Files
ports/net/rsync/files/extra-patch-file-flags.diff
T
2026-10-04 04:07:15 +00:00

2035 lines
66 KiB
Diff

--- backup.c.orig
+++ backup.c
@@ -246,7 +246,7 @@
return 0;
}
#endif
- if (do_rename_at(from, to) == 0) {
+ if (do_rename_at(from, to, stp->st_mode, ST_FLAGS(*stp)) == 0) {
if (stp->st_nlink > 1 && !S_ISDIR(stp->st_mode)) {
/* If someone has hard-linked the file into the backup
* dir, rename() might return success but do nothing! */
--- compat.c.orig
+++ compat.c
@@ -40,6 +40,7 @@
extern int basis_dir_cnt;
extern int prune_empty_dirs;
extern int protocol_version;
+extern int force_change;
extern int protect_args;
extern int preserve_uid;
extern int preserve_gid;
@@ -47,6 +48,7 @@
extern int preserve_crtimes;
extern int preserve_acls;
extern int preserve_xattrs;
+extern int preserve_file_flags;
extern int xfer_flags_as_varint;
extern int need_messages_from_generator;
extern int delete_mode, delete_before, delete_during, delete_after;
@@ -87,7 +89,7 @@
int xattr_sum_len = 0;
/* These index values are for the file-list's extra-attribute array. */
-int pathname_ndx, depth_ndx, atimes_ndx, crtimes_ndx, uid_ndx, gid_ndx, acls_ndx, xattrs_ndx, unsort_ndx;
+int pathname_ndx, depth_ndx, atimes_ndx, crtimes_ndx, uid_ndx, gid_ndx, file_flags_ndx, acls_ndx, xattrs_ndx, unsort_ndx;
int receiver_symlink_times = 0; /* receiver can set the time on a symlink */
int sender_symlink_iconv = 0; /* sender should convert symlink content */
@@ -645,6 +647,8 @@
uid_ndx = ++file_extra_cnt;
if (preserve_gid)
gid_ndx = ++file_extra_cnt;
+ if (preserve_file_flags || (force_change && !am_sender))
+ file_flags_ndx = ++file_extra_cnt;
if (preserve_acls && !am_sender)
acls_ndx = ++file_extra_cnt;
if (preserve_xattrs)
@@ -763,6 +767,10 @@
fprintf(stderr, "Both rsync versions must be at least 3.2.0 for --crtimes.\n");
exit_cleanup(RERR_PROTOCOL);
}
+ if (!xfer_flags_as_varint && preserve_file_flags) {
+ fprintf(stderr, "Both rsync versions must be at least 3.2.0 for --file-flags.\n");
+ exit_cleanup(RERR_PROTOCOL);
+ }
if (am_sender) {
receiver_symlink_times = am_server
? strchr(client_info, 'L') != NULL
--- delete.c.orig
+++ delete.c
@@ -25,6 +25,7 @@
extern int am_root;
extern int make_backups;
extern int max_delete;
+extern int force_change;
extern char *backup_dir;
extern char *backup_suffix;
extern int backup_suffix_len;
@@ -62,10 +63,19 @@
{
const char *leaf;
int dfd = del_held_dfd(fbuf, &leaf);
- if (dfd >= 0)
- do_chmod_atfd(dfd, leaf, mode);
- else
- do_chmod_at(fbuf, mode);
+ if (dfd >= 0) {
+ if (do_chmod_atfd(dfd, leaf, mode) == 0)
+ return;
+#ifdef SUPPORT_FORCE_CHANGE
+ /* The fd-relative wrapper cannot chflags(); let the full-path
+ * wrapper's force-change logic have a go at an immutable target. */
+ if (!(force_change && errno == EPERM))
+ return;
+#else
+ return;
+#endif
+ }
+ do_chmod_at(fbuf, mode, NO_FFLAGS);
}
static int del_unlink(const char *fbuf)
@@ -224,6 +234,12 @@
int dfd = del_held_dfd(fbuf, &leaf);
what = "rmdir";
ok = (dfd >= 0 ? do_unlink_atfd(dfd, leaf, AT_REMOVEDIR) : do_rmdir_at(fbuf)) == 0;
+#ifdef SUPPORT_FORCE_CHANGE
+ /* The fd-relative wrapper cannot chflags(); retry an immutable
+ * directory through the full-path wrapper. */
+ if (!ok && dfd >= 0 && force_change && errno == EPERM)
+ ok = do_rmdir_at(fbuf) == 0;
+#endif
} else {
if (make_backups > 0 && !(flags & DEL_FOR_BACKUP) && (backup_dir || !is_backup_file(fbuf))) {
what = "make_backup";
--- testsuite/file-flags_test.py.orig
+++ testsuite/file-flags_test.py
@@ -0,0 +1,302 @@
+#!/usr/bin/env python3
+# Test the FreeBSD "File system flags" patch: --file-flags and the
+# --force-change / --force-uchange / --force-schange family.
+#
+# --file-flags copies a file's BSD st_flags (chflags(2)) to the receiver.
+# --force-change lets the receiver update or delete a file/dir whose
+# immutable flag would otherwise make the operation fail with EPERM.
+#
+# Both need a chflags(2) platform AND a filesystem that actually stores the
+# flag, so everything here is gated behind a set-then-clear probe: ZFS, for
+# instance, keeps the system flags (schg/sappnd) but rejects the user ones
+# (uchg/uappnd), and a non-root run or securelevel >= 1 can set neither.
+
+import atexit
+import os
+import stat
+
+from rsyncfns import (
+ FROMDIR, SCRATCHDIR, TODIR,
+ makepath, run_rsync, test_fail, test_skipped,
+)
+
+
+if not hasattr(os, 'chflags'):
+ test_skipped("no chflags(2) on this platform")
+
+vv = run_rsync('-VV', check=True, capture_output=True).stdout
+if '"file_flags": true' not in vv:
+ test_skipped("rsync is configured without file-flags support")
+
+
+# --- flag probing ----------------------------------------------------------
+
+def clear_flags_tree(top) -> None:
+ """Drop every st_flag under `top` so the tree can be rewritten/removed.
+
+ Registered with atexit as well as called between sub-tests: an immutable
+ file left behind would defeat not just this test's cleanup but the
+ runner's removal of the whole scratch directory.
+ """
+ for root, dirs, files in os.walk(top, topdown=False):
+ for name in files + dirs:
+ try:
+ os.chflags(os.path.join(root, name), 0)
+ except OSError:
+ pass
+ try:
+ os.chflags(top, 0)
+ except OSError:
+ pass
+
+
+atexit.register(clear_flags_tree, SCRATCHDIR)
+
+makepath(FROMDIR, TODIR)
+
+
+def probe_flag():
+ """Return (flag_bit, name) for an immutable flag this filesystem stores,
+ or (None, None). Must survive a set *and* a clear: securelevel >= 1
+ makes the system flags one-way, which would strand the scratch tree."""
+ probe = SCRATCHDIR / '.flagprobe'
+ probe.write_text('x\n')
+ try:
+ for bit, name in (stat.SF_IMMUTABLE, 'schg'),(stat.UF_IMMUTABLE, 'uchg'):
+ try:
+ os.chflags(probe, bit)
+ except (OSError, AttributeError):
+ continue
+ if not os.lstat(probe).st_flags & bit:
+ continue
+ try:
+ os.chflags(probe, 0)
+ except OSError:
+ continue # cannot be cleared -- unusable for testing
+ return bit, name
+ return None, None
+ finally:
+ try:
+ os.chflags(probe, 0)
+ except OSError:
+ pass
+ probe.unlink(missing_ok=True)
+
+
+IMMUTABLE, FLAGNAME = probe_flag()
+if IMMUTABLE is None:
+ test_skipped("this filesystem does not store a settable/clearable "
+ "immutable flag (tried uchg and schg)")
+
+print(f"using the {FLAGNAME} flag")
+
+
+def flags_of(path) -> int:
+ return os.lstat(path).st_flags
+
+
+def reset() -> None:
+ """Empty from/ and to/ for the next sub-test."""
+ for d in (FROMDIR, TODIR):
+ clear_flags_tree(d)
+ for root, dirs, files in os.walk(d, topdown=False):
+ for name in files:
+ os.unlink(os.path.join(root, name))
+ for name in dirs:
+ os.rmdir(os.path.join(root, name))
+ makepath(FROMDIR / 'sub', TODIR)
+
+
+# --- 1: --file-flags propagates the flag to the receiver -------------------
+
+reset()
+(FROMDIR / 'sub' / 'f').write_text("hello\n")
+os.chflags(FROMDIR / 'sub' / 'f', IMMUTABLE)
+
+run_rsync('-a', '--file-flags', f'{FROMDIR}/', f'{TODIR}/')
+if not flags_of(TODIR / 'sub' / 'f') & IMMUTABLE:
+ test_fail(f"--file-flags did not copy the {FLAGNAME} flag to the receiver")
+print("ok: --file-flags propagates the flag")
+
+
+# --- 2: without --file-flags the receiver keeps no flag --------------------
+
+reset()
+(FROMDIR / 'sub' / 'f').write_text("hello\n")
+os.chflags(FROMDIR / 'sub' / 'f', IMMUTABLE)
+
+run_rsync('-a', f'{FROMDIR}/', f'{TODIR}/')
+if flags_of(TODIR / 'sub' / 'f') & IMMUTABLE:
+ test_fail("plain -a propagated a file flag; --file-flags is opt-in")
+print("ok: plain -a leaves receiver flags alone")
+
+
+# --- 3: an immutable destination blocks an update without --force-change ---
+
+reset()
+(FROMDIR / 'sub' / 'f').write_text("new-content\n")
+makepath(TODIR / 'sub')
+(TODIR / 'sub' / 'f').write_text("old\n")
+os.chflags(TODIR / 'sub' / 'f', IMMUTABLE)
+
+proc = run_rsync('-a', f'{FROMDIR}/', f'{TODIR}/', check=False,
+ capture_output=True)
+kept = (TODIR / 'sub' / 'f').read_text()
+clear_flags_tree(TODIR)
+if kept != "old\n":
+ test_fail("an immutable destination file was updated without "
+ f"--force-change (content is now {kept!r})")
+if proc.returncode == 0:
+ test_fail("rsync reported success while failing to update an "
+ "immutable destination file")
+print(f"ok: immutable destination blocks the update (exit {proc.returncode})")
+
+
+# --- 4: --force-change pushes the update through ---------------------------
+
+reset()
+(FROMDIR / 'sub' / 'f').write_text("new-content\n")
+makepath(TODIR / 'sub')
+(TODIR / 'sub' / 'f').write_text("old\n")
+os.chflags(TODIR / 'sub' / 'f', IMMUTABLE)
+
+proc = run_rsync('-a', '--force-change', f'{FROMDIR}/', f'{TODIR}/',
+ check=False, capture_output=True)
+got = (TODIR / 'sub' / 'f').read_text()
+clear_flags_tree(TODIR)
+if got != "new-content\n":
+ test_fail("--force-change did not update the immutable destination file "
+ f"(content is {got!r}, rsync said: {proc.stderr.strip()})")
+if proc.returncode != 0:
+ test_fail(f"--force-change exited {proc.returncode}: {proc.stderr.strip()}")
+print("ok: --force-change updates an immutable destination file")
+
+
+# --- 5: --delete needs --force-change to remove an immutable file ----------
+
+reset()
+(FROMDIR / 'sub' / 'f').write_text("keep\n")
+makepath(TODIR / 'sub')
+(TODIR / 'sub' / 'f').write_text("keep\n")
+(TODIR / 'sub' / 'extra').write_text("gone\n")
+os.chflags(TODIR / 'sub' / 'extra', IMMUTABLE)
+
+run_rsync('-a', '--delete', f'{FROMDIR}/', f'{TODIR}/', check=False)
+survived = (TODIR / 'sub' / 'extra').exists()
+if not survived:
+ clear_flags_tree(TODIR)
+ test_fail("--delete removed an immutable file without --force-change")
+print("ok: --delete alone leaves an immutable file in place")
+
+# Same tree, now with --force-change: it must go.
+proc = run_rsync('-a', '--delete', '--force-change', f'{FROMDIR}/', f'{TODIR}/',
+ check=False, capture_output=True)
+still_there = (TODIR / 'sub' / 'extra').exists()
+clear_flags_tree(TODIR)
+if still_there:
+ test_fail("--force-change --delete did not remove the immutable file "
+ f"(rsync said: {proc.stderr.strip()})")
+if proc.returncode != 0:
+ test_fail(f"--force-change --delete exited {proc.returncode}: "
+ f"{proc.stderr.strip()}")
+print("ok: --force-change --delete removes an immutable file")
+
+
+# --- 6: an immutable *directory* is a documented limitation ----------------
+#
+# The patch clears the immutable flag on the object it is about to touch, but
+# unlinking a file also needs write permission on its *parent*, and nothing
+# makes an immutable parent directory mutable first. do_unlink() in syscall.c
+# says so outright:
+#
+# /* TODO: handle immutable directories */
+#
+# So --force-change does NOT descend into an immutable directory. This test
+# pins that behaviour rather than wishing it away: if someone teaches the
+# patch to handle immutable parents, this is the test that should fail and be
+# rewritten into a positive assertion.
+
+reset()
+(FROMDIR / 'sub' / 'f').write_text("keep\n")
+makepath(TODIR / 'sub', TODIR / 'doomed')
+(TODIR / 'sub' / 'f').write_text("keep\n")
+(TODIR / 'doomed' / 'inner').write_text("x\n")
+os.chflags(TODIR / 'doomed' / 'inner', IMMUTABLE)
+os.chflags(TODIR / 'doomed', IMMUTABLE)
+
+proc = run_rsync('-a', '--delete', '--force-change', f'{FROMDIR}/', f'{TODIR}/',
+ check=False, capture_output=True)
+still_there = (TODIR / 'doomed').exists()
+clear_flags_tree(TODIR)
+if not still_there:
+ test_fail("--force-change --delete removed a file under an immutable "
+ "directory -- immutable parents are now handled, so this "
+ "known-limitation test needs to become a positive assertion")
+print("ok: immutable parent directory still blocks deletion "
+ "(known limitation, see do_unlink()'s TODO)")
+
+
+# --- 7: the itemized output grows an 'f' column for a flag change ----------
+
+reset()
+(FROMDIR / 'sub' / 'f').write_text("hello\n")
+run_rsync('-a', '--file-flags', f'{FROMDIR}/', f'{TODIR}/')
+
+# Change nothing but the source's flags.
+os.chflags(FROMDIR / 'sub' / 'f', IMMUTABLE)
+proc = run_rsync('-a', '--file-flags', '-i', f'{FROMDIR}/', f'{TODIR}/',
+ capture_output=True)
+line = next((ln for ln in proc.stdout.splitlines() if ln.endswith('sub/f')), None)
+clear_flags_tree(FROMDIR)
+clear_flags_tree(TODIR)
+if line is None:
+ test_fail("a flags-only change was not itemized at all:\n" + proc.stdout)
+if 'f' not in line.split()[0]:
+ test_fail(f"itemized output has no 'f' flag column: {line!r}")
+print(f"ok: itemize reports the flag change ({line})")
+
+
+# --- 8: a second --file-flags pass is a no-op ------------------------------
+
+reset()
+(FROMDIR / 'sub' / 'f').write_text("hello\n")
+os.chflags(FROMDIR / 'sub' / 'f', IMMUTABLE)
+run_rsync('-a', '--file-flags', f'{FROMDIR}/', f'{TODIR}/')
+proc = run_rsync('-a', '--file-flags', '-i', f'{FROMDIR}/', f'{TODIR}/',
+ capture_output=True)
+changed = [ln for ln in proc.stdout.splitlines() if ln.strip()]
+clear_flags_tree(FROMDIR)
+clear_flags_tree(TODIR)
+if changed:
+ test_fail("a second --file-flags pass was not a no-op:\n"
+ + '\n'.join(changed))
+print("ok: a second --file-flags pass is a no-op")
+
+
+# --- 9: --force-change can descend into an immutable directory ------------------------------
+
+reset()
+(FROMDIR / 'sub' / 'f').write_text("old\n")
+os.chflags(FROMDIR / 'sub' / 'f', IMMUTABLE)
+os.chflags(FROMDIR / 'sub', IMMUTABLE)
+run_rsync('-a', '--file-flags', '--force-schange', f'{FROMDIR}/', f'{TODIR}/')
+
+copied = (TODIR / 'sub' / 'f').exists()
+if not copied:
+ test_fail("file not copied: \n")
+
+os.chflags(FROMDIR / 'sub' / 'f', 0)
+(FROMDIR / 'sub' / 'f').write_text("new\n")
+os.chflags(FROMDIR / 'sub' / 'f', IMMUTABLE)
+
+run_rsync('-a', '-c', '--file-flags', '--force-schange', f'{FROMDIR}/', f'{TODIR}/')
+
+kept = (TODIR / 'sub' / 'f').read_text()
+if kept != "new\n":
+ test_fail("--force-change cannot descend into an immutable directory: \n" + kept)
+
+clear_flags_tree(FROMDIR)
+clear_flags_tree(TODIR)
+
+print("ok: --force-change descend into an immutable directory")
+
--- flist.c.orig
+++ flist.c
@@ -57,6 +57,7 @@
extern int preserve_hard_links;
extern int preserve_devices;
extern int preserve_specials;
+extern int preserve_file_flags;
extern int delete_during;
extern int missing_args;
extern int eol_nulls;
@@ -483,6 +484,9 @@
static time_t crtime;
#endif
static mode_t mode;
+#ifdef SUPPORT_FILE_FLAGS
+ static uint32 file_flags;
+#endif
#ifdef SUPPORT_HARD_LINKS
static int64 dev;
#endif
@@ -526,6 +530,14 @@
xflags |= XMIT_SAME_MODE;
else
mode = file->mode;
+#ifdef SUPPORT_FILE_FLAGS
+ if (preserve_file_flags) {
+ if (F_FFLAGS(file) == file_flags)
+ xflags |= XMIT_SAME_FLAGS;
+ else
+ file_flags = F_FFLAGS(file);
+ }
+#endif
if (preserve_devices && IS_DEVICE(mode)) {
if (protocol_version < 28) {
@@ -687,6 +699,10 @@
#endif
if (!(xflags & XMIT_SAME_MODE))
write_int(f, to_wire_mode(mode));
+#ifdef SUPPORT_FILE_FLAGS
+ if (preserve_file_flags && !(xflags & XMIT_SAME_FLAGS))
+ write_int(f, (int)file_flags);
+#endif
if (atimes_ndx && !S_ISDIR(mode) && !(xflags & XMIT_SAME_ATIME))
write_varlong(f, atime, 4);
if (preserve_uid && !(xflags & XMIT_SAME_UID)) {
@@ -781,6 +797,9 @@
static time_t crtime;
#endif
static mode_t mode;
+#ifdef SUPPORT_FILE_FLAGS
+ static uint32 file_flags;
+#endif
#ifdef SUPPORT_HARD_LINKS
static int64 dev;
#endif
@@ -899,6 +918,10 @@
if (crtimes_ndx)
crtime = F_CRTIME(first);
#endif
+#ifdef SUPPORT_FILE_FLAGS
+ if (preserve_file_flags)
+ file_flags = F_FFLAGS(first);
+#endif
if (preserve_uid)
uid = F_OWNER(first);
if (preserve_gid)
@@ -995,6 +1018,10 @@
if (chmod_modes && !S_ISLNK(mode) && mode)
mode = tweak_mode(mode, chmod_modes);
+#ifdef SUPPORT_FILE_FLAGS
+ if (preserve_file_flags && !(xflags & XMIT_SAME_FLAGS))
+ file_flags = (uint32)read_int(f);
+#endif
if (preserve_uid && !(xflags & XMIT_SAME_UID)) {
if (protocol_version < 30)
@@ -1203,6 +1230,10 @@
}
#endif
file->mode = mode;
+#ifdef SUPPORT_FILE_FLAGS
+ if (preserve_file_flags)
+ F_FFLAGS(file) = file_flags;
+#endif
if (preserve_uid)
F_OWNER(file) = uid;
if (preserve_gid) {
@@ -1667,6 +1698,10 @@
}
#endif
file->mode = st.st_mode;
+#if defined SUPPORT_FILE_FLAGS || defined SUPPORT_FORCE_CHANGE
+ if (file_flags_ndx)
+ F_FFLAGS(file) = st.st_flags;
+#endif
if (preserve_uid)
F_OWNER(file) = st.st_uid;
if (preserve_gid)
--- generator.c.orig
+++ generator.c
@@ -46,6 +46,8 @@
extern int preserve_hard_links;
extern int preserve_executability;
extern int preserve_perms;
+extern int preserve_file_flags;
+extern int force_change;
extern int preserve_mtimes;
extern int omit_dir_times;
extern int omit_link_times;
@@ -499,6 +501,10 @@
return 0;
if (perms_differ(file, sxp))
return 0;
+#ifdef SUPPORT_FILE_FLAGS
+ if (preserve_file_flags && sxp->st.st_flags != F_FFLAGS(file))
+ return 0;
+#endif
if (ownership_differs(file, sxp))
return 0;
#ifdef SUPPORT_ACLS
@@ -560,6 +566,11 @@
iflags |= ITEM_REPORT_OWNER;
if (gid_ndx && !(file->flags & FLAG_SKIP_GROUP) && sxp->st.st_gid != (gid_t)F_GROUP(file))
iflags |= ITEM_REPORT_GROUP;
+#ifdef SUPPORT_FILE_FLAGS
+ if (preserve_file_flags && !S_ISLNK(file->mode)
+ && sxp->st.st_flags != F_FFLAGS(file))
+ iflags |= ITEM_REPORT_FFLAGS;
+#endif
#ifdef SUPPORT_ACLS
if (preserve_acls && !S_ISLNK(file->mode)) {
if (!ACL_READY(*sxp))
@@ -1414,9 +1425,16 @@
int dfd = held_dfd_for(fname, file);
if (dfd >= 0) {
const char *slash = strrchr(fname, '/');
- return do_chmod_atfd(dfd, slash ? slash + 1 : fname, mode);
+ int ret = do_chmod_atfd(dfd, slash ? slash + 1 : fname, mode);
+#ifdef SUPPORT_FORCE_CHANGE
+ /* The fd-relative wrapper cannot chflags(); let the full-path
+ * wrapper's force-change logic have a go at an immutable target. */
+ if (ret < 0 && force_change && errno == EPERM)
+ ret = do_chmod_at(fname, mode, NO_FFLAGS);
+#endif
+ return ret;
}
- return do_chmod_at(fname, mode);
+ return do_chmod_at(fname, mode, NO_FFLAGS);
}
static void gen_entry_set_times(const char *fname, struct file_struct *file, STRUCT_STAT *stp)
@@ -1424,7 +1442,14 @@
int dfd = held_dfd_for(fname, file);
if (dfd >= 0) {
const char *slash = strrchr(fname, '/');
- if (set_times_at(dfd, slash ? slash + 1 : fname, stp) != -2)
+ int ret = set_times_at(dfd, slash ? slash + 1 : fname, stp);
+#ifdef SUPPORT_FORCE_CHANGE
+ /* set_times_at() has no force-change tier; fall through to the
+ * full-path set_times(), which does. */
+ if (ret < 0 && force_change && errno == EPERM)
+ ret = -2;
+#endif
+ if (ret != -2)
return; /* handled (success or error) by the at-on-dfd tier */
}
set_times(fname, stp);
@@ -1493,7 +1518,12 @@
int dfd = held_dfd_for(path, file);
if (dfd >= 0) {
const char *slash = strrchr(path, '/');
- return do_unlink_atfd(dfd, slash ? slash + 1 : path, 0);
+ int ret = do_unlink_atfd(dfd, slash ? slash + 1 : path, 0);
+#ifdef SUPPORT_FORCE_CHANGE
+ if (ret < 0 && force_change && errno == EPERM)
+ ret = do_unlink_at(path);
+#endif
+ return ret;
}
return do_unlink_at(path);
}
@@ -1508,9 +1538,14 @@
if (odfd >= 0 && ndfd >= 0) {
const char *os = strrchr(opath, '/');
const char *ns = strrchr(npath, '/');
- return do_rename_atfd(odfd, os ? os + 1 : opath, ndfd, ns ? ns + 1 : npath);
+ int ret = do_rename_atfd(odfd, os ? os + 1 : opath, ndfd, ns ? ns + 1 : npath);
+#ifdef SUPPORT_FORCE_CHANGE
+ if (ret < 0 && force_change && errno == EPERM)
+ ret = do_rename_at(opath, npath, 0, NO_FFLAGS);
+#endif
+ return ret;
}
- return do_rename_at(opath, npath);
+ return do_rename_at(opath, npath, 0, NO_FFLAGS);
}
#ifdef SUPPORT_XATTRS
@@ -1855,6 +1890,10 @@
if (!preserve_perms) { /* See comment in non-dir code below. */
file->mode = dest_mode(file->mode, sx.st.st_mode, dflt_perms, statret == 0);
}
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && !preserve_file_flags && statret == 0)
+ F_FFLAGS(file) = ST_FLAGS(sx.st);
+#endif
if (statret != 0 && basis_dir[0] != NULL) {
int j = try_dests_non(file, fname, ndx, fnamecmpbuf, &sx, itemizing, code);
if (j == -2) {
@@ -1900,6 +1939,11 @@
* readable and writable permissions during the time we are
* putting files within them. This is then restored to the
* former permissions after the transfer is done. */
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && F_FFLAGS(file) & force_change
+ && make_mutable(fname, file->mode, F_FFLAGS(file), force_change) > 0)
+ need_retouch_dir_perms = 1;
+#endif
#ifdef HAVE_CHMOD
if (!am_root && (file->mode & S_IRWXU) != S_IRWXU && dir_tweaking) {
mode_t mode = file->mode | S_IRWXU;
@@ -2607,6 +2651,10 @@
gen_entry_set_times(fname, file, &st);
}
}
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && F_FFLAGS(file) & force_change)
+ undo_make_mutable(fname, F_FFLAGS(file));
+#endif
if (counter >= loopchk_limit) {
if (allowed_lull)
maybe_send_keepalive(time(NULL), MSK_ALLOW_FLUSH);
--- log.c.orig
+++ log.c
@@ -763,7 +763,8 @@
: iflags & ITEM_REPORT_ATIME ? 'u' : 'n';
c[9] = !(iflags & ITEM_REPORT_ACL) ? '.' : 'a';
c[10] = !(iflags & ITEM_REPORT_XATTR) ? '.' : 'x';
- c[11] = '\0';
+ c[11] = !(iflags & ITEM_REPORT_FFLAGS) ? '.' : 'f';
+ c[12] = '\0';
if (iflags & (ITEM_IS_NEW|ITEM_MISSING_DATA)) {
char ch = iflags & ITEM_IS_NEW ? '+' : '?';
--- main.c.orig
+++ main.c
@@ -34,6 +34,9 @@
#ifdef HAVE_SYS_RESOURCE_H
#include <sys/resource.h>
#endif
+#ifdef SUPPORT_FORCE_CHANGE
+#include <sys/sysctl.h>
+#endif
extern int dry_run;
extern int list_only;
@@ -53,6 +56,7 @@
extern int got_xfer_error;
extern volatile sig_atomic_t got_sigusr2;
extern int old_style_args;
+extern int force_change;
extern int msgs2stderr;
extern int module_id;
extern int read_only;
@@ -1010,6 +1014,22 @@
* points to an identical file won't be replaced by the referent. */
copy_links = copy_dirlinks = copy_unsafe_links = 0;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change & SYS_IMMUTABLE) {
+ /* Determine whether we'll be able to unlock a system immutable item. */
+ int mib[2];
+ int securityLevel = 0;
+ size_t len = sizeof securityLevel;
+
+ mib[0] = CTL_KERN;
+ mib[1] = KERN_SECURELVL;
+ if (sysctl(mib, 2, &securityLevel, &len, NULL, 0) == 0 && securityLevel > 0) {
+ rprintf(FERROR, "System security level is too high to force mutability on system immutable files and directories.\n");
+ exit_cleanup(RERR_UNSUPPORTED);
+ }
+ }
+#endif
+
#ifdef SUPPORT_HARD_LINKS
if (preserve_hard_links && !inc_recurse)
match_hard_links(first_flist);
--- options.c.orig
+++ options.c
@@ -57,6 +57,7 @@
int preserve_acls = 0;
int preserve_xattrs = 0;
int preserve_perms = 0;
+int preserve_file_flags = 0;
int preserve_executability = 0;
int preserve_devices = 0;
int preserve_specials = 0;
@@ -104,6 +105,7 @@
int saw_stderr_opt = 0;
int allow_8bit_chars = 0;
int force_delete = 0;
+int force_change = 0;
int io_timeout = 0;
int prune_empty_dirs = 0;
int use_qsort = 0;
@@ -642,6 +644,10 @@
{"perms", 'p', POPT_ARG_VAL, &preserve_perms, 1, 0, 0 },
{"no-perms", 0, POPT_ARG_VAL, &preserve_perms, 0, 0, 0 },
{"no-p", 0, POPT_ARG_VAL, &preserve_perms, 0, 0, 0 },
+ {"file-flags", 0, POPT_ARG_VAL, &preserve_file_flags, 1, 0, 0 },
+ {"fileflags", 0, POPT_ARG_VAL, &preserve_file_flags, 1, 0, 0 },
+ {"no-file-flags", 0, POPT_ARG_VAL, &preserve_file_flags, 0, 0, 0 },
+ {"no-fileflags", 0, POPT_ARG_VAL, &preserve_file_flags, 0, 0, 0 },
{"executability", 'E', POPT_ARG_NONE, &preserve_executability, 0, 0, 0 },
{"acls", 'A', POPT_ARG_NONE, 0, 'A', 0, 0 },
{"no-acls", 0, POPT_ARG_VAL, &preserve_acls, 0, 0, 0 },
@@ -745,6 +751,12 @@
{"remove-source-files",0,POPT_ARG_VAL, &remove_source_files, 1, 0, 0 },
{"force", 0, POPT_ARG_VAL, &force_delete, 1, 0, 0 },
{"no-force", 0, POPT_ARG_VAL, &force_delete, 0, 0, 0 },
+ {"force-delete", 0, POPT_ARG_VAL, &force_delete, 1, 0, 0 },
+ {"no-force-delete", 0, POPT_ARG_VAL, &force_delete, 0, 0, 0 },
+ {"force-change", 0, POPT_ARG_VAL, &force_change, ALL_IMMUTABLE, 0, 0 },
+ {"no-force-change", 0, POPT_ARG_VAL, &force_change, 0, 0, 0 },
+ {"force-uchange", 0, POPT_ARG_VAL, &force_change, USR_IMMUTABLE, 0, 0 },
+ {"force-schange", 0, POPT_ARG_VAL, &force_change, SYS_IMMUTABLE, 0, 0 },
{"ignore-errors", 0, POPT_ARG_VAL, &ignore_errors, 1, 0, 0 },
{"no-ignore-errors", 0, POPT_ARG_VAL, &ignore_errors, 0, 0, 0 },
{"max-delete", 0, POPT_ARG_INT, &max_delete, 0, 0, 0 },
@@ -1105,6 +1117,15 @@
#ifndef SUPPORT_CRTIMES
parse_one_refuse_match(0, "crtimes", list_end);
#endif
+#ifndef SUPPORT_FILE_FLAGS
+ parse_one_refuse_match(0, "file-flags", list_end);
+ parse_one_refuse_match(0, "fileflags", list_end);
+#endif
+#ifndef SUPPORT_FORCE_CHANGE
+ parse_one_refuse_match(0, "force-change", list_end);
+ parse_one_refuse_match(0, "force-uchange", list_end);
+ parse_one_refuse_match(0, "force-schange", list_end);
+#endif
/* Now we use the descrip values to actually mark the options for refusal. */
for (op = long_options; op != list_end; op++) {
@@ -2918,6 +2939,9 @@
if (xfer_dirs && !recurse && delete_mode && am_sender)
args[ac++] = "--no-r";
+ if (preserve_file_flags)
+ args[ac++] = "--fileflags";
+
if (do_compression && do_compression_level != CLVL_NOT_SPECIFIED) {
if (asprintf(&arg, "--compress-level=%d", do_compression_level) < 0)
goto oom;
@@ -3013,6 +3037,16 @@
args[ac++] = "--delete-excluded";
if (force_delete)
args[ac++] = "--force";
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change) {
+ if (force_change == ALL_IMMUTABLE)
+ args[ac++] = "--force-change";
+ else if (force_change == USR_IMMUTABLE)
+ args[ac++] = "--force-uchange";
+ else if (force_change == SYS_IMMUTABLE)
+ args[ac++] = "--force-schange";
+ }
+#endif
if (write_batch < 0)
args[ac++] = "--only-write-batch=X";
if (am_root > 1)
--- receiver.c.orig
+++ receiver.c
@@ -264,11 +264,11 @@
return -1;
}
prior_mode = cst.st_mode & CHMOD_BITS;
- if (do_chmod_at(fname, prior_mode | S_IWUSR) < 0)
+ if (do_chmod_at(fname, prior_mode | S_IWUSR, NO_FFLAGS) < 0)
return -1;
fd = do_open(fname, O_WRONLY, 0600);
open_errno = errno;
- if (do_chmod_at(fname, prior_mode) < 0) {
+ if (do_chmod_at(fname, prior_mode, NO_FFLAGS) < 0) {
restore_errno = errno;
if (fd >= 0)
close(fd);
@@ -704,7 +704,7 @@
* an excluded subtree. */
int rret;
operator_path_resolve = 1;
- rret = do_rename_at(partialptr, fname);
+ rret = do_rename_at(partialptr, fname, 0, NO_FFLAGS);
operator_path_resolve = 0;
if (rret < 0) {
rsyserr(FERROR_XFER, errno,
--- rsync.1.md.orig 2026-08-02 21:10:00.000000000 +0000
+++ rsync.1.md 2026-08-21 20:48:04.173090000 +0000
@@ -558,6 +558,7 @@
--chmod=CHMOD affect file and/or directory permissions
--acls, -A preserve ACLs (implies --perms)
--xattrs, -X preserve extended attributes
+--file-flags preserve file flags (aka chflags)
--owner, -o preserve owner (super-user only)
--group, -g preserve group
--devices preserve device files (super-user only)
@@ -598,7 +599,10 @@
--ignore-missing-args ignore missing source arguments without error
--delete-missing-args delete missing source arguments from destination
--ignore-errors delete even if there are I/O errors
---force force deletion of directories even if not empty
+--force, --force-delete force deletion of directories even if not empty
+--force-change affect user-/system-immutable files/dirs
+--force-uchange affect user-immutable files/dirs
+--force-schange affect system-immutable files/dirs
--max-delete=NUM don't delete more than NUM files
--max-size=SIZE don't transfer any file larger than SIZE
--min-size=SIZE don't transfer any file smaller than SIZE
@@ -945,6 +949,7 @@
recursion and want to preserve almost everything. Be aware that it does
**not** include preserving ACLs (`-A`), xattrs (`-X`), atimes (`-U`),
crtimes (`-N`), nor the finding and preserving of hardlinks (`-H`).
+ It also does **not** imply [`--file-flags`](#opt).
The only exception to the above equivalence is when [`--files-from`](#opt)
is specified, in which case [`-r`](#opt) is not implied.
@@ -2246,8 +2251,8 @@
[`--ignore-missing-args`](#opt) option a step farther: each missing argument
will become a deletion request of the corresponding destination file on the
receiving side (should it exist). If the destination file is a non-empty
- directory, it will only be successfully deleted if [`--force`](#opt) or
- [`--delete`](#opt) are in effect. Other than that, this option is
+ directory, it will only be successfully deleted if [`--force-delete`](#opt)
+ or [`--delete`](#opt) are in effect. Other than that, this option is
independent of any other type of delete processing.
The missing source files are represented by special file-list entries which
@@ -2258,7 +2263,38 @@
Tells [`--delete`](#opt) to go ahead and delete files even when there are
I/O errors.
-0. `--force`
+0. `--file-flags`
+
+ This option causes rsync to update the file flags to be the same as the
+ source files and directories (if your OS supports the **chflags**(2) system
+ call). Some flags can only be altered by the super-user and some might
+ only be unset below a certain secure-level (usually single-user mode). It
+ will not make files alterable that are set to immutable on the receiver.
+ To do that, see [`--force-change`](#opt), [`--force-uchange`](#opt), and
+ [`--force-schange`](#opt).
+
+0. `--force-change`
+
+ This option causes rsync to disable both user-immutable and
+ system-immutable flags on files and directories that are being updated or
+ deleted on the receiving side. This option overrides
+ [`--force-uchange`](#opt) and [`--force-schange`](#opt)
+
+0. `--force-uchange`
+
+ This option causes rsync to disable user-immutable flags on files and
+ directories that are being updated or deleted on the receiving side. It
+ does not try to affect system flags. This option overrides
+ [`--force-change`](#opt) and [`--force-schange`](#opt).
+
+0. `--force-schange`
+
+ This option causes rsync to disable system-immutable flags on files and
+ directories that are being updated or deleted on the receiving side. It
+ does not try to affect user flags. This option overrides
+ [`--force-change`](#opt) and [`--force-uchange`](#opt).
+
+0. `--force`, `--force-delete`
This option tells rsync to delete a non-empty directory when it is to be
replaced by a non-directory. This is only relevant if deletions are not
@@ -3365,7 +3401,7 @@
but that also turns on the output of other verbose messages.
The "%i" escape has a cryptic output that is 11 letters long. The general
- format is like the string `YXcstpoguax`, where **Y** is replaced by the type
+ format is like the string `YXcstpoguaxf`, where **Y** is replaced by the type
of update being done, **X** is replaced by the file-type, and the other
letters represent attributes that may be output if they are being modified.
--- rsync.1.orig 2026-08-13 00:05:31.000000000 +0000
+++ rsync.1 2026-08-21 21:22:19.276574000 +0000
@@ -1,5 +1,5 @@
-.TH "rsync" "1" "13 Aug 2026" "rsync 3.5.0" "User Commands"
-.\" prefix=/usr
+.TH "rsync" "1" "7 Aug 2026" "rsync 3.5.0" "User Commands"
+.\" prefix=/usr/local
.P
.SH "NAME"
.P
@@ -661,6 +661,7 @@
--chmod=CHMOD affect file and/or directory permissions
--acls, -A preserve ACLs (implies --perms)
--xattrs, -X preserve extended attributes
+--file-flags preserve file flags (aka chflags)
--owner, -o preserve owner (super-user only)
--group, -g preserve group
--devices preserve device files (super-user only)
@@ -701,7 +702,10 @@
--ignore-missing-args ignore missing source arguments without error
--delete-missing-args delete missing source arguments from destination
--ignore-errors delete even if there are I/O errors
---force force deletion of directories even if not empty
+--force, --force-delete force deletion of directories even if not empty
+--force-change affect user-/system-immutable files/dirs
+--force-uchange affect user-immutable files/dirs
+--force-schange affect system-immutable files/dirs
--max-delete=NUM don't delete more than NUM files
--max-size=SIZE don't transfer any file larger than SIZE
--min-size=SIZE don't transfer any file smaller than SIZE
@@ -1035,6 +1039,7 @@
recursion and want to preserve almost everything. Be aware that it does
\fBnot\fP include preserving ACLs (\fB\-A\fP), xattrs (\fB\-X\fP), atimes (\fB\-U\fP),
crtimes (\fB\-N\fP), nor the finding and preserving of hardlinks (\fB\-H\fP).
+It also does \fBnot\fP imply \fB\-\-file\-flags\fP.
.IP
The only exception to the above equivalence is when \fB\-\-files\-from\fP
is specified, in which case \fB\-r\fP is not implied.
@@ -2309,8 +2314,8 @@
\fB\-\-ignore\-missing\-args\fP option a step farther: each missing argument
will become a deletion request of the corresponding destination file on the
receiving side (should it exist). If the destination file is a non-empty
-directory, it will only be successfully deleted if \fB\-\-force\fP or
-\fB\-\-delete\fP are in effect. Other than that, this option is
+directory, it will only be successfully deleted if \fB\-\-force\-delete\fP
+or \fB\-\-delete\fP are in effect. Other than that, this option is
independent of any other type of delete processing.
.IP
The missing source files are represented by special file-list entries which
@@ -2318,7 +2323,30 @@
.IP "\fB\-\-ignore\-errors\fP"
Tells \fB\-\-delete\fP to go ahead and delete files even when there are
I/O errors.
-.IP "\fB\-\-force\fP"
+.IP "\fB\-\-file\-flags\fP"
+This option causes rsync to update the file flags to be the same as the
+source files and directories (if your OS supports the \fBchflags\fP(2) system
+call). Some flags can only be altered by the super-user and some might
+only be unset below a certain secure-level (usually single-user mode). It
+will not make files alterable that are set to immutable on the receiver.
+To do that, see \fB\-\-force\-change\fP, \fB\-\-force\-uchange\fP, and
+\fB\-\-force\-schange\fP.
+.IP "\fB\-\-force\-change\fP"
+This option causes rsync to disable both user-immutable and
+system-immutable flags on files and directories that are being updated or
+deleted on the receiving side. This option overrides
+\fB\-\-force\-uchange\fP and \fB\-\-force\-schange\fP
+.IP "\fB\-\-force\-uchange\fP"
+This option causes rsync to disable user-immutable flags on files and
+directories that are being updated or deleted on the receiving side. It
+does not try to affect system flags. This option overrides
+\fB\-\-force\-change\fP and \fB\-\-force\-schange\fP.
+.IP "\fB\-\-force\-schange\fP"
+This option causes rsync to disable system-immutable flags on files and
+directories that are being updated or deleted on the receiving side. It
+does not try to affect user flags. This option overrides
+\fB\-\-force\-change\fP and \fB\-\-force\-uchange\fP.
+.IP "\fB\-\-force\fP, \fB\-\-force\-delete\fP"
This option tells rsync to delete a non-empty directory when it is to be
replaced by a non-directory. This is only relevant if deletions are not
active (see \fB\-\-delete\fP for details).
@@ -3425,7 +3453,7 @@
but that also turns on the output of other verbose messages.
.IP
The "%i" escape has a cryptic output that is 11 letters long. The general
-format is like the string \fBYXcstpoguax\fP, where \fBY\fP is replaced by the type
+format is like the string \fBYXcstpoguaxf\fP, where \fBY\fP is replaced by the type
of update being done, \fBX\fP is replaced by the file-type, and the other
letters represent attributes that may be output if they are being modified.
.IP
--- rsync.c.orig
+++ rsync.c
@@ -31,6 +31,8 @@
extern int preserve_acls;
extern int preserve_xattrs;
extern int preserve_perms;
+extern int preserve_file_flags;
+extern int force_change;
extern int preserve_executability;
extern int preserve_mtimes;
extern int omit_dir_times;
@@ -486,6 +488,39 @@
return new_mode;
}
+#if defined SUPPORT_FILE_FLAGS || defined SUPPORT_FORCE_CHANGE
+/* Set a file's st_flags. */
+static int set_file_flags(const char *fname, uint32 file_flags)
+{
+ if (do_chflags(fname, file_flags) != 0) {
+ rsyserr(FERROR_XFER, errno,
+ "failed to set file flags on %s",
+ full_fname(fname));
+ return 0;
+ }
+
+ return 1;
+}
+
+/* Remove immutable flags from an object, so it can be altered/removed. */
+int make_mutable(const char *fname, mode_t mode, uint32 file_flags, uint32 iflags)
+{
+ if (S_ISLNK(mode) || !(file_flags & iflags))
+ return 0;
+ if (!set_file_flags(fname, file_flags & ~iflags))
+ return -1;
+ return 1;
+}
+
+/* Undo a prior make_mutable() call that returned a 1. */
+int undo_make_mutable(const char *fname, uint32 file_flags)
+{
+ if (!set_file_flags(fname, file_flags))
+ return -1;
+ return 1;
+}
+#endif
+
static int same_mtime(struct file_struct *file, STRUCT_STAT *st, int extra_accuracy)
{
#ifdef ST_MTIME_NSEC
@@ -676,10 +711,19 @@
if (am_root >= 0) {
uid_t uid = change_uid ? (uid_t)F_OWNER(file) : sxp->st.st_uid;
gid_t gid = change_gid ? (gid_t)F_GROUP(file) : sxp->st.st_gid;
- if ((op_leaf_fd >= 0 ? do_fchown(op_leaf_fd, uid, gid)
- : op_refuse ? (errno = ELOOP, -1)
- : dfd >= 0 ? do_lchown_atfd(dfd, leaf, uid, gid)
- : do_lchown_at(fname, uid, gid)) != 0) {
+ int own_ret = op_leaf_fd >= 0 ? do_fchown(op_leaf_fd, uid, gid)
+ : op_refuse ? (errno = ELOOP, -1)
+ : dfd >= 0 ? do_lchown_atfd(dfd, leaf, uid, gid)
+ : do_lchown_at(fname, uid, gid, sxp->st.st_mode, ST_FLAGS(sxp->st));
+#ifdef SUPPORT_FORCE_CHANGE
+ /* The fd-relative wrappers have no path to chflags(), so an
+ * immutable target fails there with EPERM. Retry through the
+ * full-path wrapper, which carries the force-change logic. */
+ if (own_ret != 0 && force_change && errno == EPERM
+ && !op_refuse && (op_leaf_fd >= 0 || dfd >= 0))
+ own_ret = do_lchown_at(fname, uid, gid, sxp->st.st_mode, ST_FLAGS(sxp->st));
+#endif
+ if (own_ret != 0) {
/* We shouldn't have attempted to change uid
* or gid unless have the privilege. */
rsyserr(FERROR_XFER, errno, "%s %s failed",
@@ -809,7 +853,14 @@
: op_leaf_fd >= 0 ? do_fchmod(op_leaf_fd, new_mode)
: op_refuse ? (errno = ELOOP, -1)
: dfd >= 0 && !S_ISLNK(new_mode) ? do_chmod_atfd(dfd, leaf, new_mode)
- : do_chmod_at(fname, new_mode);
+ : do_chmod_at(fname, new_mode, ST_FLAGS(sxp->st));
+#ifdef SUPPORT_FORCE_CHANGE
+ /* See the chown comment above: retry an fd-relative EPERM through
+ * the full-path wrapper so --force-change can clear the flags. */
+ if (ret < 0 && force_change && errno == EPERM && am_root >= 0
+ && !op_refuse && (op_leaf_fd >= 0 || (dfd >= 0 && !S_ISLNK(new_mode))))
+ ret = do_chmod_at(fname, new_mode, ST_FLAGS(sxp->st));
+#endif
if (ret < 0) {
rsyserr(FERROR_XFER, errno,
"failed to set permissions on %s",
@@ -821,6 +872,19 @@
}
#endif
+#ifdef SUPPORT_FILE_FLAGS
+ if (preserve_file_flags && !S_ISLNK(sxp->st.st_mode)
+ && sxp->st.st_flags != F_FFLAGS(file)) {
+ uint32 file_flags = F_FFLAGS(file);
+ if (flags & ATTRS_DELAY_IMMUTABLE)
+ file_flags &= ~ALL_IMMUTABLE;
+ if (sxp->st.st_flags != file_flags
+ && !set_file_flags(fname, file_flags))
+ goto cleanup;
+ updated = 1;
+ }
+#endif
+
if (INFO_GTE(NAME, 2) && flags & ATTRS_REPORT) {
if (updated)
rprintf(FCLIENT, "%s\n", fname);
@@ -909,7 +973,8 @@
* (in-tree temps keep their held dirfd, so op_pin stays off there). */
operator_path_resolve = 1;
set_file_attrs(fnametmp, file, NULL, fnamecmp,
- ok_to_set_time ? ATTRS_ACCURATE_TIME : ATTRS_SKIP_MTIME | ATTRS_SKIP_ATIME | ATTRS_SKIP_CRTIME);
+ ATTRS_DELAY_IMMUTABLE
+ | (ok_to_set_time ? ATTRS_ACCURATE_TIME : ATTRS_SKIP_MTIME | ATTRS_SKIP_ATIME | ATTRS_SKIP_CRTIME));
operator_path_resolve = 0;
/* move tmp file over real file */
@@ -927,6 +992,10 @@
}
if (ret == 0) {
/* The file was moved into place (not copied), so it's done. */
+#ifdef SUPPORT_FILE_FLAGS
+ if (preserve_file_flags && F_FFLAGS(file) & ALL_IMMUTABLE)
+ set_file_flags(fname, F_FFLAGS(file));
+#endif
return 1;
}
/* The file was copied, so tweak the perms of the copied file. If it
@@ -938,7 +1007,7 @@
ok_to_set_time ? ATTRS_ACCURATE_TIME : ATTRS_SKIP_MTIME | ATTRS_SKIP_ATIME | ATTRS_SKIP_CRTIME);
if (temp_copy_name) {
- if (do_rename_at(fnametmp, fname) < 0) {
+ if (do_rename_at(fnametmp, fname, file->mode, NO_FFLAGS) < 0) {
rsyserr(FERROR_XFER, errno, "rename %s -> \"%s\"",
full_fname(fnametmp), fname);
return 0;
--- rsync.h.orig
+++ rsync.h
@@ -69,7 +69,7 @@
/* The following XMIT flags require an rsync that uses a varint for the flag values */
-#define XMIT_RESERVED_16 (1<<16) /* reserved for future fileflags use */
+#define XMIT_SAME_FLAGS (1<<16) /* any protocol - restricted by command-line option */
#define XMIT_CRTIME_EQ_MTIME (1<<17) /* any protocol - restricted by command-line option */
/* These flags are used in the live flist data. */
@@ -223,6 +223,7 @@
#define ATTRS_SKIP_MTIME (1<<1)
#define ATTRS_ACCURATE_TIME (1<<2)
#define ATTRS_SKIP_ATIME (1<<3)
+#define ATTRS_DELAY_IMMUTABLE (1<<4)
#define ATTRS_SKIP_CRTIME (1<<5)
#define MSG_FLUSH 2
@@ -251,6 +252,7 @@
#define ITEM_REPORT_GROUP (1<<6)
#define ITEM_REPORT_ACL (1<<7)
#define ITEM_REPORT_XATTR (1<<8)
+#define ITEM_REPORT_FFLAGS (1<<9)
#define ITEM_REPORT_CRTIME (1<<10)
#define ITEM_BASIS_TYPE_FOLLOWS (1<<11)
#define ITEM_XNAME_FOLLOWS (1<<12)
@@ -628,6 +630,31 @@
#define SUPPORT_CRTIMES 1
#endif
+#define NO_FFLAGS ((uint32)-1)
+
+#ifdef HAVE_CHFLAGS
+#define SUPPORT_FILE_FLAGS 1
+#define SUPPORT_FORCE_CHANGE 1
+#endif
+
+#if defined SUPPORT_FILE_FLAGS || defined SUPPORT_FORCE_CHANGE
+#ifndef UF_NOUNLINK
+#define UF_NOUNLINK 0
+#endif
+#ifndef SF_NOUNLINK
+#define SF_NOUNLINK 0
+#endif
+#define USR_IMMUTABLE (UF_IMMUTABLE|UF_NOUNLINK|UF_APPEND)
+#define SYS_IMMUTABLE (SF_IMMUTABLE|SF_NOUNLINK|SF_APPEND)
+#define ALL_IMMUTABLE (USR_IMMUTABLE|SYS_IMMUTABLE)
+#define ST_FLAGS(st) ((st).st_flags)
+#else
+#define USR_IMMUTABLE 0
+#define SYS_IMMUTABLE 0
+#define ALL_IMMUTABLE 0
+#define ST_FLAGS(st) NO_FFLAGS
+#endif
+
/* Find a variable that is either exactly 32-bits or longer.
* If some code depends on 32-bit truncation, it will need to
* take special action in a "#if SIZEOF_INT32 > 4" section. */
@@ -861,6 +888,7 @@
extern int depth_ndx;
extern int uid_ndx;
extern int gid_ndx;
+extern int file_flags_ndx;
extern int acls_ndx;
extern int xattrs_ndx;
extern int file_sum_extra_cnt;
@@ -916,6 +944,11 @@
/* When the associated option is on, all entries will have these present: */
#define F_OWNER(f) REQ_EXTRA(f, uid_ndx)->unum
#define F_GROUP(f) REQ_EXTRA(f, gid_ndx)->unum
+#if defined SUPPORT_FILE_FLAGS || defined SUPPORT_FORCE_CHANGE
+#define F_FFLAGS(f) REQ_EXTRA(f, file_flags_ndx)->unum
+#else
+#define F_FFLAGS(f) NO_FFLAGS
+#endif
#define F_ACL(f) REQ_EXTRA(f, acls_ndx)->num
#define F_XATTR(f) REQ_EXTRA(f, xattrs_ndx)->num
#define F_NDX(f) REQ_EXTRA(f, unsort_ndx)->num
--- testsuite/rsyncfns.py.orig
+++ testsuite/rsyncfns.py
@@ -176,9 +176,9 @@
# all_plus -> +++++++++ every attribute changed (an additive create)
# allspace -> every attribute unchanged
# dots -> ..... trailing dots after the change columns
-all_plus = '+++++++++'
-allspace = ' '
-dots = '.....'
+all_plus = '++++++++++'
+allspace = ' '
+dots = '......'
# The "$tmpdir/from", "$tmpdir/to", "$tmpdir/chk" layout from rsync.fns.
TMPDIR = SCRATCHDIR
--- sender.c.orig
+++ sender.c
@@ -25,6 +25,7 @@
extern int do_xfers;
extern int open_noatime;
extern int am_server;
+extern int force_change;
extern int am_daemon;
extern int local_server;
extern int inc_recurse;
@@ -400,7 +401,7 @@
struct file_struct *file;
struct file_list *flist;
STRUCT_STAT st;
- int dfd = -1, secure_errno = 0;
+ int dfd = -1, secure_errno = 0, rm_ret;
if (!remove_source_files)
return;
@@ -450,7 +451,14 @@
return;
}
- if (dfd >= 0 ? secure_remove_source_file(dfd, bname) < 0 : do_unlink(fname) < 0) {
+ rm_ret = dfd >= 0 ? secure_remove_source_file(dfd, bname) : do_unlink(fname);
+#ifdef SUPPORT_FORCE_CHANGE
+ /* The fd-relative wrapper cannot chflags(); retry an immutable source
+ * through do_unlink(), which carries the force-change logic. */
+ if (rm_ret < 0 && dfd >= 0 && force_change && errno == EPERM)
+ rm_ret = do_unlink(fname);
+#endif
+ if (rm_ret < 0) {
failed_op = "remove";
failed:
if (errno == ENOENT)
--- syscall.c.orig
+++ syscall.c
@@ -54,6 +54,7 @@
extern int am_sender;
extern int read_only;
extern int list_only;
+extern int force_change;
extern int inplace;
extern int preallocate_files;
extern int sparse_files;
@@ -641,7 +642,23 @@
{
if (dry_run) return 0;
RETURN_ERROR_IF_RO_OR_LO;
- return unlink(path);
+ if (unlink(path) == 0)
+ return 0;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && errno == EPERM) {
+ STRUCT_STAT st;
+
+ if (do_lstat(path, &st) == 0
+ && make_mutable(path, st.st_mode, st.st_flags, force_change) > 0) {
+ if (unlink(path) == 0)
+ return 0;
+ undo_make_mutable(path, st.st_flags);
+ }
+ /* TODO: handle immutable directories */
+ errno = EPERM;
+ }
+#endif
+ return -1;
}
/*
@@ -678,6 +695,18 @@
return -1;
ret = unlinkat(dfd, bname, 0);
e = errno;
+# ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && e == EPERM) {
+ STRUCT_STAT st;
+ if (do_lstat(path, &st) == 0
+ && make_mutable(path, st.st_mode, st.st_flags, force_change) > 0) {
+ ret = unlinkat(dfd, bname, 0);
+ e = errno;
+ if (ret != 0)
+ undo_make_mutable(path, st.st_flags);
+ }
+ }
+# endif
close(dfd);
errno = e;
return ret;
@@ -709,6 +738,18 @@
ret = unlinkat(dfd, bname, 0);
e = errno;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && e == EPERM) {
+ STRUCT_STAT st;
+ if (do_lstat(path, &st) == 0
+ && make_mutable(path, st.st_mode, st.st_flags, force_change) > 0) {
+ ret = unlinkat(dfd, bname, 0);
+ e = errno;
+ if (ret != 0)
+ undo_make_mutable(path, st.st_flags);
+ }
+ }
+#endif
close(dfd);
errno = e;
return ret;
@@ -1078,7 +1119,7 @@
}
#endif
-int do_lchown(const char *path, uid_t owner, gid_t group)
+int do_lchown(const char *path, uid_t owner, gid_t group, UNUSED(mode_t mode), UNUSED(uint32 file_flags))
{
if (dry_run) return 0;
RETURN_ERROR_IF_RO_OR_LO;
@@ -1086,7 +1127,28 @@
#ifndef HAVE_LCHOWN
#define lchown chown
#endif
- return lchown(path, owner, group);
+ if (lchown(path, owner, group) == 0)
+ return 0;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && errno == EPERM) {
+ if (file_flags == NO_FFLAGS) {
+ STRUCT_STAT st;
+ if (do_lstat(path, &st) == 0) {
+ mode = st.st_mode;
+ file_flags = st.st_flags;
+ }
+ }
+ if (file_flags != NO_FFLAGS
+ && make_mutable(path, mode, file_flags, force_change) > 0) {
+ int ret = lchown(path, owner, group);
+ undo_make_mutable(path, file_flags);
+ if (ret == 0)
+ return 0;
+ }
+ errno = EPERM;
+ }
+#endif
+ return -1;
}
/*
@@ -1103,7 +1165,7 @@
Falls through to do_lchown() in the dry-run / non-daemon / chrooted /
absolute-path / no-parent cases, identical to do_chmod_at().
*/
-int do_lchown_at(const char *fname, uid_t owner, gid_t group)
+int do_lchown_at(const char *fname, uid_t owner, gid_t group, UNUSED(mode_t mode), UNUSED(uint32 file_flags))
{
#if defined AT_FDCWD && defined AT_SYMLINK_NOFOLLOW
extern int am_daemon, am_chrooted;
@@ -1123,12 +1185,29 @@
* fall straight through to the unconfined full-path do_lchown(). */
if (operator_path_resolve && fname && *fname) {
if (symlink_optout_allowed())
- return do_lchown(fname, owner, group);
+ return do_lchown(fname, owner, group, mode, file_flags);
dfd = owner_walk_parent(fname, &bname);
if (dfd < 0)
return -1;
ret = fchownat(dfd, bname, owner, group, AT_SYMLINK_NOFOLLOW);
e = errno;
+# ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && e == EPERM) {
+ if (file_flags == NO_FFLAGS) {
+ STRUCT_STAT st;
+ if (do_lstat(fname, &st) == 0) {
+ mode = st.st_mode;
+ file_flags = st.st_flags;
+ }
+ }
+ if (file_flags != NO_FFLAGS
+ && make_mutable(fname, mode, file_flags, force_change) > 0) {
+ ret = fchownat(dfd, bname, owner, group, AT_SYMLINK_NOFOLLOW);
+ e = errno;
+ undo_make_mutable(fname, file_flags);
+ }
+ }
+# endif
close(dfd);
errno = e;
return ret;
@@ -1136,14 +1215,14 @@
#endif
if (!secure_relpath_active())
- return do_lchown(fname, owner, group);
+ return do_lchown(fname, owner, group, mode, file_flags);
if (!fname || !*fname || *fname == '/')
- return do_lchown(fname, owner, group);
+ return do_lchown(fname, owner, group, mode, file_flags);
slash = strrchr(fname, '/');
if (!slash)
- return do_lchown(fname, owner, group);
+ return do_lchown(fname, owner, group, mode, file_flags);
dlen = slash - fname;
if (dlen >= sizeof dirpath) {
@@ -1160,11 +1239,28 @@
ret = fchownat(dfd, bname, owner, group, AT_SYMLINK_NOFOLLOW);
e = errno;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && e == EPERM) {
+ if (file_flags == NO_FFLAGS) {
+ STRUCT_STAT st;
+ if (do_lstat(fname, &st) == 0) {
+ mode = st.st_mode;
+ file_flags = st.st_flags;
+ }
+ }
+ if (file_flags != NO_FFLAGS
+ && make_mutable(fname, mode, file_flags, force_change) > 0) {
+ ret = fchownat(dfd, bname, owner, group, AT_SYMLINK_NOFOLLOW);
+ e = errno;
+ undo_make_mutable(fname, file_flags);
+ }
+ }
+#endif
close(dfd);
errno = e;
return ret;
#else
- return do_lchown(fname, owner, group);
+ return do_lchown(fname, owner, group, mode, file_flags);
#endif
}
@@ -1215,7 +1311,7 @@
return -1;
close(sock);
#ifdef HAVE_CHMOD
- return do_chmod(pathname, mode);
+ return do_chmod(pathname, mode, 0);
#else
return 0;
#endif
@@ -1391,7 +1487,21 @@
{
if (dry_run) return 0;
RETURN_ERROR_IF_RO_OR_LO;
- return rmdir(pathname);
+ if (rmdir(pathname) == 0)
+ return 0;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && errno == EPERM) {
+ STRUCT_STAT st;
+ if (do_lstat(pathname, &st) == 0
+ && make_mutable(pathname, st.st_mode, st.st_flags, force_change) > 0) {
+ if (rmdir(pathname) == 0)
+ return 0;
+ undo_make_mutable(pathname, st.st_flags);
+ }
+ errno = EPERM;
+ }
+#endif
+ return -1;
}
/*
@@ -1422,6 +1532,18 @@
return -1;
ret = unlinkat(dfd, bname, AT_REMOVEDIR);
e = errno;
+# ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && e == EPERM) {
+ STRUCT_STAT st;
+ if (do_lstat(pathname, &st) == 0
+ && make_mutable(pathname, st.st_mode, st.st_flags, force_change) > 0) {
+ ret = unlinkat(dfd, bname, AT_REMOVEDIR);
+ e = errno;
+ if (ret != 0)
+ undo_make_mutable(pathname, st.st_flags);
+ }
+ }
+# endif
close(dfd);
errno = e;
return ret;
@@ -1453,6 +1575,18 @@
ret = unlinkat(dfd, bname, AT_REMOVEDIR);
e = errno;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && e == EPERM) {
+ STRUCT_STAT st;
+ if (do_lstat(pathname, &st) == 0
+ && make_mutable(pathname, st.st_mode, st.st_flags, force_change) > 0) {
+ ret = unlinkat(dfd, bname, AT_REMOVEDIR);
+ e = errno;
+ if (ret != 0)
+ undo_make_mutable(pathname, st.st_flags);
+ }
+ }
+#endif
close(dfd);
errno = e;
return ret;
@@ -1563,7 +1697,7 @@
}
#ifdef HAVE_CHMOD
-int do_chmod(const char *path, mode_t mode)
+int do_chmod(const char *path, mode_t mode, UNUSED(uint32 file_flags))
{
static int switch_step = 0;
int code;
@@ -1603,6 +1737,23 @@
code = chmod(path, mode & CHMOD_BITS); /* DISCOURAGED FUNCTION */
break;
}
+#ifdef SUPPORT_FORCE_CHANGE
+ if (code < 0 && force_change && errno == EPERM && !S_ISLNK(mode)) {
+ if (file_flags == NO_FFLAGS) {
+ STRUCT_STAT st;
+ if (do_lstat(path, &st) == 0)
+ file_flags = st.st_flags;
+ }
+ if (file_flags != NO_FFLAGS
+ && make_mutable(path, mode, file_flags, force_change) > 0) {
+ code = chmod(path, mode & CHMOD_BITS);
+ undo_make_mutable(path, file_flags);
+ if (code == 0)
+ return 0;
+ }
+ errno = EPERM;
+ }
+#endif
if (code != 0 && (preserve_perms || preserve_executability))
return code;
return 0;
@@ -1767,7 +1918,7 @@
Falls back to do_chmod() for absolute paths and for paths with no parent
component, where there is nothing to protect against.
*/
-int do_chmod_at(const char *fname, mode_t mode)
+int do_chmod_at(const char *fname, mode_t mode, UNUSED(uint32 file_flags))
{
#ifdef AT_FDCWD
extern int am_daemon, am_chrooted;
@@ -1788,12 +1939,27 @@
* S_ISLNK(mode) still needs do_chmod()'s lchmod()/setattrlist() handling. */
if (operator_path_resolve && fname && *fname && !S_ISLNK(mode)) {
if (symlink_optout_allowed())
- return do_chmod(fname, mode);
+ return do_chmod(fname, mode, file_flags);
dfd = owner_walk_parent(fname, &bname);
if (dfd < 0)
return -1;
ret = do_fchmodat_nofollow(dfd, bname, mode);
e = errno;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (ret < 0 && force_change && e == EPERM && !S_ISLNK(mode)) {
+ if (file_flags == NO_FFLAGS) {
+ STRUCT_STAT st;
+ if (do_lstat(fname, &st) == 0)
+ file_flags = st.st_flags;
+ }
+ if (file_flags != NO_FFLAGS
+ && make_mutable(fname, mode, file_flags, force_change) > 0) {
+ ret = do_fchmodat_nofollow(dfd, bname, mode);
+ e = errno;
+ undo_make_mutable(fname, file_flags);
+ }
+ }
+#endif
close(dfd);
errno = e;
return ret;
@@ -1807,14 +1973,14 @@
* already access. Everywhere else, fall through to plain
* do_chmod() to avoid the dirfd-open overhead on every call. */
if (!secure_relpath_active())
- return do_chmod(fname, mode);
+ return do_chmod(fname, mode, file_flags);
if (!fname || !*fname || *fname == '/' || S_ISLNK(mode))
- return do_chmod(fname, mode);
+ return do_chmod(fname, mode, file_flags);
slash = strrchr(fname, '/');
if (!slash)
- return do_chmod(fname, mode);
+ return do_chmod(fname, mode, file_flags);
dlen = slash - fname;
if (dlen >= sizeof dirpath) {
@@ -1831,20 +1997,64 @@
ret = do_fchmodat_nofollow(dfd, bname, mode);
e = errno;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (ret < 0 && force_change && e == EPERM && !S_ISLNK(mode)) {
+ if (file_flags == NO_FFLAGS) {
+ STRUCT_STAT st;
+ if (do_lstat(fname, &st) == 0)
+ file_flags = st.st_flags;
+ }
+ if (file_flags != NO_FFLAGS
+ && make_mutable(fname, mode, file_flags, force_change) > 0) {
+ ret = do_fchmodat_nofollow(dfd, bname, mode);
+ e = errno;
+ undo_make_mutable(fname, file_flags);
+ }
+ }
+#endif
close(dfd);
errno = e;
return ret;
#else
- return do_chmod(fname, mode);
+ return do_chmod(fname, mode, file_flags);
#endif
}
#endif
-int do_rename(const char *old_path, const char *new_path)
+#ifdef HAVE_CHFLAGS
+int do_chflags(const char *path, uint32 file_flags)
{
if (dry_run) return 0;
RETURN_ERROR_IF_RO_OR_LO;
- return rename(old_path, new_path);
+ return chflags(path, file_flags);
+}
+#endif
+
+int do_rename(const char *old_path, const char *new_path, UNUSED(mode_t mode), UNUSED(uint32 file_flags))
+{
+ int ret;
+
+ if (dry_run) return 0;
+ RETURN_ERROR_IF_RO_OR_LO;
+ ret = rename(old_path, new_path);
+#ifdef SUPPORT_FORCE_CHANGE
+ if (ret < 0 && force_change && errno == EPERM) {
+ if (file_flags == NO_FFLAGS) {
+ STRUCT_STAT st;
+ if (do_lstat(new_path, &st) == 0)
+ file_flags = st.st_flags;
+ }
+ if (file_flags != NO_FFLAGS
+ && make_mutable(new_path, mode, file_flags, force_change) > 0) {
+ ret = rename(old_path, new_path);
+ undo_make_mutable(new_path, file_flags);
+ if (ret == 0)
+ return 0;
+ }
+ errno = EPERM;
+ }
+#endif
+ return ret;
}
/*
@@ -1863,7 +2073,7 @@
Falls through to do_rename() in dry-run, non-daemon, chrooted and
absolute-path cases, identical to the other do_*_at() wrappers.
*/
-int do_rename_at(const char *old_path, const char *new_path)
+int do_rename_at(const char *old_path, const char *new_path, UNUSED(mode_t mode), UNUSED(uint32 file_flags))
{
#ifdef AT_FDCWD
extern int am_daemon, am_chrooted;
@@ -1879,10 +2089,10 @@
RETURN_ERROR_IF_RO_OR_LO;
if (!secure_relpath_active())
- return do_rename(old_path, new_path);
+ return do_rename(old_path, new_path, mode, file_flags);
if (!old_path || !*old_path || !new_path || !*new_path)
- return do_rename(old_path, new_path);
+ return do_rename(old_path, new_path, mode, file_flags);
#if defined O_NOFOLLOW && defined O_DIRECTORY
/* Operator-supplied path (e.g. a --backup-dir destination or a --temp-dir
@@ -1890,7 +2100,7 @@
* uid0/euid symlinks, refuse others; absolute and relative alike). */
if (operator_path_resolve) {
if (symlink_optout_allowed())
- return do_rename(old_path, new_path);
+ return do_rename(old_path, new_path, mode, file_flags);
old_dfd = owner_walk_parent(old_path, &old_bname);
if (old_dfd < 0)
return -1;
@@ -1903,6 +2113,21 @@
}
ret = renameat(old_dfd, old_bname, new_dfd, new_bname);
e = errno;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (ret < 0 && force_change && e == EPERM) {
+ if (file_flags == NO_FFLAGS) {
+ STRUCT_STAT st;
+ if (do_lstat(new_path, &st) == 0)
+ file_flags = st.st_flags;
+ }
+ if (file_flags != NO_FFLAGS
+ && make_mutable(new_path, mode, file_flags, force_change) > 0) {
+ ret = renameat(old_dfd, old_bname, new_dfd, new_bname);
+ e = errno;
+ undo_make_mutable(new_path, file_flags);
+ }
+ }
+#endif
close(new_dfd);
close(old_dfd);
errno = e;
@@ -1996,6 +2221,24 @@
ret = renameat(old_dfd, old_bname, new_dfd, new_bname);
e = errno;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (ret < 0 && force_change && e == EPERM) {
+ if (file_flags == NO_FFLAGS) {
+ STRUCT_STAT st;
+ if (do_lstat(new_path, &st) == 0)
+ file_flags = st.st_flags;
+ }
+ if (file_flags != NO_FFLAGS
+ && make_mutable(new_path, mode, file_flags, force_change) > 0) {
+ ret = renameat(old_dfd, old_bname, new_dfd, new_bname);
+ e = errno;
+ undo_make_mutable(new_path, file_flags);
+ if (ret == 0)
+ return 0;
+ }
+ errno = EPERM;
+ }
+#endif
if (new_owns)
close(new_dfd);
if (old_owns)
@@ -2003,7 +2246,7 @@
errno = e;
return ret;
#else
- return do_rename(old_path, new_path);
+ return do_rename(old_path, new_path, mode, file_flags);
#endif
}
--- t_chmod_secure.c.orig
+++ t_chmod_secure.c
@@ -112,26 +112,26 @@
* Solaris, older Cygwin, HPE NonStop, pre-5.6 Linux) -- which now follows
* an in-tree directory symlink whose target is relative and ".."-free.
* Escapes are still rejected on both paths (Scenario B). */
- int rc = do_chmod_at("inside_link/sentinel", 0640);
+ int rc = do_chmod_at("inside_link/sentinel", 0640, 0);
check("A: legit dir-symlink within tree (followed)",
rc, 1, "realdir/sentinel", 0640);
/* Scenario B: parent symlink escapes the tree -- chmod must be
* rejected and the outside file's mode must be unchanged. */
- rc = do_chmod_at("escape_link/sentinel", 0666);
+ rc = do_chmod_at("escape_link/sentinel", 0666, 0);
check("B: parent symlink escapes tree (the attack)",
rc, 0, "../trap/sentinel", 0600);
/* Scenario C: plain relative path with no symlink components,
* regression check that the safe wrapper doesn't break the
* normal case. */
- rc = do_chmod_at("realdir/sentinel", 0644);
+ rc = do_chmod_at("realdir/sentinel", 0644, 0);
check("C: plain relative path (regression check)",
rc, 1, "realdir/sentinel", 0644);
/* Scenario D: top-level file, no parent directory component.
* Falls back to do_chmod(); should succeed. */
- rc = do_chmod_at("topfile", 0640);
+ rc = do_chmod_at("topfile", 0640, 0);
check("D: top-level file, no parent component",
rc, 1, "topfile", 0640);
@@ -141,7 +141,7 @@
* (refused on Linux, lchmod-the-symlink on *BSD/macOS), so assert only that
* the outside target's mode is unchanged. */
if (leaf_chmod_nofollow_supported()) {
- rc = do_chmod_at("realdir/leaflink", 0666);
+ rc = do_chmod_at("realdir/leaflink", 0666, 0);
check("E: leaf component is an escaping symlink (must not be followed)",
rc, -1, "../trap/sentinel", 0600);
} else {
--- t_rename_secure.c.orig
+++ t_rename_secure.c
@@ -30,14 +30,14 @@
if (!old_path || !*old_path || *old_path == '/'
|| !new_path || !*new_path || *new_path == '/')
- return do_rename(old_path, new_path);
+ return do_rename(old_path, new_path, 0, NO_FFLAGS);
old_slash = strrchr(old_path, '/');
new_slash = strrchr(new_path, '/');
if (!old_slash || !new_slash)
- return do_rename(old_path, new_path);
+ return do_rename(old_path, new_path, 0, NO_FFLAGS);
- return do_rename_at(old_path, new_path);
+ return do_rename_at(old_path, new_path, 0, NO_FFLAGS);
}
#endif
@@ -64,7 +64,7 @@
int saved_errno;
errno = 0;
- rc = do_rename_at(old_path, new_path);
+ rc = do_rename_at(old_path, new_path, 0, NO_FFLAGS);
saved_errno = errno;
got_ok = rc == 0;
--- t_stub.c.orig
+++ t_stub.c
@@ -32,7 +32,9 @@
int protect_args = 0;
int module_id = -1;
int relative_paths = 0;
+int force_change = 0;
unsigned int module_dirlen = 0;
+int preserve_acls = 0;
int preserve_xattrs = 0;
int preserve_perms = 0;
int preserve_executability = 0;
@@ -130,3 +132,23 @@
{
return cst ? 0 : 0;
}
+
+#if defined SUPPORT_FILE_FLAGS || defined SUPPORT_FORCE_CHANGE
+ int make_mutable(UNUSED(const char *fname), UNUSED(mode_t mode), UNUSED(uint32 file_flags), UNUSED(uint32 iflags))
+{
+ return 0;
+}
+
+/* Undo a prior make_mutable() call that returned a 1. */
+ int undo_make_mutable(UNUSED(const char *fname), UNUSED(uint32 file_flags))
+{
+ return 0;
+}
+#endif
+
+#ifdef SUPPORT_XATTRS
+ int x_lstat(UNUSED(const char *fname), UNUSED(STRUCT_STAT *fst), UNUSED(STRUCT_STAT *xst))
+{
+ return -1;
+}
+#endif
--- usage.c.orig
+++ usage.c
@@ -156,6 +156,11 @@
#endif
"crtimes",
+#ifndef SUPPORT_FILE_FLAGS
+ "no "
+#endif
+ "file-flags",
+
"*Optimizations",
#ifndef USE_ROLL_SIMD
--- util1.c.orig
+++ util1.c
@@ -32,6 +32,7 @@
extern int modify_window;
extern int relative_paths;
extern int preserve_xattrs;
+extern int force_change;
extern int omit_link_times;
extern int preallocate_files;
extern int operator_path_resolve;
@@ -117,6 +118,33 @@
rprintf(FCLIENT, " (%d args)\n", cnt);
}
+#ifdef SUPPORT_FORCE_CHANGE
+static int try_a_force_change(const char *fname, STRUCT_STAT *stp)
+{
+ uint32 file_flags = ST_FLAGS(*stp);
+ if (file_flags == NO_FFLAGS) {
+ STRUCT_STAT st;
+ if (x_lstat(fname, &st, NULL) == 0)
+ file_flags = st.st_flags;
+ }
+ if (file_flags != NO_FFLAGS && make_mutable(fname, stp->st_mode, file_flags, force_change) > 0) {
+ int ret, save_force_change = force_change;
+
+ force_change = 0; /* Make certain we can't come back here. */
+ ret = set_times(fname, stp);
+ force_change = save_force_change;
+
+ undo_make_mutable(fname, file_flags);
+
+ return ret;
+ }
+
+ errno = EPERM;
+
+ return -1;
+}
+#endif
+
/* This returns 0 for success, 1 for a symlink if symlink time-setting
* is not possible, or -1 for any other error. */
int set_times(const char *fname, STRUCT_STAT *stp)
@@ -144,6 +172,10 @@
#include "case_N.h"
if (do_utimensat_at(fname, stp) == 0)
break;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && errno == EPERM && try_a_force_change(fname, stp) == 0)
+ break;
+#endif
if (errno != ENOSYS)
return -1;
switch_step++;
@@ -153,6 +185,10 @@
#include "case_N.h"
if (do_lutimes(fname, stp) == 0)
break;
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && errno == EPERM && try_a_force_change(fname, stp) == 0)
+ break;
+#endif
if (errno != ENOSYS)
return -1;
switch_step++;
@@ -174,6 +210,10 @@
if (do_utime(fname, stp) == 0)
break;
#endif
+#ifdef SUPPORT_FORCE_CHANGE
+ if (force_change && errno == EPERM && try_a_force_change(fname, stp) == 0)
+ break;
+#endif
return -1;
}
@@ -581,7 +621,7 @@
}
/* maybe we should return rename()'s exit status? Nah. */
- if (do_rename_at(fname, path) != 0) {
+ if (do_rename_at(fname, path, 0, NO_FFLAGS) != 0) {
errno = ETXTBSY;
return -1;
}
@@ -613,8 +653,14 @@
const char *os = strrchr(from, '/');
const char *ns = strrchr(to, '/');
rr = do_rename_atfd(ofd, os ? os + 1 : from, nfd, ns ? ns + 1 : to);
+#ifdef SUPPORT_FORCE_CHANGE
+ /* The fd-relative wrapper cannot chflags(); retry an
+ * immutable destination via the full-path wrapper. */
+ if (rr < 0 && force_change && errno == EPERM)
+ rr = do_rename_at(from, to, 0, NO_FFLAGS);
+#endif
} else
- rr = do_rename_at(from, to);
+ rr = do_rename_at(from, to, 0, NO_FFLAGS);
if (rr == 0)
return 0;
--- xattrs.c.orig
+++ xattrs.c
@@ -1154,7 +1154,7 @@
#endif
&& access(fname, W_OK) < 0
&& (fd >= 0 ? fchmod(fd, (sxp->st.st_mode & CHMOD_BITS) | S_IWUSR)
- : do_chmod_at(fname, (sxp->st.st_mode & CHMOD_BITS) | S_IWUSR)) == 0)
+ : do_chmod_at(fname, (sxp->st.st_mode & CHMOD_BITS) | S_IWUSR, ST_FLAGS(sxp->st))) == 0)
added_write_perm = 1;
ndx = F_XATTR(file);
@@ -1166,7 +1166,7 @@
if (fd >= 0)
fchmod(fd, sxp->st.st_mode);
else
- do_chmod_at(fname, sxp->st.st_mode);
+ do_chmod_at(fname, sxp->st.st_mode, ST_FLAGS(sxp->st));
}
return 0;
}
@@ -1177,7 +1177,7 @@
if (fd >= 0)
fchmod(fd, sxp->st.st_mode);
else
- do_chmod_at(fname, sxp->st.st_mode);
+ do_chmod_at(fname, sxp->st.st_mode, ST_FLAGS(sxp->st));
}
return return_value;
}
@@ -1317,7 +1317,7 @@
if (fd >= 0)
fchmod(fd, mode);
else
- do_chmod_at(fname, mode);
+ do_chmod_at(fname, mode, ST_FLAGS(fst));
}
if (!IS_DEVICE(fst.st_mode))
fst.st_rdev = 0; /* just in case */