; extern int am_server; +extern int force_change; extern int am_daemon; extern int local_server; extern int inc_recurse; @@ -400,7 +401,7 @@ struct file_struct *file; struct file_list *flist; STRUCT_STAT st; - int dfd = -1, secure_errno = 0; + int dfd = -1, secure_errno = 0, rm_ret; if (!remove_source_files) return; @@ -450,7 +451,14 @@ return; } - if (dfd >= 0 ? secure_remove_source_file(dfd, bname) < 0 : do_unlink(fname) < 0) { + rm_ret = dfd >= 0 ? secure_remove_source_file(dfd, bname) : do_unlink(fname); +#ifdef SUPPORT_FORCE_CHANGE + /* The fd-relative wrapper cannot chflags(); retry an immutable source + * through do_unlink(), which carries the force-change logic. */ + if (rm_ret < 0 && dfd >= 0 && force_change && errno == EPERM) + rm_ret = do_unlink(fname); +#endif + if (rm_ret < 0) { failed_op = "remove"; failed: if (errno == ENOENT) --- syscall.c.orig +++ syscall.c @@ -54,6 +54,7 @@ extern int am_sender; extern int read_only; extern int list_only; +extern int force_change; extern int inplace; extern int preallocate_files; extern int sparse_files; @@ -641,7 +642,23 @@ { if (dry_run) return 0; RETURN_ERROR_IF_RO_OR_LO; - return unlink(path); + if (unlink(path) == 0) + return 0; +#ifdef SUPPORT_FORCE_CHANGE + if (force_change && errno == EPERM) { + STRUCT_STAT st; + + if (do_lstat(path, &st) == 0 + && make_mutable(path, st.st_mode, st.st_flags, force_change) > 0) { + if (unlink(path) == 0) + return 0; + undo_make_mutable(path, st.st_flags); + } + /* TODO: handle immutable directories */ + errno = EPERM; + } +#endif + return -1; } /* @@ -678,6 +695,18 @@ return -1; ret = unlinkat(dfd, bname, 0); e = errno; +# ifdef SUPPORT_FORCE_CHANGE + if (force_change && e == EPERM) { + STRUCT_STAT st; + if (do_lstat(path, &st) == 0 + && make_mutable(path, st.st_mode, st.st_flags, force_change) > 0) { + ret = unlinkat(dfd, bname, 0); + e = errno; + if (ret != 0) + undo_make_mutable(path, st.st_flags); + } + } +# endif close(dfd); errno = e; return ret; @@ -709,6 +738,18 @@ ret = unlinkat(dfd, bname, 0); e = errno; +#ifdef SUPPORT_FORCE_CHANGE + if (force_change && e == EPERM) { + STRUCT_STAT st; + if (do_lstat(path, &st) == 0 + && make_mutable(path, st.st_mode, st.st_flags, force_change) > 0) { + ret = unlinkat(dfd, bname, 0); + e = errno; + if (ret != 0) + undo_make_mutable(path, st.st_flags); + } + } +#endif close(dfd); errno = e; return ret; @@ -1078,7 +1119,7 @@ } #endif -int do_lchown(const char *path, uid_t owner, gid_t group) +int do_lchown(const char *path, uid_t owner, gid_t group, UNUSED(mode_t mode), UNUSED(uint32 file_flags)) { if (dry_run) return 0; RETURN_ERROR_IF_RO_OR_LO; @@ -1086,7 +1127,28 @@ #ifndef HAVE_LCHOWN #define lchown chown #endif - return lchown(path, owner, group); + if (lchown(path, owner, group) == 0) + return 0; +#ifdef SUPPORT_FORCE_CHANGE + if (force_change && errno == EPERM) { + if (file_flags == NO_FFLAGS) { + STRUCT_STAT st; + if (do_lstat(path, &st) == 0) { + mode = st.st_mode; + file_flags = st.st_flags; + } + } + if (file_flags != NO_FFLAGS + && make_mutable(path, mode, file_flags, force_change) > 0) { + int ret = lchown(path, owner, group); + undo_make_mutable(path, file_flags); + if (ret == 0) + return 0; + } + errno = EPERM; + } +#endif + return -1; } /* @@ -1103,7 +1165,7 @@ Falls through to do_lchown() in the dry-run / non-daemon / chrooted / absolute-path / no-parent cases, identical to do_chmod_at(). */ -int do_lchown_at(const char *fname, uid_t owner, gid_t group) +int do_lchown_at(const char *fname, uid_t owner, gid_t group, UNUSED(mode_t mode), UNUSED(uint32 file_flags)) { #if defined AT_FDCWD && defined AT_SYMLINK_NOFOLLOW extern int am_daemon, am_chrooted; @@ -1123,12 +1185,29 @@ * fall straight through to the unconfined full-path do_lchown(). */ if (operator_path_resolve && fname && *fname) { if (symlink_optout_allowed()) - return do_lchown(fname, owner, group); + return do_lchown(fname, owner, group, mode, file_flags); dfd = owner_walk_parent(fname, &bname); if (dfd < 0) return -1; ret = fchownat(dfd, bname, owner, group, AT_SYMLINK_NOFOLLOW); e = errno; +# ifdef SUPPORT_FORCE_CHANGE + if (force_change && e == EPERM) { + if (file_flags == NO_FFLAGS) { + STRUCT_STAT st; + if (do_lstat(fname, &st) == 0) { + mode = st.st_mode; + file_flags = st.st_flags; + } + } + if (file_flags != NO_FFLAGS + && make_mutable(fname, mode, file_flags, force_change) > 0) { + ret = fchownat(dfd, bname, owner, group, AT_SYMLINK_NOFOLLOW); + e = errno; + undo_make_mutable(fname, file_flags); + } + } +# endif close(dfd); errno = e; return ret; @@ -1136,14 +1215,14 @@ #endif if (!secure_relpath_active()) - return do_lchown(fname, owner, group); + return do_lchown(fname, owner, group, mode, file_flags); if (!fname || !*fname || *fname == '/') - return do_lchown(fname, owner, group); + return do_lchown(fname, owner, group, mode, file_flags); slash = strrchr(fname, '/'); if (!slash) - return do_lchown(fname, owner, group); + return do_lchown(fname, owner, group, mode, file_flags); dlen = slash - fname; if (dlen >= sizeof dirpath) { @@ -1160,11 +1239,28 @@ ret = fchownat(dfd, bname, owner, group, AT_SYMLINK_NOFOLLOW); e = errno; +#ifdef SUPPORT_FORCE_CHANGE + if (force_change && e == EPERM) { + if (file_flags == NO_FFLAGS) { + STRUCT_STAT st; + if (do_lstat(fname, &st) == 0) { + mode = st.st_mode; + file_flags = st.st_flags; + } + } + if (file_flags != NO_FFLAGS + && make_mutable(fname, mode, file_flags, force_change) > 0) { + ret = fchownat(dfd, bname, owner, group, AT_SYMLINK_NOFOLLOW); + e = errno; + undo_make_mutable(fname, file_flags); + } + } +#endif close(dfd); errno = e; return ret; #else - return do_lchown(fname, owner, group); + return do_lchown(fname, owner, group, mode, file_flags); #endif } @@ -1215,7 +1311,7 @@ return -1; close(sock); #ifdef HAVE_CHMOD - return do_chmod(pathname, mode); + return do_chmod(pathname, mode, 0); #else return 0; #endif @@ -1391,7 +1487,21 @@ { if (dry_run) return 0; RETURN_ERROR_IF_RO_OR_LO; - return rmdir(pathname); + if (rmdir(pathname) == 0) + return 0; +#ifdef SUPPORT_FORCE_CHANGE + if (force_change && errno == EPERM) { + STRUCT_STAT st; + if (do_lstat(pathname, &st) == 0 + && make_mutable(pathname, st.st_mode, st.st_flags, force_change) > 0) { + if (rmdir(pathname) == 0) + return 0; + undo_make_mutable(pathname, st.st_flags); + } + errno = EPERM; + } +#endif + return -1; } /* @@ -1422,6 +1532,18 @@ return -1; ret = unlinkat(dfd, bname, AT_REMOVEDIR); e = errno; +# ifdef SUPPORT_FORCE_CHANGE + if (force_change && e == EPERM) { + STRUCT_STAT st; + if (do_lstat(pathname, &st) == 0 + && make_mutable(pathname, st.st_mode, st.st_flags, force_change) > 0) { + ret = unlinkat(dfd, bname, AT_REMOVEDIR); + e = errno; + if (ret != 0) + undo_make_mutable(pathname, st.st_flags); + } + } +# endif close(dfd); errno = e; return ret; @@ -1453,6 +1575,18 @@ ret = unlinkat(dfd, bname, AT_REMOVEDIR); e = errno; +#ifdef SUPPORT_FORCE_CHANGE + if (force_change && e == EPERM) { + STRUCT_STAT st; + if (do_lstat(pathname, &st) == 0 + && make_mutable(pathname, st.st_mode, st.st_flags, force_change) > 0) { + ret = unlinkat(dfd, bname, AT_REMOVEDIR); + e = errno; + if (ret != 0) + undo_make_mutable(pathname, st.st_flags); + } + } +#endif close(dfd); errno = e; return ret; @@ -1563,7 +1697,7 @@ } #ifdef HAVE_CHMOD -int do_chmod(const char *path, mode_t mode) +int do_chmod(const char *path, mode_t mode, UNUSED(uint32 file_flags)) { static int switch_step = 0; int code; @@ -1603,6 +1737,23 @@ code = chmod(path, mode & CHMOD_BITS); /* DISCOURAGED FUNCTION */ break; } +#ifdef SUPPORT_FORCE_CHANGE + if (code < 0 && force_change && errno == EPERM && !S_ISLNK(mode)) { + if (file_flags == NO_FFLAGS) { + STRUCT_STAT st; + if (do_lstat(path, &st) == 0) + file_flags = st.st_flags; + } + if (file_flags != NO_FFLAGS + && make_mutable(path, mode, file_flags, force_change) > 0) { + code = chmod(path, mode & CHMOD_BITS); + undo_make_mutable(path, file_flags); + if (code == 0) + return 0; + } + errno = EPERM; + } +#endif if (code != 0 && (preserve_perms || preserve_executability)) return code; return 0; @@ -1767,7 +1918,7 @@ Falls back to do_chmod() for absolute paths and for paths with no parent component, where there is nothing to protect against. */ -int do_chmod_at(const char *fname, mode_t mode) +int do_chmod_at(const char *fname, mode_t mode, UNUSED(uint32 file_flags)) { #ifdef AT_FDCWD extern int am_daemon, am_chrooted; @@ -1788,12 +1939,27 @@ * S_ISLNK(mode) still needs do_chmod()'s lchmod()/setattrlist() handling. */ if (operator_path_resolve && fname && *fname && !S_ISLNK(mode)) { if (symlink_optout_allowed()) - return do_chmod(fname, mode); + return do_chmod(fname, mode, file_flags); dfd = owner_walk_parent(fname, &bname); if (dfd < 0) return -1; ret = do_fchmodat_nofollow(dfd, bname, mode); e = errno; +#ifdef SUPPORT_FORCE_CHANGE + if (ret < 0 && force_change && e == EPERM && !S_ISLNK(mode)) { + if (file_flags == NO_FFLAGS) { + STRUCT_STAT st; + if (do_lstat(fname, &st) == 0) + file_flags = st.st_flags; + } + if (file_flags != NO_FFLAGS + && make_mutable(fname, mode, file_flags, force_change) > 0) { + ret = do_fchmodat_nofollow(dfd, bname, mode); + e = errno; + undo_make_mutable(fname, file_flags); + } + } +#endif close(dfd); errno = e; return ret; @@ -1807,14 +1973,14 @@ * already access. Everywhere else, fall through to plain * do_chmod() to avoid the dirfd-open overhead on every call. */ if (!secure_relpath_active()) - return do_chmod(fname, mode); + return do_chmod(fname, mode, file_flags); if (!fname || !*fname || *fname == '/' || S_ISLNK(mode)) - return do_chmod(fname, mode); + return do_chmod(fname, mode, file_flags); slash = strrchr(fname, '/'); if (!slash) - return do_chmod(fname, mode); + return do_chmod(fname, mode, file_flags); dlen = slash - fname; if (dlen >= sizeof dirpath) { @@ -1831,20 +1997,64 @@ ret = do_fchmodat_nofollow(dfd, bname, mode); e = errno; +#ifdef SUPPORT_FORCE_CHANGE + if (ret < 0 && force_change && e == EPERM && !S_ISLNK(mode)) { + if (file_flags == NO_FFLAGS) { + STRUCT_STAT st; + if (do_lstat(fname, &st) == 0) + file_flags = st.st_flags; + } + if (file_flags != NO_FFLAGS + && make_mutable(fname, mode, file_flags, force_change) > 0) { + ret = do_fchmodat_nofollow(dfd, bname, mode); + e = errno; + undo_make_mutable(fname, file_flags); + } + } +#endif close(dfd); errno = e; return ret; #else - return do_chmod(fname, mode); + return do_chmod(fname, mode, file_flags); #endif } #endif -int do_rename(const char *old_path, const char *new_path) +#ifdef HAVE_CHFLAGS +int do_chflags(const char *path, uint32 file_flags) { if (dry_run) return 0; RETURN_ERROR_IF_RO_OR_LO; - return rename(old_path, new_path); + return chflags(path, file_flags); +} +#endif + +int do_rename(const char *old_path, const char *new_path, UNUSED(mode_t mode), UNUSED(uint32 file_flags)) +{ + int ret; + + if (dry_run) return 0; + RETURN_ERROR_IF_RO_OR_LO; + ret = rename(old_path, new_path); +#ifdef SUPPORT_FORCE_CHANGE + if (ret < 0 && force_change && errno == EPERM) { + if (file_flags == NO_FFLAGS) { + STRUCT_STAT st; + if (do_lstat(new_path, &st) == 0) + file_flags = st.st_flags; + } + if (file_flags != NO_FFLAGS + && make_mutable(new_path, mode, file_flags, force_change) > 0) { + ret = rename(old_path, new_path); + undo_make_mutable(new_path, file_flags); + if (ret == 0) + return 0; + } + errno = EPERM; + } +#endif + return ret; } /* @@ -1863,7 +2073,7 @@ Falls through to do_rename() in dry-run, non-daemon, chrooted and absolute-path cases, identical to the other do_*_at() wrappers. */ -int do_rename_at(const char *old_path, const char *new_path) +int do_rename_at(const char *old_path, const char *new_path, UNUSED(mode_t mode), UNUSED(uint32 file_flags)) { #ifdef AT_FDCWD extern int am_daemon, am_chrooted; @@ -1879,10 +2089,10 @@ RETURN_ERROR_IF_RO_OR_LO; if (!secure_relpath_active()) - return do_rename(old_path, new_path); + return do_rename(old_path, new_path, mode, file_flags); if (!old_path || !*old_path || !new_path || !*new_path) - return do_rename(old_path, new_path); + return do_rename(old_path, new_path, mode, file_flags); #if defined O_NOFOLLOW && defined O_DIRECTORY /* Operator-supplied path (e.g. a --backup-dir destination or a --temp-dir @@ -1890,7 +2100,7 @@ * uid0/euid symlinks, refuse others; absolute and relative alike). */ if (operator_path_resolve) { if (symlink_optout_allowed()) - return do_rename(old_path, new_path); + return do_rename(old_path, new_path, mode, file_flags); old_dfd = owner_walk_parent(old_path, &old_bname); if (old_dfd < 0) return -1; @@ -1903,6 +2113,21 @@ } ret = renameat(old_dfd, old_bname, new_dfd, new_bname); e = errno; +#ifdef SUPPORT_FORCE_CHANGE + if (ret < 0 && force_change && e == EPERM) { + if (file_flags == NO_FFLAGS) { + STRUCT_STAT st; + if (do_lstat(new_path, &st) == 0) + file_flags = st.st_flags; + } + if (file_flags != NO_FFLAGS + && make_mutable(new_path, mode, file_flags, force_change) > 0) { + ret = renameat(old_dfd, old_bname, new_dfd, new_bname); + e = errno; + undo_make_mutable(new_path, file_flags); + } + } +#endif close(new_dfd); close(old_dfd); errno = e; @@ -1996,6 +2221,24 @@ ret = renameat(old_dfd, old_bname, new_dfd, new_bname); e = errno; +#ifdef SUPPORT_FORCE_CHANGE + if (ret < 0 && force_change && e == EPERM) { + if (file_flags == NO_FFLAGS) { + STRUCT_STAT st; + if (do_lstat(new_path, &st) == 0) + file_flags = st.st_flags; + } + if (file_flags != NO_FFLAGS + && make_mutable(new_path, mode, file_flags, force_change) > 0) { + ret = renameat(old_dfd, old_bname, new_dfd, new_bname); + e = errno; + undo_make_mutable(new_path, file_flags); + if (ret == 0) + return 0; + } + errno = EPERM; + } +#endif if (new_owns) close(new_dfd); if (old_owns) @@ -2003,7 +2246,7 @@ errno = e; return ret; #else - return do_rename(old_path, new_path); + return do_rename(old_path, new_path, mode, file_flags); #endif } --- t_chmod_secure.c.orig +++ t_chmod_secure.c @@ -112,26 +112,26 @@ * Solaris, older Cygwin, HPE NonStop, pre-5.6 Linux) -- which now follows * an in-tree directory symlink whose target is relative and ".."-free. * Escapes are still rejected on both paths (Scenario B). */ - int rc = do_chmod_at("inside_link/sentinel", 0640); + int rc = do_chmod_at("inside_link/sentinel", 0640, 0); check("A: legit dir-symlink within tree (followed)", rc, 1, "realdir/sentinel", 0640); /* Scenario B: parent symlink escapes the tree -- chmod must be * rejected and the outside file's mode must be unchanged. */ - rc = do_chmod_at("escape_link/sentinel", 0666); + rc = do_chmod_at("escape_link/sentinel", 0666, 0); check("B: parent symlink escapes tree (the attack)", rc, 0, "../trap/sentinel", 0600); /* Scenario C: plain relative path with no symlink components, * regression check that the safe wrapper doesn't break the * normal case. */ - rc = do_chmod_at("realdir/sentinel", 0644); + rc = do_chmod_at("realdir/sentinel", 0644, 0); check("C: plain relative path (regression check)", rc, 1, "realdir/sentinel", 0644); /* Scenario D: top-level file, no parent directory component. * Falls back to do_chmod(); should succeed. */ - rc = do_chmod_at("topfile", 0640); + rc = do_chmod_at("topfile", 0640, 0); check("D: top-level file, no parent component", rc, 1, "topfile", 0640); @@ -141,7 +141,7 @@ * (refused on Linux, lchmod-the-symlink on *BSD/macOS), so assert only that * the outside target's mode is unchanged. */ if (leaf_chmod_nofollow_supported()) { - rc = do_chmod_at("realdir/leaflink", 0666); + rc = do_chmod_at("realdir/leaflink", 0666, 0); check("E: leaf component is an escaping symlink (must not be followed)", rc, -1, "../trap/sentinel", 0600); } else { --- t_rename_secure.c.orig +++ t_rename_secure.c @@ -30,14 +30,14 @@ if (!old_path || !*old_path || *old_path == '/' || !new_path || !*new_path || *new_path == '/') - return do_rename(old_path, new_path); + return do_rename(old_path, new_path, 0, NO_FFLAGS); old_slash = strrchr(old_path, '/'); new_slash = strrchr(new_path, '/'); if (!old_slash || !new_slash) - return do_rename(old_path, new_path); + return do_rename(old_path, new_path, 0, NO_FFLAGS); - return do_rename_at(old_path, new_path); + return do_rename_at(old_path, new_path, 0, NO_FFLAGS); } #endif @@ -64,7 +64,7 @@ int saved_errno; errno = 0; - rc = do_rename_at(old_path, new_path); + rc = do_rename_at(old_path, new_path, 0, NO_FFLAGS); saved_errno = errno; got_ok = rc == 0; --- t_stub.c.orig +++ t_stub.c @@ -32,7 +32,9 @@ int protect_args = 0; int module_id = -1; int relative_paths = 0; +int force_change = 0; unsigned int module_dirlen = 0; +int preserve_acls = 0; int preserve_xattrs = 0; int preserve_perms = 0; int preserve_executability = 0; @@ -130,3 +132,23 @@ { return cst ? 0 : 0; } + +#if defined SUPPORT_FILE_FLAGS || defined SUPPORT_FORCE_CHANGE + int make_mutable(UNUSED(const char *fname), UNUSED(mode_t mode), UNUSED(uint32 file_flags), UNUSED(uint32 iflags)) +{ + return 0; +} + +/* Undo a prior make_mutable() call that returned a 1. */ + int undo_make_mutable(UNUSED(const char *fname), UNUSED(uint32 file_flags)) +{ + return 0; +} +#endif + +#ifdef SUPPORT_XATTRS + int x_lstat(UNUSED(const char *fname), UNUSED(STRUCT_STAT *fst), UNUSED(STRUCT_STAT *xst)) +{ + return -1; +} +#endif --- usage.c.orig +++ usage.c @@ -156,6 +156,11 @@ #endif "crtimes", +#ifndef SUPPORT_FILE_FLAGS + "no " +#endif + "file-flags", + "*Optimizations", #ifndef USE_ROLL_SIMD --- util1.c.orig +++ util1.c @@ -32,6 +32,7 @@ extern int modify_window; extern int relative_paths; extern int preserve_xattrs; +extern int force_change; extern int omit_link_times; extern int preallocate_files; extern int operator_path_resolve; @@ -117,6 +118,33 @@ rprintf(FCLIENT, " (%d args)\n", cnt); } +#ifdef SUPPORT_FORCE_CHANGE +static int try_a_force_change(const char *fname, STRUCT_STAT *stp) +{ + uint32 file_flags = ST_FLAGS(*stp); + if (file_flags == NO_FFLAGS) { + STRUCT_STAT st; + if (x_lstat(fname, &st, NULL) == 0) + file_flags = st.st_flags; + } + if (file_flags != NO_FFLAGS && make_mutable(fname, stp->st_mode, file_flags, force_change) > 0) { + int ret, save_force_change = force_change; + + force_change = 0; /* Make certain we can't come back here. */ + ret = set_times(fname, stp); + force_change = save_force_change; + + undo_make_mutable(fname, file_flags); + + return ret; + } + + errno = EPERM; + + return -1; +} +#endif + /* This returns 0 for success, 1 for a symlink if symlink time-setting * is not possible, or -1 for any other error. */ int set_times(const char *fname, STRUCT_STAT *stp) @@ -144,6 +172,10 @@ #include "case_N.h" if (do_utimensat_at(fname, stp) == 0) break; +#ifdef SUPPORT_FORCE_CHANGE + if (force_change && errno == EPERM && try_a_force_change(fname, stp) == 0) + break; +#endif if (errno != ENOSYS) return -1; switch_step++; @@ -153,6 +185,10 @@ #include "case_N.h" if (do_lutimes(fname, stp) == 0) break; +#ifdef SUPPORT_FORCE_CHANGE + if (force_change && errno == EPERM && try_a_force_change(fname, stp) == 0) + break; +#endif if (errno != ENOSYS) return -1; switch_step++; @@ -174,6 +210,10 @@ if (do_utime(fname, stp) == 0) break; #endif +#ifdef SUPPORT_FORCE_CHANGE + if (force_change && errno == EPERM && try_a_force_change(fname, stp) == 0) + break; +#endif return -1; } @@ -581,7 +621,7 @@ } /* maybe we should return rename()'s exit status? Nah. */ - if (do_rename_at(fname, path) != 0) { + if (do_rename_at(fname, path, 0, NO_FFLAGS) != 0) { errno = ETXTBSY; return -1; } @@ -613,8 +653,14 @@ const char *os = strrchr(from, '/'); const char *ns = strrchr(to, '/'); rr = do_rename_atfd(ofd, os ? os + 1 : from, nfd, ns ? ns + 1 : to); +#ifdef SUPPORT_FORCE_CHANGE + /* The fd-relative wrapper cannot chflags(); retry an + * immutable destination via the full-path wrapper. */ + if (rr < 0 && force_change && errno == EPERM) + rr = do_rename_at(from, to, 0, NO_FFLAGS); +#endif } else - rr = do_rename_at(from, to); + rr = do_rename_at(from, to, 0, NO_FFLAGS); if (rr == 0) return 0; --- xattrs.c.orig +++ xattrs.c @@ -1154,7 +1154,7 @@ #endif && access(fname, W_OK) < 0 && (fd >= 0 ? fchmod(fd, (sxp->st.st_mode & CHMOD_BITS) | S_IWUSR) - : do_chmod_at(fname, (sxp->st.st_mode & CHMOD_BITS) | S_IWUSR)) == 0) + : do_chmod_at(fname, (sxp->st.st_mode & CHMOD_BITS) | S_IWUSR, ST_FLAGS(sxp->st))) == 0) added_write_perm = 1; ndx = F_XATTR(file); @@ -1166,7 +1166,7 @@ if (fd >= 0) fchmod(fd, sxp->st.st_mode); else - do_chmod_at(fname, sxp->st.st_mode); + do_chmod_at(fname, sxp->st.st_mode, ST_FLAGS(sxp->st)); } return 0; } @@ -1177,7 +1177,7 @@ if (fd >= 0) fchmod(fd, sxp->st.st_mode); else - do_chmod_at(fname, sxp->st.st_mode); + do_chmod_at(fname, sxp->st.st_mode, ST_FLAGS(sxp->st)); } return return_value; } @@ -1317,7 +1317,7 @@ if (fd >= 0) fchmod(fd, mode); else - do_chmod_at(fname, mode); + do_chmod_at(fname, mode, ST_FLAGS(fst)); } if (!IS_DEVICE(fst.st_mode)) fst.st_rdev = 0; /* just in case */