Mention the security fix.
[rsync/rsync.git] / NEWS
CommitLineData
03a9ca0a
WD
1NEWS for rsync 2.6.3 (UNRELEASED)
2Protocol: 28 (unchanged)
3Changes since 2.6.2:
4
8fb7db24
WD
5 SECURITY FIXES:
6
7 - A bug in the sanitize_path routine (which affects a non-chrooted
8 rsync daemon) could allow a user to specify an absolute path for
9 certain options (but not for file-transfer names). If you're running
10 a rsync daemon with chroot disabled, *please upgrade*, ESPECIALLY if
11 the user privs you run rsync under is anything above "nobody".
12
f6c0d3d7
WD
13 OUTPUT CHANGES (ATTN: those using a script to parse the verbose output):
14
15 - Please note that the 2-line footer (output when verbose) now uses the
16 term "sent" instead of "wrote" and "received" instead of "read". If
17 you are not parsing the numeric values out of this footer, a script
82c6be7e 18 would be better off using the empty line prior to the footer as the
f6c0d3d7 19 indicator that the verbose output is over.
446a2987 20
f6c0d3d7
WD
21 - The output from the --stats option was similarly affected to change
22 "written" to "sent" and "read" to "received".
23
82c6be7e
WD
24 - Rsync ensures that a filename that contains a newline gets mentioned
25 with each newline transformed into a question mark (which prevents a
26 filename from causing an empty line to be output).
446a2987 27
03a9ca0a
WD
28 BUG FIXES:
29
831f05df
WD
30 - Fixed a crash bug that might appear when --delete was used and
31 multiple source directories were specified.
03a9ca0a 32
c7b1a56b
WD
33 - Fixed the 32-bit truncation of the file length when generating the
34 checksums.
35
03a9ca0a
WD
36 - The --backup code no longer attempts to create some directories
37 over and over again (generating warnings along the way).
38
cbd85b47
WD
39 - Fixed a bug in the reading of the secrets file (by the daemon) and
40 the password file (by the client): the files no longer need to be
41 terminated by a newline for their content to be read in.
03a9ca0a 42
99d24f77
WD
43 - If a file has a read error on the sending side or the reconstructed
44 data doesn't match the expected checksum (perhaps due to the basis
45 file changing during the transfer), the receiver will no longer
46 retain the resulting file unless the --partial option was specified.
47 (Note: for the read-error detection to work, neither side can be
48 older than 2.6.3 -- older receivers will always retain the file, and
49 older senders don't tell the receiver that the file had a read
50 error.)
03a9ca0a 51
c54f5170 52 - If a file gets resent in a single transfer and the --backup option
82c6be7e
WD
53 is enabled, rsync no longer performs a duplicate backup (it used to
54 overwrite the original file in the backup area).
03a9ca0a 55
cbd85b47 56 - Files specified in the daemon's "exclude" or "exclude from" config
bd1574b2
WD
57 items are now excluded from being uploaded (assuming that the module
58 allows uploading at all) in addition to the old download exclusion.
cbd85b47 59
40e8d11e
WD
60 - Got rid of a potential hang in the receiver when near the end of a
61 phase.
62
b03bded7
WD
63 - When using --backup without a --backup-dir, rsync no longer preserves
64 the modify time on directories. This avoids confusing NFS.
65
40e8d11e
WD
66 - When --copy-links (-L) is specified, we now output a separate error
67 for a symlink that has no referent instead of claiming that a file
68 "vanished".
69
f6c0d3d7
WD
70 - The --copy-links (-L) option no longer has the side-effect of telling
71 the receiving side to follow symlinks. See the --keep-dirlinks
72 option (mentioned below) for a way to specify that behavior.
73
2c2898a3
WD
74 - Error messages from the daemon server's option-parsing (such as
75 refused options) now get sent back to the client (the server used
eae4e1f9
WD
76 to just exit because the socket wasn't in the right state to send
77 the message).
2c2898a3 78
c54f5170
WD
79 - Most errors that occur during a daemon transfer are now returned to
80 the user in addition to being logged (some messages are intended to
81 be daemon-only).
82
b03bded7
WD
83 - Fixed a bug in the daemon authentication code when using one of the
84 batch-processing options.
85
40564811
WD
86 - We try to work around some buggy IPv6 implementations that fail to
87 implement IPV6_V6ONLY. This should fix the "address in use" error
88 that some daemons get when running on an OS with a buggy IPv6
89 implementation. Also, if the new code gets this error, we might
90 suggest that the user specify --ipv4 or --ipv6 (if we think it will
91 help).
92
65af3dab 93 - When the remote rsync dies, make a better effort to recover any error
86e2f445
WD
94 messages it may have sent before dying (the local rsync used to just
95 die with a socket-write error).
65af3dab
WD
96
97 - When using --delete and a --backup-dir that contains files that are
98 hard-linked to their destination equivalents, rsync now makes sure
99 that removed files really get removed (works around a really weird
100 rename() behavior).
101
102 - Avoid a bogus run-time complaint about a lack of 64-bit integers when
99d24f77 103 the int64 type is defined as an off_t and it actually has 64-bits.
65af3dab 104
00735149
WD
105 - Added a configure check for open64() without mkstemp64() so that we
106 can avoid using mkstemp() when such a combination is encountered.
107 This bypasses a problem writing out large temp files on OSes such as
108 AIX and HP-UX.
109
82c6be7e
WD
110 - Fixed an age-old crash problem with --read-batch on a local copy
111 (rsync was improperly assuming --whole-file for the local copy).
112
113 - When --dry-run (-n) is used and the destination directory does not
114 exist, rsync now produces a correct report of files that would be
115 sent instead of dying with a chdir() error.
116
03a9ca0a
WD
117 ENHANCEMENTS:
118
65af3dab
WD
119 - Added the --partial-dir=DIR option that lets you specify where to
120 (temporarily) put a partially transferred file (instead of over-
121 writing the destination file). E.g. --partial-dir=.rsync-partial
122
40e8d11e 123 - Added --keep-dirlinks (-K), which allows you to symlink a directory
40564811 124 onto another partition on the receiving side and have rsync treat it
4e1f3857
WD
125 as matching a normal directory from the sender.
126
61fb21ad
WD
127 - Added the --inplace option that tells rsync to write each destination
128 file without using a temporary file. The matching of existing data
129 in the destination file can be severely limited by this, but there
99d24f77
WD
130 are also cases where this is more efficient (such as appending data).
131 Use only when needed (see the man page for more details).
61fb21ad 132
86e2f445 133 - Added the "write only" option for the daemon's config file.
cbd85b47 134
03a9ca0a 135 - Added long-option names for -4 and -6 (namely --ipv4 and --ipv6)
831f05df 136 and documented all these options in the man page.
03a9ca0a 137
ef0bc0ab
WD
138 - Improved the handling of the --bwlimit option so that it's less
139 bursty, more accurate, and works properly over a larger range of
140 values.
141
5b36173d
WD
142 - The rsync daemon-over-ssh code now looks for SSH_CONNECTION and
143 SSH2_CLIENT in addition to SSH_CLIENT to figure out the IP address.
144
bd1574b2
WD
145 - Added the --checksum-seed=N option for advanced users.
146
bb3edc3b
WD
147 - Batch writing/reading has a brand-new implementation that is simpler,
148 fixes a few weird problems with the old code (such as no longer
149 sprinkling the batch files into different dirs or even onto different
150 systems), and is much less intrusive into the code (making it easier
151 to maintain for the future). The new code generates just one data
152 file instead of three, which makes it possible to read the batch via
82c6be7e
WD
153 stdin over a remote shell. Also, the old requirement of forcing the
154 same fixed checksum-seed for all batch processing has been removed.
0fac7fe8 155
99d24f77
WD
156 - If an rsync daemon has a module set with "list = no" (which hides its
157 presence in the list of available modules), a user that fails to
158 authenticate gets the same "unknown module" error that they would get
159 if the module were actually unknown (while still logging the real
86e2f445 160 error to the daemon's log file). This prevents fishing for module
99d24f77
WD
161 names.
162
86e2f445
WD
163 - The daemon's "refuse options" config item now allows you to match
164 option names using wildcards and/or the single-letter option names.
165
c16d69b2 166 - The finished file now gets its permissions and modified-time updated
82c6be7e
WD
167 before it gets moved into place.
168
03a9ca0a
WD
169 INTERNAL:
170
0058c58e
WD
171 - Some cleanup in the exclude code has saved some per-exclude memory
172 and made the code easier to maintain.
03a9ca0a 173
82c6be7e
WD
174 - Improved the argv-overflow checking for a remote command that has a
175 lot of args.
78112d30 176
82c6be7e
WD
177 - Use rsyserr() in the various places that were still calling rprintf()
178 with strerror() as an arg.
03a9ca0a 179
c54f5170
WD
180 - If an rsync daemon is listening on multiple sockets (to handle both
181 IPv4 and IPv6 to a single port), we now close all the unneeded file
40564811 182 handles after we accept a connection (we used to close just one of
c54f5170
WD
183 them).
184
82c6be7e
WD
185 - Optimized the handling of larger block sizes (rsync used to slow to a
186 crawl if the block size got too large).
65af3dab 187
c7b1a56b
WD
188 - Optimized away a loop in hash_search().
189
82c6be7e
WD
190 - Some improvements to the sanitize_path() and clean_fname() functions
191 makes them more efficient and produce better results (while still
192 being compatible with the file-name cleaning that gets done on both
193 sides when sending the file-list).
194
195 - Got rid of alloc_sanitize_path() after adding a destination-buffer
196 arg to sanitize_path() made it possible to put all the former's
197 functionality into the latter.
198
03a9ca0a
WD
199 BUILD CHANGES:
200
bd1574b2
WD
201 - Added a "gen" target to rebuild most of the generated files,
202 including configure, config.h.in, the man pages, and proto.h.
03a9ca0a 203
bd1574b2 204 - If "make proto" doesn't find some changes in the prototypes, the
40564811 205 proto.h file is left untouched (its time-stamp used to always be
40e8d11e 206 updated).
03a9ca0a 207
c54f5170
WD
208 - The variable $STRIP (that is optionally set by the install-strip
209 target's rule) was changed to $INSTALL_STRIP because some systems
210 have $STRIP set in the environment.
211
c7b1a56b
WD
212 - Fixed a build problem when SUPPORT_HARD_LINKS isn't defined.
213
03a9ca0a
WD
214 DEVELOPER RELATED:
215
82c6be7e
WD
216 - The scripts in the testsuite dir were cleaned up a bit and a few
217 new tests added.
03a9ca0a 218
eae4e1f9 219 - Some new diffs were added to the patches dir, and some accepted
40e8d11e 220 ones were removed.
17f59e81 221