Skip to content

Dev minor - #159

Merged
rapier1 merged 76 commits into
masterfrom
dev_minor
Sep 15, 2026
Merged

rapier1 merged 76 commits into
masterfrom
dev_minor

Conversation

@rapier1

@rapier1 rapier1 commented Sep 14, 2026

Copy link
Copy Markdown
Owner

Update HPN-SSH to OpenSSH 10.5. No functionality changes.

djmdjm and others added 30 commits July 7, 2026 11:02
refactoring servconf.c bz3974 patch from Colin Watson

OpenBSD-Commit-ID: be39ad3dbe36d9ecdb86f3811da5dfbdc9bcb1e6
OpenBSD-Commit-ID: 03fc22fb427b7547ee7844907cf3257bce7fdc3c
it's badly out of date, has already been deleted upstream and is not
well-adapted for portable.
other key types:  - change the DNS names to be rsa.* for the existing RSA
fingerprints.  - verify that all required SSHFP records exist in DNS.  - only
run the RSA tests if the build supports RSA.

OpenBSD-Regress-ID: 03e4087c3bd09ad8bede788f76f0ab59b732639e
OpenBSD-Regress-ID: a4bc60d0f398b148a29df3594d5f36de0e4e5ea2
OpenBSD-Regress-ID: dafa6c3e723cf39ca5e552304372bc085c348102
fingerprints. Dynamically generate the required zone file.

OpenBSD-Regress-ID: 61acdf25efc8c5d3bb0156fd3a53bf8159d3e13a
OpenBSD-Commit-ID: 3af5548ba2112045db392a14c959ca309605bdb9
scheme (and its corresponding certificate form) in the lowest-priority
position.

"what took you so long" deraadt@

OpenBSD-Commit-ID: b7be74df494323a7021cf230f11eff824d2810d0
documentation of -o and instead just direct readers to the actual
ssh_config(5) manpage.

ok deraadt@

OpenBSD-Commit-ID: bed2058af847c2149e0e457202a8c4ee7000ad33
acting as a post- authentication monitor; ok dtucker@

OpenBSD-Commit-ID: a3c36a005a61ccaeb974afd7b9290b826e1620ba
request, allow each hostkey to perform at most one signature operation. ok
dtucker@

OpenBSD-Commit-ID: ad4149015634f8156ba723656035ec26140875e8
algorithm

OpenBSD-Commit-ID: c519ba7408cfb2700d184c9441de4ff01ecda726
default

ok djm@

OpenBSD-Commit-ID: c45683d341d7dce6c126903bf9a37393f2b75839
case for consistency

ok djm@

OpenBSD-Commit-ID: 55647b13194d0aaa7095b89455d4c44ddeb53e7d
to tunnel forwarding (which is administratively disabled by default).

Reported by Erichen, Institute of Computing Technology,
Chinese Academy of Sciences

OpenBSD-Commit-ID: 5b3cc987a64749c94b20e12755db32a83f8f01e6
binary change

OpenBSD-Commit-ID: 6527baa1f07b7fdf42ca84531a13ae3ff2c0dbc8
OpenBSD-Commit-ID: 0c70f26de19babb2557a7a95ae7057d996a2c3f8
OpenBSD-Commit-ID: d003b300b0062d8e5951b84e8e09bd8d98cfe562
sshd_config Match blocks; reported by Alex Harrison

OpenBSD-Commit-ID: 2d8866b841fc92e6e079e3f37590ba5948531b3d
of awk.

OpenBSD-Regress-ID: aa5fac0e3ee8f518794d3361d537090c6e3f0bec
OpenBSD-Regress-ID: 23084bcf86071a7fe0c121552ec6e0b208cc7e28
OpenBSD-Regress-ID: 30770cad71ca060aaaa05e4bdd0ea8941b768c6b
This lets us skip them in Portable on platforms that don't support IPv6
all in one place, removing diffs from within the tests themselves and
making syncs easier.

OpenBSD-Regress-ID: be5d2d67c28f8134f84e8baab09f303be8ceb626
and test IPv6 parsing if found. This should always be enabled on OpenBSD,
but allows us to use the same test in Portable without modifications
that make syncs harder.

OpenBSD-Regress-ID: 80dce2465e9414695d878a9af18a3d75711f7861
the packet code as this provides context of the failing peer (address, port,
user, etc). Based on patch from Dag-Erling Smørgrav
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

OpenBSD-Commit-ID: 2e50ab08ab697722230f5d7dbebc9ea3c4f2931b
daztucker and others added 29 commits August 3, 2026 18:19
The change making ECC required also incorrectly made EC_KEY_METHOD_new
required, causing builds with BoringSSL to fail.
These fail at runtime, so disable until we figure out why.
OpenBSD-Regress-ID: 3ba8907d381fb738578ba2090d4b2f22d35a555a
up the user's keys from ~/.ssh

OpenBSD-Regress-ID: 5295a8cefe1d2def5c8b10f9d60d9bb7a350d316
This is documented to be allowed, and was up until 10.4p1 when a
transcription error in the config handling rework reverted it to
global-only, ie not allowed inside Match.  bz#3987.
mlkem768{brainpoolp256r1,nistp256}-sha256 KEXes

OpenBSD-Commit-ID: e9a9b01a19ed3ccdd82c7fc4c77395495b28faf9
OpenBSD-Commit-ID: 7f0f8e7f610f6af6890cb10915bf316f23651505
remote forwarding is added via the local session multiplexing socket while a
remote forwarding open request is pending with the server.

Report and fix from Brian Mingus of Cognatory

OpenBSD-Commit-ID: c7888d566576386d0e96859f9ec7310a1e2d3609
locked, otherwise forwarding sessions established with an agent was locked
will be treated as local, rather than remote.

Reported by sn0x-sharma

OpenBSD-Commit-ID: 524f210c6f2b3a06e0a2f6d0af5188a9a75fa2c7
touch-required and verify-required flags on FIDO private keys when resetting
the passphrase.

feedback/ok tb@

OpenBSD-Commit-ID: 8895e62eae5778711fe7dd6c09f8679acb2e6674
OpenBSD-Commit-ID: 451ba42a5dc88723a0b8837d4583957f18edbf40
markus

OpenBSD-Commit-ID: 0fcb5943abe5476e42983dcfc4c400e39e5db6a7
Some versions of clang-19 report:
error: invalid feature combination:  +avx10.1-256; will be promoted to
avx10.1-512 [-Werror,-Winvalid-feature-combination]
stuck server from blocking a many-host keyscan; from Thomas Yiu

ok dtucker@ markus@

OpenBSD-Commit-ID: 4970af00975119ebf9c1e0e132e3317b72ac0c2e
release (it will be back soon)

OpenBSD-Commit-ID: 2466825e05a2cae6b0cb5fa34f39792a0b5a46d3
OpenBSD-Commit-ID: 047bc46c0a58babdf702e01b8ffc7728d404cb9c
from Thomas Yiu

OpenBSD-Regress-ID: 86a25553c75bddc6fc239dc272aca97c61047d22
On some of the longer algorithms in hpnssh the
2900 byte offset was landing in the wrong location
of the userauth packet and caused errors in the test.
for fips_enabled. Reported by whoschek@github. Issue #158.
@rapier1
rapier1 merged commit 1bd5619 into master Sep 15, 2026
2 of 170 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants