Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package rsync for openSUSE:Factory checked in at 2026-09-23 14:32:28 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/rsync (Old) and /work/SRC/openSUSE:Factory/.rsync.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "rsync" Wed Sep 23 14:32:28 2026 rev:99 rq:1379582 version:3.5.1 Changes: -------- --- /work/SRC/openSUSE:Factory/rsync/rsync.changes 2026-06-12 19:25:09.888258376 +0200 +++ /work/SRC/openSUSE:Factory/.rsync.new.383539/rsync.changes 2026-09-23 14:32:58.858396622 +0200 @@ -1,0 +2,560 @@ +Mon Sep 21 12:10:18 UTC 2026 - David Anes <[email protected]> + +- Update to 3.5.1 + - Protocol: + - The protocol number was changed to 33. + - Bug fixes: + - Fixed several path-handling regressions from 3.5.0. Explicit + sender paths can again traverse symlinked ancestors without + weakening confinement of paths found during recursive scans. + Local and remote-shell `--files-from` paths are handled as + operator-supplied paths rather than paths beneath the transfer + root. + - Fixed access to `/dev/stdin`, `/dev/stdout`, `/dev/stderr` and + `/dev/fd/N` when they refer to pipes or descriptors inside user + namespaces. Reading batch data from a FIFO or process + substitution works again. + - Restored `--max-alloc=0` as a spelling for the parser's maximum + allocation limit rather than disabling that limit. + - Fixed restricted-root paths in `rrsync` and detection of an + inetd connection when a daemon is started with a local socket on + standard input, as can happen under ADB without a PTY. + - Allowed `--contimeout` for daemon connections made through + `--rsh` without applying it to ordinary remote-shell transfers. + - Tightened validation of partial-directory state and + alternate-destination paths on the receiver. An + alternate-destination leaf symlink is no longer followed as a + basis file. + - Fixed undefined shifts in the bundled zlib code and a FreeBSD + amd64 build failure involving the assembly and SIMD objects. + - Enhancements: + - Added support for internationalised domain names when the + required library is available at build time. + - Added the number of 4 KiB logical blocks touched to `--stats`. + This counts distinct logical file regions written by the + receiver, not physical disk blocks or disk I/O. It is reported + when both peers negotiate protocol 33. + - Build and tests: + - `install-strip` now honours `STRIP` including during + cross-compilation. + - Updated platform tests and fleet-test coverage for the 3.5.0 + fixes. +- Activate IDN (internationalised domain name) support by adding + BuildRequires: libidn2-devel +- Drop rsync-fix-protected-regultar-test.patch (already upstream) + +------------------------------------------------------------------- +Fri Aug 14 07:09:48 UTC 2026 - Angel Yankov <[email protected]> + +- Fix test suit protected-regular test + * Added rsync-fix-protected-regultar-test.patch + +------------------------------------------------------------------- +Thu Aug 13 14:19:11 UTC 2026 - Marcus Rueckert <[email protected]> + +- explicitly require python-rpm-macros to not rely on any indirect + requires. Fixes build on SLE 16.0 + +------------------------------------------------------------------- +Thu Aug 13 02:26:23 UTC 2026 - Marcus Rueckert <[email protected]> + +- Update to 3.5.0 + - Security update (bsc#1269060, rsync 3.5.0 security backports): + - CVE-2026-53783, bsc#1269041: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) + - CVE-2026-53784, bsc#1269042: Daemon module-root chdir escape under "use chroot = no" + - CVE-2026-53785, bsc#1269043: --relative implied-parent creation escapes the destination tree + - CVE-2026-53786, bsc#1269044: Daemon --filter merge file bypasses the module filter list + - CVE-2026-53788, bsc#1269046: Daemon name-converter accepts newline-bearing names into its line protocol + - CVE-2026-53789, bsc#1269047: Malicious sender expands --delete scope by reclassifying an implied parent + - CVE-2026-53790, bsc#1269048: Command / argument injection via unquoted peer- or host-controlled values + - CVE-2026-53791, bsc#1269049: PROXY-protocol mode lets a direct client spoof the daemon's source address + - CVE-2026-53792, bsc#1269050: Receiver-supplied zero checksum block length drives sender matching negative + - CVE-2026-53793, bsc#1269051: Chroot "/./" inner-module escape via a parent-component symlink + - CVE-2026-53794, bsc#1269052: Remote peer disables the per-allocation sanity cap via --max-alloc=0 + - CVE-2026-53795, bsc#1269053: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement + - CVE-2026-53796, bsc#1269054: Non-daemon receiver destination-chdir symlink race (TOCTOU) + - CVE-2026-53797, bsc#1269055: Sender source-tree parent-component symlink race -> out-of-tree disclosure + - CVE-2026-53798, bsc#1269045: Daemon name-converter empty response maps an unknown name to uid/gid 0 + - CVE-2026-53799, bsc#1269056: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege escalation) + - CVE-2026-53800, bsc#1269057: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion outside the source tree + - CVE-2026-53801, bsc#1269058: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure + - CVE-2026-53802, bsc#1269039: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files + - CVE-2026-53803, bsc#1269040: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths + - CVE-2026-70463, bsc#1273430: "auth users" ignores documented comma-only parsing, silently skipping a deny/read-only rule + - CVE-2026-70462, bsc#1273431: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (signed overflow, and a non-positive value) + - CVE-2026-70461, bsc#1273432: Peer-driven one-byte heap out-of-bounds write in add_implied_include() + - CVE-2026-70460, bsc#1273433: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in-module symlink + - CVE-2026-70459, bsc#1273434: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root + - CVE-2026-70458, bsc#1273435: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H + - CVE-2026-70457, bsc#1273436: Attacker-chosen-offset write in parse_size_arg() error formatting + - CVE-2026-70456, bsc#1273437: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs + - CVE-2026-70454, bsc#1273439: rsync-ssl establishes an unauthenticated TLS connection (no CA verification; no stunnel hostname binding) + - CVE-2026-70453, bsc#1273440: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain + - CVE-2026-70464, bsc#1273429: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module + - CVE-2026-70455, bsc#1273438: Peer-controlled Zstandard worker exhaustion on an rsync daemon + - CVE-2026-70452, bsc#1273441: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block + - Rejected CVEs (duplicates, resolved to canonical CVEs above): + - CVE-2026-44507, bsc#1271931: duplicate of CVE-2026-43617 + - CVE-2026-44508, bsc#1271932: duplicate of CVE-2026-43618 + - CVE-2026-44509, bsc#1271933: duplicate of CVE-2026-43619 + - CVE-2026-44510, bsc#1271934: duplicate of CVE-2026-43620 + - Security update: + - CVE-2025-10158, bsc#1254441: Out of bounds array access via negative index + - CVE-2026-41035, bsc#1262223: count of entries mismatch can lead to a use-after-free + - CVE-2026-43617, bsc#1264515: Authorization Bypass via Hostname Resolution + - CVE-2026-29518, bsc#1264512: Integer Overflow Information Disclosure + - CVE-2026-43619, bsc#1264514: Symlink Race Condition via Path-Based Syscalls + - CVE-2026-43620, bsc#1264513: Out-of-Bounds Array Read via recv_files() + - CVE-2026-45232, bsc#1265296: Off-by-one stack OOB write in HTTP CONNECT proxy response parsing + + - SECURITY FIXES: + - This release fixes 33 security issues found during a focused + audit of rsync's path handling and daemon protocol, a + companion daemon-protocol fuzzing pass, and reports from + external researchers -- plus several robustness hardenings. + CVE IDs were assigned by VulnCheck (CNA); the precise + "introduced in" version ranges accompany each advisory, and + many are much narrower than "everything before 3.5.0". Every + fix ships with a regression test in the test suite that fails + on the unfixed tree. Many thanks to the external researchers + credited below. + - Link following (CWE-59/61) -- a local user who controls a + path component plants a symlink that a privileged rsync then + follows: + - CVE-2026-53802 (HIGH): Arbitrary file read / transfer-shaping + via symlinked operator-supplied input files. rsync followed + attacker-planted symlinks in --filter merge files (including + per-directory merges and -C .cvsignore), --files-from / + --include-from / --exclude-from, and the client + --password-file / daemon secrets file -- reading an arbitrary + file as filter rules, or sending a victim file's contents as + the daemon authentication response. Operator-supplied paths + are now resolved component-by-component with + openat(O_PATH|O_NOFOLLOW), allowing a symlink component only + when it is owned by uid 0 or the effective uid. + - CVE-2026-53803 (HIGH): Arbitrary file write / privilege + escalation via symlinked operator-supplied output paths -- + --log-file, --write-batch/--read-batch, and the daemon's motd + / lock / early-input / --config opens. A planted symlink (or + parent component) could redirect the write, e.g. append the + log to authorized_keys; --read-batch could also feed chosen + bytes to the protocol parser. Same trusted-owner path walk, + plus an S_ISREG check on the --read-batch file. + - CVE-2026-53785 (HIGH): Under --relative, the receiver's + implied-parent creation (make_path()) built the parent chain + with a plain mkdir() on the full path, so a planted parent + symlink placed the new directories and file outside the + destination tree. make_path() now creates each component + through the held-directory-fd primitive. Reported by Omar + Elsayed (seks99x). + - CVE-2026-53784 (HIGH): Daemon module-root chdir escape under + use chroot = no: a plain chdir() followed a planted + parent-component symlink, serving files from outside the + module. The module-root chdir now goes through the secure + resolver. + - CVE-2026-53793 (HIGH): Chroot /./ inner-module escape -- a + symlinked parent component inside the inner module reached a + sibling outside it (the generator basis stat, the receiver + write/finish path, the module chdir, and the receiver's + delta-basis open). The secure resolver is now engaged for all + of those paths. + - CVE-2026-53795 (HIGH): An absolute --temp-dir or --link-dest + disabled the receiver's rename/link confinement. + do_rename_at()/do_link_at() bailed to the unconfined + path-based call whenever either path was absolute, so an + absolute source (the temp file, or the link-dest basis) let + finish_transfer()'s tmp->final rename -- or a hard-link + create -- follow a destination parent component an attacker + flipped to a symlink mid-transfer, writing the file outside + the tree. Each side is now confined independently. Reported + by Omar Elsayed (seks99x). + - CVE-2026-53796 (MEDIUM): A non-daemon receiver's one-time + chdir() into the operator-named destination was not fully + confined (a relative destination took a plain chdir()), so an + attacker who raced the named destination from a directory to + a symlink moved the receiver's CWD -- and every file it then + created -- outside the tree. The destination chdir now uses + the same ownership-checked O_NOFOLLOW walk as the daemon + module chdir (see BEHAVIOR CHANGES). Reported by Omar Elsayed + (seks99x). + - CVE-2026-53797 (MEDIUM): A non-daemon sender opened each + transferred file's content by path (leaf O_NOFOLLOW only), so + a source parent component an unprivileged user raced to a + symlink after the file-list scan was followed -- reading a + file from outside the source tree into an attacker-readable + destination. The content open is now anchored at the transfer + root with secure_relative_open(); -L / --copy-unsafe-links / + -k still follow, and --insecure-links restores the legacy + open. + - CVE-2026-53799 (MEDIUM): Receiver ACL/xattr metadata + application followed a symlink race -> arbitrary ACL + set (local privilege escalation). When preserving metadata + (-A/--acls, -X/--xattrs, or fake-super ACL-as-xattr), the + receiver applied each entry's ACL/xattrs by path via + acl_set_file() / setxattr(). A local user who raced a + just-received entry (or a parent) into a symlink before the + apply could redirect an attacker-chosen ACL -- the bytes are + carried in the source entry -- onto a victim inode outside + the destination tree, granting rwx on a root-owned file. The + apply now pins each entry's inode with an O_RDONLY|O_NOFOLLOW + fd and sets all metadata on the held inode (Linux 6.13+ + *xattrat syscalls, or a patched libacl's *_at bindings, else + the /proc/self/fd compat path). Where neither primitive + exists (the BSDs, Solaris, macOS, or a /proc-less Linux + container) it falls back to the path-based apply to keep + --acls functional -- a documented residual, refusable via + refuse options = acls. + - CVE-2026-53800 (MEDIUM): Sender --remove-source-files unlink + followed a parent-component symlink race -> arbitrary + file deletion outside the source tree. The post-send unlink + and its same-file safety re-stat resolved by path relative to + the process CWD, so an unprivileged user who raced a source + parent into a symlink after the file was sent could make a + higher-authority sender (a root --remove-source-files run, or + a daemon module not refusing the option) delete a file + outside the served tree. The removal is now resolved through + the secure held-dirfd walk anchored at the served module root + (daemon) or transfer-root CWD (local sender), the safety + re-stat is confined likewise, and the per-file dev/ino is + only computed when --remove-source-files is in effect. + - CVE-2026-53801 (MEDIUM): Sender/daemon directory-scan + enumeration escaped the transfer root / module -> + out-of-tree disclosure. The sender enumerated each source + directory with a plain opendir() on the accumulated path, not + through the secure resolver (the enumeration sibling of the + previous item, which confined only the content open). A + parent component raced to a symlink between the file-list + scan and the recursive opendir() -- or, in daemon following + mode (-L/--copy-dirlinks/--copy-unsafe-links), an in-module + symlinked directory pointing outside the module -- let a + higher-authority sender enumerate an out-of-tree directory + and copy its entry names, metadata and symlink targets. The + directory scan is now confined through a held opendir fd + anchored at the transfer root / module. + - support/rrsync (the restricted SSH wrapper): + - CVE-2026-53783 (HIGH): rrsync restricted-directory escape. It + validated each argument with realpath() and then exec'd rsync + against the same name (a TOCTOU window), and left dangerous + options enabled in a restricted subdir. rrsync now inode-pins + the validated path and roots the argument it hands rsync at + that pinned fd, denies --copy-unsafe-links, forces --no-D, + and refuses a symlinked --log-file. The pin relies on Linux's + /proc/self/fd magic links being bound to the open inode, so + it is Linux-only; on the BSDs, macOS, Solaris and Cygwin + rrsync passes the realpath()-validated name as it + always did. Two limits are worth stating: under --relative + only the anchor the transmitted name starts from is pinned, + so a component below it can still be raced, and the final + component of an ordinary sender argument is not pinned either + (rsync does not follow a symlink there, and the options that + would change that are refused in a restricted dir). + - A filter rule that failed to parse was echoed back verbatim, + including when the rule came from a merge file's contents. A + per-directory merge rule names a file the peer chooses and + travels over the protocol rather than in an argument, so this + let a peer read back any line of any file the server process + could open that is not valid filter syntax -- through an + rrsync restricted account as well as a daemon module, since + neither confined a merge open that the wrapper never sees. A + syntax error in a rule read from a file now reports the file + and line rather than the text; a rule given as an argument is + still shown. The --debug=FILTER traces print the same + file-derived text, so rrsync now refuses a peer-selected + --debug (a stock client never sends one). An operator who + turns debugging on for their own server still sees the rule + text. + - Redacting those diagnostics did not close the merge route on + its own, because the worst shape produces no diagnostic at + all: an exclude-only merge (the - modifier) makes every line + of the file a pattern, so nothing fails to parse and the peer + reads the contents off which of its own names went missing + from the file list. Through an rrsync restricted account that + needs no --delete and no verbosity on a pull. The open is now + confined rather than the disclosure suppressed: rsync gained + --confine-root=DIR, which refuses an operator- or + peer-supplied path that resolves outside DIR, and rrsync + passes its restricted directory. A merge file inside that + directory keeps working. A daemon already had this through + its module root and is unaffected. + - Daemon protocol / identity: + - CVE-2026-53786 (MEDIUM): A client-supplied --filter merge + file bypassed the module filter list (it was checked against + the module-prefixed path, which never matched a module rule). + The module-dir prefix is now stripped before the check. + Reported by Mitchell Benjamin (Revamp Studio). + - CVE-2026-53798 (MEDIUM): The daemon name converter mapped an + unknown name to uid/gid 0 (an empty response was read as + atol("") == 0); with fake super = yes the stored metadata + became root-owned. An empty/non-numeric response is now + treated as a lookup failure. Reported by Mitchell Benjamin + (Revamp Studio). + - CVE-2026-53788 (MEDIUM): A peer-controlled name containing a + newline/CR was written verbatim into the name-converter line + protocol, allowing request injection. Converter tokens + containing control characters are now rejected. Reported by + Mitchell Benjamin (Revamp Studio). + - CVE-2026-53789 (MEDIUM): A malicious daemon-sender could + widen --delete scope by omitting the "no content dir" flag on ++++ 274 more lines (skipped) ++++ between /work/SRC/openSUSE:Factory/rsync/rsync.changes ++++ and /work/SRC/openSUSE:Factory/.rsync.new.383539/rsync.changes Old: ---- rsync-3.4.3.tar.gz rsync-3.4.3.tar.gz.asc rsync-openat2-glibc-missing.patch New: ---- rsync-3.5.1.tar.gz rsync-3.5.1.tar.gz.asc use-sys.executable.patch ----------(Old B)---------- Old: rsyncd-return-from-list-command-with-0.patch - drop rsync-openat2-glibc-missing.patch - switch to use a modern python on sle 15 for the testsuite ----------(Old E)---------- ----------(New B)---------- New:- switch to use a modern python on sle 15 for the testsuite - add use-sys.executable.patch: don't assume python3 is the binary name. use sys.executable. ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ rsync.spec ++++++ --- /var/tmp/diff_new_pack.OQgTzS/_old 2026-09-23 14:32:59.988443864 +0200 +++ /var/tmp/diff_new_pack.OQgTzS/_new 2026-09-23 14:32:59.990443947 +0200 @@ -28,8 +28,16 @@ %bcond_with gcc11 %endif +%if 0%{?suse_version} >= 1600 +%define use_python %{primary_python} +%define python_binary %{_bindir}/python%{python_bin_suffix} +%else +%define use_python python311 +%define python_binary %{_bindir}/python3.11 +%endif + Name: rsync -Version: 3.4.3 +Version: 3.5.1 Release: 0 Summary: Versatile tool for fast incremental file transfer License: GPL-3.0-or-later @@ -52,17 +60,18 @@ # https://github.com/RsyncProject/rsync/pull/639 Patch3: rsyncd-return-from-list-command-with-0.patch Patch4: rsync-python-3.6-tests.patch -Patch5: rsync-openat2-glibc-missing.patch - +Patch5: use-sys.executable.patch +BuildRequires: %{use_python}-base BuildRequires: autoconf BuildRequires: automake BuildRequires: c++_compiler BuildRequires: libacl-devel +BuildRequires: libidn2-devel BuildRequires: liblz4-devel BuildRequires: libzstd-devel BuildRequires: pkgconfig BuildRequires: popt-devel -BuildRequires: python3-base +BuildRequires: python-rpm-macros BuildRequires: systemd-rpm-macros BuildRequires: zlib-devel %if %{with xxhash} @@ -101,6 +110,7 @@ export CFLAGS="%{optflags} -fPIC -DPIC -fPIE" export CXXFLAGS="$CFLAGS" export LDFLAGS="-Wl,-z,relro,-z,now -fPIE -pie" +export PYTHON3=%{python_binary} %configure \ --with-included-popt=no \ @@ -121,6 +131,7 @@ %make_build %check +perl -p -i -e 's|/usr/bin/env python3|%{python_binary}|g' $(grep -lr 'env python3' testsuite/ support/) runtests.py chmod +x support/* %make_build check chmod -x support/* ++++++ rsync-3.4.3.tar.gz -> rsync-3.5.1.tar.gz ++++++ ++++ 91969 lines of diff (skipped) ++++++ rsync-python-3.6-tests.patch ++++++ --- /var/tmp/diff_new_pack.OQgTzS/_old 2026-09-23 14:33:00.464463764 +0200 +++ /var/tmp/diff_new_pack.OQgTzS/_new 2026-09-23 14:33:00.470464015 +0200 @@ -1,8 +1,8 @@ -Index: rsync-3.4.3/runtests.py +Index: rsync-3.5.0/runtests.py =================================================================== ---- rsync-3.4.3.orig/runtests.py -+++ rsync-3.4.3/runtests.py -@@ -72,12 +72,12 @@ def find_setfacl_nodef(scratchbase): +--- rsync-3.5.0.orig/runtests.py ++++ rsync-3.5.0/runtests.py +@@ -151,12 +151,12 @@ def find_setfacl_nodef(scratchbase): ['setfacl', '-s', 'u::7,g::5,o:5', scratchbase], ]: try: @@ -17,7 +17,7 @@ if '-k,' in r.stdout or '-k,' in r.stderr: return ['setfacl', '-k'] except (FileNotFoundError, subprocess.TimeoutExpired): -@@ -122,11 +122,11 @@ def get_testuser(): +@@ -201,11 +201,11 @@ def get_testuser(): for cmd in ['/usr/bin/whoami', '/usr/ucb/whoami', '/bin/whoami']: if os.path.isfile(cmd): try: @@ -31,7 +31,7 @@ except (FileNotFoundError, subprocess.CalledProcessError): return os.environ.get('LOGNAME', os.environ.get('USER', 'UNKNOWN')) -@@ -134,11 +134,11 @@ def get_testuser(): +@@ -230,13 +230,13 @@ def _move_aside(path): def prep_scratch(scratchdir, srcdir, tooldir, setfacl_nodef): """Prepare a scratch directory for a test.""" if os.path.isdir(scratchdir): @@ -39,6 +39,8 @@ - subprocess.run(['rm', '-rf', scratchdir], capture_output=True) + subprocess.run(['chmod', '-R', 'u+rwX', scratchdir], stdout=subprocess.PIPE, stderr=subprocess.PIPE) + subprocess.run(['rm', '-rf', scratchdir], stdout=subprocess.PIPE, stderr=subprocess.PIPE) + if os.path.isdir(scratchdir): + _move_aside(scratchdir) # rm -rf left corrupted debris; don't inherit it os.makedirs(scratchdir, exist_ok=True) if setfacl_nodef: - subprocess.run(setfacl_nodef + [scratchdir], capture_output=True) @@ -46,7 +48,7 @@ try: os.chmod(scratchdir, os.stat(scratchdir).st_mode & ~0o2000) # clear setgid except OSError: -@@ -323,7 +323,7 @@ def main(): +@@ -753,7 +753,7 @@ def main(): print(f' srcdir={srcdir}') print(f' TLS_ARGS={tls_args}') print(f' testuser={testuser}') @@ -54,21 +56,14 @@ + print(f' os={subprocess.check_output(["uname", "-a"], universal_newlines=True).strip()}') print(f' preserve_scratch={"yes" if args.preserve_scratch else "no"}') if args.valgrind: - print(f' valgrind=enabled (logs in valgrind.*.log)') -@@ -382,13 +382,13 @@ def main(): - if tr.result == 0: - passed += 1 - if not args.preserve_scratch and os.path.isdir(scratchdir): -- subprocess.run(['rm', '-rf', scratchdir], capture_output=True) -+ subprocess.run(['rm', '-rf', scratchdir], stdout=subprocess.PIPE, stderr=subprocess.PIPE) - return False - elif tr.result == 77: - skipped_list.append(tr.testbase) - skipped += 1 - if not args.preserve_scratch and os.path.isdir(scratchdir): -- subprocess.run(['rm', '-rf', scratchdir], capture_output=True) -+ subprocess.run(['rm', '-rf', scratchdir], stdout=subprocess.PIPE, stderr=subprocess.PIPE) - return False - elif tr.result == 78: + print(f' valgrind=enabled (logs in valgrind-logs/valgrind.*.log)') +@@ -894,7 +894,7 @@ def main(): failed += 1 + if tr.result in (Exit.PASS, Exit.SKIP, Exit.XFAIL) and not args.preserve_scratch \ + and os.path.isdir(scratchdir): +- subprocess.run(['rm', '-rf', scratchdir], capture_output=True) ++ subprocess.run(['rm', '-rf', scratchdir], stdout=subprocess.PIPE, stderr=subprocess.PIPE) + # With a manifest, only a mismatch is a "failure" (an expected fail is + # fine); without one, any non-pass/non-skip/non-xfail result is a failure. + if expect is not None: ++++++ rsync-usr-etc.patch ++++++ --- /var/tmp/diff_new_pack.OQgTzS/_old 2026-09-23 14:33:00.495465060 +0200 +++ /var/tmp/diff_new_pack.OQgTzS/_new 2026-09-23 14:33:00.501465311 +0200 @@ -1,8 +1,8 @@ -Index: rsync-3.4.0/clientserver.c +Index: rsync-3.5.0/clientserver.c =================================================================== ---- rsync-3.4.0.orig/clientserver.c -+++ rsync-3.4.0/clientserver.c -@@ -1261,10 +1261,16 @@ static void send_listing(int fd) +--- rsync-3.5.0.orig/clientserver.c ++++ rsync-3.5.0/clientserver.c +@@ -1400,10 +1400,16 @@ static int proxy_peer_allowed(int fd) static int load_config(int globals_only) { if (!config_file) { @@ -21,11 +21,11 @@ } return lp_load(config_file, globals_only); } -Index: rsync-3.4.0/configure.ac +Index: rsync-3.5.0/configure.ac =================================================================== ---- rsync-3.4.0.orig/configure.ac -+++ rsync-3.4.0/configure.ac -@@ -175,7 +175,7 @@ AC_ARG_WITH(rsync-path, +--- rsync-3.5.0.orig/configure.ac ++++ rsync-3.5.0/configure.ac +@@ -197,7 +197,7 @@ AC_ARG_WITH(rsync-path, AC_DEFINE_UNQUOTED(RSYNC_PATH, "$RSYNC_PATH", [location of rsync on remote machine]) AC_ARG_WITH(rsyncd-conf, @@ -34,7 +34,7 @@ [ if test ! -z "$with_rsyncd_conf" ; then case $with_rsyncd_conf in yes|no) -@@ -193,7 +193,27 @@ AC_ARG_WITH(rsyncd-conf, +@@ -215,7 +215,27 @@ AC_ARG_WITH(rsyncd-conf, fi ], [ RSYNCD_SYSCONF="/etc/rsyncd.conf" ]) @@ -63,11 +63,11 @@ AC_ARG_WITH(rsh, AS_HELP_STRING([--with-rsh=CMD],[set remote shell command to CMD (default: ssh)])) -Index: rsync-3.4.0/rsyncd.conf.5.md +Index: rsync-3.5.0/rsyncd.conf.5.md =================================================================== ---- rsync-3.4.0.orig/rsyncd.conf.5.md -+++ rsync-3.4.0/rsyncd.conf.5.md -@@ -1242,7 +1242,7 @@ The /etc/rsyncd.secrets file would look +--- rsync-3.5.0.orig/rsyncd.conf.5.md ++++ rsync-3.5.0/rsyncd.conf.5.md +@@ -1441,7 +1441,7 @@ The /etc/rsyncd.secrets file would look ## FILES ++++++ rsync.keyring ++++++ --- /var/tmp/diff_new_pack.OQgTzS/_old 2026-09-23 14:33:00.536466774 +0200 +++ /var/tmp/diff_new_pack.OQgTzS/_new 2026-09-23 14:33:00.541466983 +0200 @@ -128,4 +128,25 @@ dfwsLhI= =whzx -----END PGP PUBLIC KEY BLOCK----- +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mDMEadXToBYJKwYBBAHaRw8BAQdAkrK1yr4aqiXhLWk68SaqsuQ33W4sGA1vDrj7 +Ynr+oby0HVplbiBEb2RkIDxtYWlsQHN0ZWFkeXRhby5jb20+iK8EExYKAFcWIQTA +4QVFBXBPdX2SWrJqZOiqLvvPXQUCadXToBsUgAAAAAAEAA5tYW51MiwyLjUrMS4x +MiwyLDECGwEFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQamToqi77z11a +YQD7BEk0nGxzMAAPoUppeU1b9fSt7LM5yRS4/FCSvfYIlmkA/jW18aZVOrGfEJgV +Qtb6EyjMc5LRgbNkz9lY9MdKY+MIuDgEadXT4xIKKwYBBAGXVQEFAQEHQOfemuEA +jVMzyVNp8KdJmXnJeymCgUaeXJ4Zku3n9/A2AwEIB4iUBBgWCgA8FiEEwOEFRQVw +T3V9klqyamToqi77z10FAmnV0+MbFIAAAAAABAAObWFudTIsMi41KzEuMTIsMiwx +AhsMAAoJEGpk6Kou+89dLn8BAPCoEu++4LgvupcW7Vo1Wlo5mrtEbq1zkKmstYu5 +YQXrAP9/D3ZAlPQ1zyfIbJ61WK+3aOjdV9idUYIoy8qWPX1eB7gzBGnV08wWCSsG +AQQB2kcPAQEHQPcdr/+s3UCETh38T80LLhShoOW1093LJuFy9OMUiwbPiQELBBgW +CgA8FiEEwOEFRQVwT3V9klqyamToqi77z10FAmnV08wbFIAAAAAABAAObWFudTIs +Mi41KzEuMTIsMiwxAhsCAIEJEGpk6Kou+89ddiAEGRYKAB0WIQSO34j0cxoei0XW +f75pCVRrLFLsLQUCadXTzAAKCRBpCVRrLFLsLd0bAP0U5jWBofzyWIfkxp+ktiNg +leR2LE8HgxCRsHgJef5UpwEA85zc6tNjj3rs4zgEjJdy/05Mj8vD32w8az9Kos5D +rwQkrgEA6vucizrQudpJsgr18ZcEDWuf2rZ3eb0tE3PiYlGLO44A/335Xmr2Hsb6 +oihb1aTl+FMJMF6o/OL3/V1FMsgMR24N +=qycZ +-----END PGP PUBLIC KEY BLOCK----- ++++++ rsyncd-return-from-list-command-with-0.patch ++++++ --- /var/tmp/diff_new_pack.OQgTzS/_old 2026-09-23 14:33:00.574468363 +0200 +++ /var/tmp/diff_new_pack.OQgTzS/_new 2026-09-23 14:33:00.578468530 +0200 @@ -15,11 +15,11 @@ clientserver.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) -Index: rsync-3.4.0/clientserver.c +Index: rsync-3.5.0/clientserver.c =================================================================== ---- rsync-3.4.0.orig/clientserver.c -+++ rsync-3.4.0/clientserver.c -@@ -1377,7 +1377,7 @@ int start_daemon(int f_in, int f_out) +--- rsync-3.5.0.orig/clientserver.c ++++ rsync-3.5.0/clientserver.c +@@ -1561,7 +1561,7 @@ int start_daemon(int f_in, int f_out) rprintf(FLOG, "module-list request from %s (%s)\n", host, addr); send_listing(f_out); ++++++ use-sys.executable.patch ++++++ Index: rsync-3.5.0/testsuite/copy-xattrs-symlink-race_test.py =================================================================== --- rsync-3.5.0.orig/testsuite/copy-xattrs-symlink-race_test.py +++ rsync-3.5.0/testsuite/copy-xattrs-symlink-race_test.py @@ -23,6 +23,7 @@ import os import platform import subprocess import time +import sys from rsyncfns import ( race_budget, SCRATCHDIR, rmtree, rsync_argv, test_fail, test_skipped, @@ -131,7 +132,7 @@ flip_code = ( " except OSError:\n" " pass\n" ) -flip = subprocess.Popen(['python3', '-c', flip_code, str(sub), str(link)]) +flip = subprocess.Popen([sys.executable, '-c', flip_code, str(sub), str(link)]) try: deadline = time.monotonic() + race_budget(10.0) while time.monotonic() < deadline: Index: rsync-3.5.0/testsuite/rename-fullpath-symlink-race_test.py =================================================================== --- rsync-3.5.0.orig/testsuite/rename-fullpath-symlink-race_test.py +++ rsync-3.5.0/testsuite/rename-fullpath-symlink-race_test.py @@ -19,6 +19,7 @@ import os import subprocess import time +import sys from rsyncfns import race_budget, SCRATCHDIR, rmtree, rsync_argv, test_fail @@ -82,7 +83,7 @@ flip_code = ( " except OSError:\n" " pass\n" ) -flip = subprocess.Popen(['python3', '-c', flip_code, str(sub), str(link)]) +flip = subprocess.Popen([sys.executable, '-c', flip_code, str(sub), str(link)]) try: deadline = time.monotonic() + race_budget(10.0) while time.monotonic() < deadline:
