1 CAUTION: This patch compiles, but is otherwise totally untested!
3 This patch also implements --times-only.
5 Implementation details for the --source-filter and -dest-filter options:
7 - These options open a *HUGE* security hole in daemon mode unless they
8 are refused in your rsyncd.conf!
10 - Filtering disables rsync alogrithm. (This should be fixed.)
12 - Source filter makes temporary files in /tmp. (Should be overridable.)
14 - If source filter fails, data is send unfiltered. (Should be changed
17 - Failure of destination filter, causes data loss!!! (Should be changed
20 - If filter changes size of file, you should use --times-only option to
21 prevent repeated transfers of unchanged files.
23 - If the COMMAND contains single quotes, option-passing breaks. (Needs
26 To use this patch, run these commands for a successful build:
28 patch -p1 <patches/source-filter_dest-filter.diff
30 ./configure (optional if already run)
33 diff --git a/generator.c b/generator.c
34 index 12007a1..88bd5e7 100644
37 @@ -64,6 +64,7 @@ extern int append_mode;
38 extern int make_backups;
39 extern int csum_length;
40 extern int ignore_times;
41 +extern int times_only;
43 extern OFF_T max_size;
44 extern OFF_T min_size;
45 @@ -524,7 +525,7 @@ void itemize(const char *fnamecmp, struct file_struct *file, int ndx, int statre
46 /* Perform our quick-check heuristic for determining if a file is unchanged. */
47 int unchanged_file(char *fn, struct file_struct *file, STRUCT_STAT *st)
49 - if (st->st_size != F_LENGTH(file))
50 + if (!times_only && st->st_size != F_LENGTH(file))
53 /* if always checksum is set then we use the checksum instead
54 diff --git a/main.c b/main.c
55 index 2ef2f47..e7b4a05 100644
58 @@ -140,7 +140,7 @@ pid_t wait_process(pid_t pid, int *status_ptr, int flags)
61 /* Wait for a process to exit, calling io_flush while waiting. */
62 -static void wait_process_with_flush(pid_t pid, int *exit_code_ptr)
63 +void wait_process_with_flush(pid_t pid, int *exit_code_ptr)
67 diff --git a/options.c b/options.c
68 index e7c6c61..059bcbf 100644
71 @@ -105,6 +105,7 @@ int safe_symlinks = 0;
72 int copy_unsafe_links = 0;
73 int munge_symlinks = 0;
76 int daemon_bwlimit = 0;
79 @@ -164,6 +165,8 @@ char *logfile_name = NULL;
80 char *logfile_format = NULL;
81 char *stdout_format = NULL;
82 char *password_file = NULL;
83 +char *source_filter = NULL;
84 +char *dest_filter = NULL;
85 char *rsync_path = RSYNC_PATH;
86 char *backup_dir = NULL;
87 char backup_dir_buf[MAXPATHLEN];
88 @@ -739,6 +742,7 @@ void usage(enum logcode F)
89 rprintf(F," -I, --ignore-times don't skip files that match in size and mod-time\n");
90 rprintf(F," -M, --remote-option=OPTION send OPTION to the remote side only\n");
91 rprintf(F," --size-only skip files that match in size\n");
92 + rprintf(F," --times-only skip files that match in mod-time\n");
93 rprintf(F," --modify-window=NUM compare mod-times with reduced accuracy\n");
94 rprintf(F," -T, --temp-dir=DIR create temporary files in directory DIR\n");
95 rprintf(F," -y, --fuzzy find similar file for basis if no dest file\n");
96 @@ -778,6 +782,8 @@ void usage(enum logcode F)
97 rprintf(F," --write-batch=FILE write a batched update to FILE\n");
98 rprintf(F," --only-write-batch=FILE like --write-batch but w/o updating destination\n");
99 rprintf(F," --read-batch=FILE read a batched update from FILE\n");
100 + rprintf(F," --source-filter=COMMAND filter file through COMMAND at source\n");
101 + rprintf(F," --dest-filter=COMMAND filter file through COMMAND at destination\n");
102 rprintf(F," --protocol=NUM force an older protocol version to be used\n");
104 rprintf(F," --iconv=CONVERT_SPEC request charset conversion of filenames\n");
105 @@ -887,6 +893,7 @@ static struct poptOption long_options[] = {
106 {"chmod", 0, POPT_ARG_STRING, 0, OPT_CHMOD, 0, 0 },
107 {"ignore-times", 'I', POPT_ARG_NONE, &ignore_times, 0, 0, 0 },
108 {"size-only", 0, POPT_ARG_NONE, &size_only, 0, 0, 0 },
109 + {"times-only", 0, POPT_ARG_NONE, ×_only , 0, 0, 0 },
110 {"one-file-system", 'x', POPT_ARG_NONE, 0, 'x', 0, 0 },
111 {"no-one-file-system",'x',POPT_ARG_VAL, &one_file_system, 0, 0, 0 },
112 {"no-x", 'x', POPT_ARG_VAL, &one_file_system, 0, 0, 0 },
113 @@ -1007,6 +1014,8 @@ static struct poptOption long_options[] = {
114 {"password-file", 0, POPT_ARG_STRING, &password_file, 0, 0, 0 },
115 {"blocking-io", 0, POPT_ARG_VAL, &blocking_io, 1, 0, 0 },
116 {"no-blocking-io", 0, POPT_ARG_VAL, &blocking_io, 0, 0, 0 },
117 + {"source-filter", 0, POPT_ARG_STRING, &source_filter, 0, 0, 0 },
118 + {"dest-filter", 0, POPT_ARG_STRING, &dest_filter, 0, 0, 0 },
119 {"remote-option", 'M', POPT_ARG_STRING, 0, 'M', 0, 0 },
120 {"protocol", 0, POPT_ARG_INT, &protocol_version, 0, 0, 0 },
121 {"checksum-seed", 0, POPT_ARG_INT, &checksum_seed, 0, 0, 0 },
122 @@ -2149,6 +2158,16 @@ int parse_arguments(int *argc_p, const char ***argv_p)
126 + if (source_filter || dest_filter) {
127 + if (whole_file == 0) {
128 + snprintf(err_buf, sizeof err_buf,
129 + "--no-whole-file cannot be used with --%s-filter\n",
130 + source_filter ? "source" : "dest");
139 @@ -2493,6 +2512,25 @@ void server_options(char **args, int *argc_p)
140 else if (missing_args == 1 && !am_sender)
141 args[ac++] = "--ignore-missing-args";
143 + if (times_only && am_sender)
144 + args[ac++] = "--times-only";
146 + if (source_filter && !am_sender) {
147 + /* Need to single quote the arg to keep the remote shell
148 + * from splitting it. FIXME: breaks if command has single quotes. */
149 + if (asprintf(&arg, "--source-filter='%s'", source_filter) < 0)
154 + if (dest_filter && am_sender) {
155 + /* Need to single quote the arg to keep the remote shell
156 + * from splitting it. FIXME: breaks if command has single quotes. */
157 + if (asprintf(&arg, "--dest-filter='%s'", dest_filter) < 0)
162 if (modify_window_set) {
163 if (asprintf(&arg, "--modify-window=%d", modify_window) < 0)
165 diff --git a/pipe.c b/pipe.c
166 index a33117c..43eea31 100644
169 @@ -180,3 +180,77 @@ pid_t local_child(int argc, char **argv, int *f_in, int *f_out,
174 +pid_t run_filter(char *command[], int out, int *pipe_to_filter)
179 + if (DEBUG_GTE(CMD, 1))
180 + print_child_argv("opening connection using:", command);
182 + if (pipe(pipefds) < 0) {
183 + rsyserr(FERROR, errno, "pipe");
184 + exit_cleanup(RERR_IPC);
189 + rsyserr(FERROR, errno, "fork");
190 + exit_cleanup(RERR_IPC);
194 + if (dup2(pipefds[0], STDIN_FILENO) < 0
195 + || close(pipefds[1]) < 0
196 + || dup2(out, STDOUT_FILENO) < 0) {
197 + rsyserr(FERROR, errno, "Failed dup/close");
198 + exit_cleanup(RERR_IPC);
201 + set_blocking(STDIN_FILENO);
203 + set_blocking(STDOUT_FILENO);
204 + execvp(command[0], command);
205 + rsyserr(FERROR, errno, "Failed to exec %s", command[0]);
206 + exit_cleanup(RERR_IPC);
209 + if (close(pipefds[0]) < 0) {
210 + rsyserr(FERROR, errno, "Failed to close");
211 + exit_cleanup(RERR_IPC);
214 + *pipe_to_filter = pipefds[1];
219 +pid_t run_filter_on_file(char *command[], int out, int in)
223 + if (DEBUG_GTE(CMD, 1))
224 + print_child_argv("opening connection using:", command);
228 + rsyserr(FERROR, errno, "fork");
229 + exit_cleanup(RERR_IPC);
233 + if (dup2(in, STDIN_FILENO) < 0
234 + || dup2(out, STDOUT_FILENO) < 0) {
235 + rsyserr(FERROR, errno, "Failed to dup2");
236 + exit_cleanup(RERR_IPC);
239 + set_blocking(STDOUT_FILENO);
240 + execvp(command[0], command);
241 + rsyserr(FERROR, errno, "Failed to exec %s", command[0]);
242 + exit_cleanup(RERR_IPC);
247 diff --git a/receiver.c b/receiver.c
248 index 4325e30..e5ede73 100644
251 @@ -52,6 +52,7 @@ extern int delay_updates;
252 extern mode_t orig_umask;
253 extern struct stats stats;
255 +extern char *dest_filter;
256 extern char *partial_dir;
257 extern char *basis_dir[MAX_BASIS_DIRS+1];
258 extern char sender_file_sum[MAX_DIGEST_LEN];
259 @@ -441,6 +442,8 @@ int recv_files(int f_in, char *local_name)
260 const char *parent_dirname = "";
264 + char *filter_argv[MAX_FILTER_ARGS + 1];
266 if (DEBUG_GTE(RECV, 1))
267 rprintf(FINFO, "recv_files(%d) starting\n", cur_flist->used);
268 @@ -448,6 +451,23 @@ int recv_files(int f_in, char *local_name)
270 delayed_bits = bitbag_create(cur_flist->used + 1);
276 + for (p = strtok(dest_filter, sep), i = 0;
277 + p && i < MAX_FILTER_ARGS;
278 + p = strtok(0, sep))
279 + filter_argv[i++] = p;
280 + filter_argv[i] = NULL;
283 + "Too many arguments to dest-filter (> %d)\n",
285 + exit_cleanup(RERR_SYNTAX);
292 @@ -742,6 +762,9 @@ int recv_files(int f_in, char *local_name)
293 else if (!am_server && INFO_GTE(NAME, 1) && INFO_EQ(PROGRESS, 1))
294 rprintf(FINFO, "%s\n", fname);
297 + pid = run_filter(filter_argv, fd2, &fd2);
300 recv_ok = receive_data(f_in, fnamecmp, fd1, st.st_size,
301 fname, fd2, F_LENGTH(file));
302 @@ -756,6 +779,16 @@ int recv_files(int f_in, char *local_name)
303 exit_cleanup(RERR_FILEIO);
308 + wait_process_with_flush(pid, &status);
310 + rprintf(FERROR, "filter %s exited code: %d\n",
311 + dest_filter, status);
316 if ((recv_ok && (!delay_updates || !partialptr)) || inplace) {
317 if (partialptr == fname)
319 diff --git a/rsync.h b/rsync.h
320 index be7cf8a..8d78818 100644
324 #define IOERR_DEL_LIMIT (1<<2)
326 #define MAX_ARGS 1000
327 +#define MAX_FILTER_ARGS 100
328 #define MAX_BASIS_DIRS 20
329 #define MAX_SERVER_ARGS (MAX_BASIS_DIRS*2 + 100)
331 diff --git a/rsync.yo b/rsync.yo
332 index 941f7a5..edfad5e 100644
335 @@ -394,6 +394,7 @@ to the detailed description below for a complete description. verb(
336 --contimeout=SECONDS set daemon connection timeout in seconds
337 -I, --ignore-times don't skip files that match size and time
338 --size-only skip files that match in size
339 + --times-only skip files that match in mod-time
340 --modify-window=NUM compare mod-times with reduced accuracy
341 -T, --temp-dir=DIR create temporary files in directory DIR
342 -y, --fuzzy find similar file for basis if no dest file
343 @@ -434,6 +435,8 @@ to the detailed description below for a complete description. verb(
344 --write-batch=FILE write a batched update to FILE
345 --only-write-batch=FILE like --write-batch but w/o updating dest
346 --read-batch=FILE read a batched update from FILE
347 + --source-filter=COMMAND filter file through COMMAND at source
348 + --dest-filter=COMMAND filter file through COMMAND at destination
349 --protocol=NUM force an older protocol version to be used
350 --iconv=CONVERT_SPEC request charset conversion of filenames
351 --checksum-seed=NUM set block/file checksum seed (advanced)
352 @@ -2256,6 +2259,33 @@ file previously generated by bf(--write-batch).
353 If em(FILE) is bf(-), the batch data will be read from standard input.
354 See the "BATCH MODE" section for details.
356 +dit(bf(--source-filter=COMMAND)) This option allows the user to specify a
357 +filter program that will be applied to the contents of all transferred
358 +regular files before the data is sent to destination. COMMAND will receive
359 +the data on its standard input and it should write the filtered data to
360 +standard output. COMMAND should exit non-zero if it cannot process the
361 +data or if it encounters an error when writing the data to stdout.
363 +Example: --source-filter="gzip -9" will cause remote files to be
365 +Use of --source-filter automatically enables --whole-file.
366 +If your filter does not output the same number of bytes that it received on
367 +input, you should use --times-only to disable size and content checks on
368 +subsequent rsync runs.
370 +dit(bf(--dest-filter=COMMAND)) This option allows you to specify a filter
371 +program that will be applied to the contents of all transferred regular
372 +files before the data is written to disk. COMMAND will receive the data on
373 +its standard input and it should write the filtered data to standard
374 +output. COMMAND should exit non-zero if it cannot process the data or if
375 +it encounters an error when writing the data to stdout.
377 +Example: --dest-filter="gzip -9" will cause remote files to be compressed.
378 +Use of --dest-filter automatically enables --whole-file.
379 +If your filter does not output the same number of bytes that it
380 +received on input, you should use --times-only to disable size and
381 +content checks on subsequent rsync runs.
383 dit(bf(--protocol=NUM)) Force an older protocol version to be used. This
384 is useful for creating a batch file that is compatible with an older
385 version of rsync. For instance, if rsync 2.6.4 is being used with the
386 diff --git a/sender.c b/sender.c
387 index bf8221d..f315f80 100644
390 @@ -42,6 +42,7 @@ extern int make_backups;
393 extern int write_batch;
394 +extern char *source_filter;
395 extern struct stats stats;
396 extern struct file_list *cur_flist, *first_flist, *dir_flist;
398 @@ -174,6 +175,26 @@ void send_files(int f_in, int f_out)
399 enum logcode log_code = log_before_transfer ? FLOG : FINFO;
400 int f_xfer = write_batch < 0 ? batch_fd : f_out;
402 + char *filter_argv[MAX_FILTER_ARGS + 1];
404 + int unlink_tmp = 0;
406 + if (source_filter) {
410 + for (p = strtok(source_filter, sep), i = 0;
411 + p && i < MAX_FILTER_ARGS;
412 + p = strtok(0, sep))
413 + filter_argv[i++] = p;
414 + filter_argv[i] = NULL;
417 + "Too many arguments to source-filter (> %d)\n",
419 + exit_cleanup(RERR_SYNTAX);
423 if (DEBUG_GTE(SEND, 1))
424 rprintf(FINFO, "send_files starting\n");
425 @@ -299,6 +320,7 @@ void send_files(int f_in, int f_out)
426 exit_cleanup(RERR_PROTOCOL);
430 fd = do_open(fname, O_RDONLY, 0);
432 if (errno == ENOENT) {
433 @@ -320,6 +342,33 @@ void send_files(int f_in, int f_out)
437 + if (source_filter) {
439 + char *tmpl = "/tmp/rsync-filtered_sourceXXXXXX";
441 + tmp = strdup(tmpl);
442 + fd2 = mkstemp(tmp);
444 + rprintf(FERROR, "mkstemp %s failed: %s\n",
445 + tmp, strerror(errno));
448 + pid_t pid = run_filter_on_file(filter_argv, fd2, fd);
451 + wait_process_with_flush(pid, &status);
454 + "bypassing source filter %s; exited with code: %d\n",
455 + source_filter, status);
456 + fd = do_open(fname, O_RDONLY, 0);
458 + fd = do_open(tmp, O_RDONLY, 0);
464 /* map the local file */
465 if (do_fstat(fd, &st) != 0) {
466 io_error |= IOERR_GENERAL;
467 @@ -370,6 +419,8 @@ void send_files(int f_in, int f_out)