Bug#455194: Rsync-daemon security advisories for writable daemons

Paul Slootman paul+rsync at wurtel.net
Tue Dec 11 11:24:46 GMT 2007

On Mon 10 Dec 2007, Matt McCutchen wrote:
> On Mon, 2007-12-10 at 21:20 +0100, Paul Slootman wrote:
> > It seems that people running the Debian 2.6.9-5.1 version which has this
> > patch applied. are running into problems where rsync wants to set
> > permissions on symlinks.
> In the report rsync seems to want to set mtimes, not permissions.

Oops, I was too much in a hurry...

> > The bug report and extra info is at
> > http://bugs.debian.org/455194 .  I can't dig into this until tomorrow,
> > so if someone wants to have a look in the meantime...
> My guess is that the problem has nothing to do with the munge-symlinks
> patch itself and it is just that the 2.6.9-5.1 package was built on a
> newer system.
> Specifically: A lutimes function to set symlink mtimes was recently
> added to glibc, and the underlying utimensat system call was added to
> Linux 2.6.22.  Rsync's configure script checks whether the build

Ah, that must be it.

I've now built a version with the git patch to ignore the return code.

Thanks for figuring this out!

Paul Slootman

