// Engineering Log

File Transfer Protocols: Part 7 — Rsync

Published on 2026-09-22

// Fast route

This article belongs to the topic Servers and infrastructure.

Rsync — a utility for copying and synchronizing files, the standard tool for Linux and Unix administrators. Its main feature is delta transfer: if a file already exists on the receiving side, rsync transmits only the changed parts, not the whole file. For backups and mirrors this saves time and bandwidth by a large factor.

How delta transfer works

The receiving side divides its copy of the file into blocks and sends checksums of the blocks. The sending side looks for matching blocks in the new version of the file and sends only the data that the receiver doesn’t have, plus instructions on how to assemble the file from the old blocks. For files that don’t exist on the receiving side, rsync sends them in full. By default changed files are detected by size and modification time; the -c flag forces comparing checksums, which is slower but more reliable.

Common flags

bash
rsync -a --delete --partial --dry-run -v /srv/www/ backup@192.0.2.20:/backup/www/
  • -a (archive) — recursive copy preserving permissions, owners, modification times and symbolic links;
  • --delete — delete files on the receiving side that no longer exist on the source (makes the copy an exact mirror);
  • -z — compress data during transfer (useful on slow links, useless for already compressed archives and video);
  • --partial — do not remove a partially transferred file on interruption, so the transfer can be resumed;
  • --dry-run (-n) — show what would be done without changing anything;
  • -v — verbose output.

Important detail: the trailing slash on the source path. /srv/www/ copies the contents of the directory, while /srv/www copies the directory itself into the destination. A one-character mistake combined with --delete can remove the wrong files, so always run a new command first with --dry-run.

Over SSH

If a remote server is specified in the path (user@host:/path), rsync runs on it via SSH: the data is encrypted and ordinary SSH keys are used for login. To specify a port or key, use -e:

bash
rsync -a -e "ssh -p 2222 -i ~/.ssh/backup_key" /srv/data/ backup@192.0.2.20:/backup/data/

For automated backups, create a separate user on the receiving server with access only to the backup directory and a separate key.

A simple mirror with --delete does not protect against mistakes: a deleted or corrupted file will disappear from the copy after a few minutes. The --link-dest option lets you keep daily snapshots with almost no extra space: unchanged files in the new snapshot become hard links to files in the previous one.

bash
today=$(date +%F)
rsync -a --delete --link-dest=/backup/latest /srv/data/ /backup/$today/
ln -sfn /backup/$today /backup/latest

Each /backup/YYYY-MM-DD directory looks like a full copy, but only changed files consume space. Old snapshots are removed with ordinary rm -rf without affecting the others.

Rsync daemon and port 873

Besides working over SSH, rsync can run as a standalone service (rsync --daemon) listening on TCP port 873. This mode is used by distribution mirrors to serve packages. The daemon protocol does not encrypt data, and the daemon itself is an attractive target for attacks. You do not need to open port 873 to the internet for backups: use SSH or restrict daemon access to your internal network and firewall.

Vulnerabilities and updates

In January 2025 rsync 3.4.0 was released, which fixed six vulnerabilities: a buffer overflow when parsing checksums (CVE-2024-12084), a stack contents leak (CVE-2024-12085), the ability for a server to read arbitrary client files (CVE-2024-12086), writing files outside the destination directory via symbolic links (CVE-2024-12087), bypassing --safe-links (CVE-2024-12088) and a race when handling symbolic links (CVE-2024-12747). Some of these allowed code execution on servers running the daemon. As of September 2026 the current version is 3.5.1 (21 September 2026). Check the version with rsync --version and update the package if it is older than 3.4.0.

Common mistakes

  • Trailing slash in the path — the wrong thing gets copied; with --delete this leads to data loss.
  • Mirror instead of a backup — --delete without snapshot history propagates mistakes and deletions into the backup.
  • A backup that nobody checked — periodically restore a few files and verify their contents.
  • Open rsync daemon — port 873 exposed to the internet without access restrictions.
  • Permissions and owners — when copying not as root, file owners on the receiving side are lost; for a full system copy run rsync as root on both sides.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Servers and infrastructure

VPS, Linux, web stack, migrations, hosting, databases, and core operations.

Typical tasks behind this topic

  • Move a site or service to a new server
  • Set up Linux, Nginx, databases, and backups
  • Figure out why the system behaves unstably

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply