From 03a9ff353721ba8fb5f37cad2546d25788011451 Mon Sep 17 00:00:00 2001 From: Craig Jennings Date: Thu, 25 Jun 2026 01:07:31 -0400 Subject: fix: harden rsyncshot destination, rotation, and mount handling Refuse to run when REMOTE_PATH or MOUNTDIR is empty or non-absolute. A blank config value otherwise resolves the destination to the filesystem root, where rotation runs rm -rf and --delete. Run the rotation cp/mv/rm as bare command names in remote mode, resolved by the remote PATH, instead of hardcoded /usr/bin paths that broke on remotes whose binaries live elsewhere. Resolve the real binary via command -v in local mode. Pass rsync -R so each source is stored under its full path. Two includes sharing a basename (/usr/local/bin and /usr/bin) previously both mapped to latest/bin, and the second sync's --delete wiped the first. This changes the stored layout: /usr/local/bin now lives at latest/usr/local/bin instead of latest/bin. /home and /etc are unchanged. Add rsync --numeric-ids so /etc and /home ownership survives a restore when the destination has a different passwd/group database. Match mount points exactly via is_mounted() instead of a substring grep of /proc/mounts, so /media/backup no longer matches /media/backup2, paths compare literally, and mount points with spaces work. Reject a retention count below 1, which previously still created one snapshot. Drop the grep "|| echo 0" that emitted a stray second line, assemble ssh options as arrays, and quote the RSYNC_RSH identity path. Extract derive_paths() and is_mounted() as sourceable functions and add unit, rsync-flag, and gated remote-mode test suites. The suite now runs 36 tests, and shellcheck is clean across the script and tests. --- tests/test_rsyncshot.sh | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'tests/test_rsyncshot.sh') diff --git a/tests/test_rsyncshot.sh b/tests/test_rsyncshot.sh index 15f2a99..95a0032 100755 --- a/tests/test_rsyncshot.sh +++ b/tests/test_rsyncshot.sh @@ -22,6 +22,7 @@ QUICK=false while [[ $# -gt 0 ]]; do case $1 in -v|--verbose) + # shellcheck disable=SC2034 # reserved flag; verbose output not yet wired VERBOSE=true shift ;; @@ -90,12 +91,15 @@ run_test_file() { # Run test suites run_test_file "$SCRIPT_DIR/cases/test_validation.sh" "validation" +run_test_file "$SCRIPT_DIR/cases/test_functions.sh" "functions" run_test_file "$SCRIPT_DIR/cases/test_includes.sh" "includes" run_test_file "$SCRIPT_DIR/cases/test_dryrun.sh" "dryrun" +run_test_file "$SCRIPT_DIR/cases/test_rsync_flags.sh" "rsync_flags" if [ "$QUICK" = false ]; then run_test_file "$SCRIPT_DIR/cases/test_backup.sh" "backup" run_test_file "$SCRIPT_DIR/cases/test_cron.sh" "cron" + run_test_file "$SCRIPT_DIR/cases/test_remote.sh" "remote" else echo "" echo "Skipping slow tests (backup, cron) - use without --quick to run all" -- cgit v1.2.3