From 03a9ff353721ba8fb5f37cad2546d25788011451 Mon Sep 17 00:00:00 2001 From: Craig Jennings Date: Thu, 25 Jun 2026 01:07:31 -0400 Subject: fix: harden rsyncshot destination, rotation, and mount handling Refuse to run when REMOTE_PATH or MOUNTDIR is empty or non-absolute. A blank config value otherwise resolves the destination to the filesystem root, where rotation runs rm -rf and --delete. Run the rotation cp/mv/rm as bare command names in remote mode, resolved by the remote PATH, instead of hardcoded /usr/bin paths that broke on remotes whose binaries live elsewhere. Resolve the real binary via command -v in local mode. Pass rsync -R so each source is stored under its full path. Two includes sharing a basename (/usr/local/bin and /usr/bin) previously both mapped to latest/bin, and the second sync's --delete wiped the first. This changes the stored layout: /usr/local/bin now lives at latest/usr/local/bin instead of latest/bin. /home and /etc are unchanged. Add rsync --numeric-ids so /etc and /home ownership survives a restore when the destination has a different passwd/group database. Match mount points exactly via is_mounted() instead of a substring grep of /proc/mounts, so /media/backup no longer matches /media/backup2, paths compare literally, and mount points with spaces work. Reject a retention count below 1, which previously still created one snapshot. Drop the grep "|| echo 0" that emitted a stray second line, assemble ssh options as arrays, and quote the RSYNC_RSH identity path. Extract derive_paths() and is_mounted() as sourceable functions and add unit, rsync-flag, and gated remote-mode test suites. The suite now runs 36 tests, and shellcheck is clean across the script and tests. --- .shellcheckrc | 7 +++++++ 1 file changed, 7 insertions(+) create mode 100644 .shellcheckrc (limited to '.shellcheckrc') diff --git a/.shellcheckrc b/.shellcheckrc new file mode 100644 index 0000000..0ac34f0 --- /dev/null +++ b/.shellcheckrc @@ -0,0 +1,7 @@ +# Project shellcheck configuration. +# +# Disable the "can't follow sourced file" infos. They are not actionable here: +# - rsyncshot sources /etc/rsyncshot/config, which doesn't exist at lint time. +# - the test suite sources lib/test_helpers.sh via a runtime-computed path. +# Both are correct at runtime; shellcheck simply can't resolve them statically. +disable=SC1090,SC1091 -- cgit v1.2.3