Skip to content

Port OpenSSH 10.6 to HPN-SSH - #166

Merged
rapier1 merged 126 commits into
masterfrom
dev_minor
Oct 8, 2026
Merged

rapier1 merged 126 commits into
masterfrom
dev_minor

Conversation

@rapier1

@rapier1 rapier1 commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

No functionality changes. Straightforward port process. Passes all regression and CI tests.

djmdjm and others added 30 commits August 12, 2026 09:29
The original upstream location of x11-ssh-askpass is gone.  Replace with
its archive.org page for now, similar to what Debian uses.
OpenBSD-Commit-ID: 0750536f5669c41097e2178d54ca518ef9580770
This has been removed in OS X SDK >= 27, so if it's not present then
don't enable the corresponding sandbox.
Only display the last 50 lines to keep log volume down.
On Ubuntu 26.04, we need the crypt(4) from libcrypt to support
the "yescrypt" and other advanced password format.
The Yubico PPA doesn't have the full set of versions+arch packages, so
continue if a given install fails.  Should fix tests on
ubuntu-26.04-arm.
Azerbaijani and Crimean Tatar also have the i/I problem.

bz3991; ok dtucker
The Yubico PPA does not have ubuntu 26.04 arm64 binaries.
Fixes redefinition warning on recent Linuxes where the declarations for
le32toh and friends are behind _DEFAULT_SOURCE.
During the refactor of server option parsing, the ability to set
PAMServiceName in Match blocks was accidentally disabled.

Reported by Kanishka De Silva; ok markus
some platforms. ok djm@

OpenBSD-Commit-ID: 020416d345c31e967f07a3e483d2e5b8e5bfa5c7
ok schwarze@ sthen@ krw@

OpenBSD-Commit-ID: adef73df2ccb7eac0e16a521f4dce6b8a72696b7
ssh-mldsa44-ed25519, so use it instead of the vendored "@openssh.com" name.

Note: this replaces the vendored name, which was only marked as
experimental and not enabled by default.cw

If you have ssh-mldsa44-ed25519@openssh.com keys manually configured
in sshd, then you will need to remove them from sshd_config and
restart.

OpenBSD-Commit-ID: bace7031444413274b6414df576c00f38801fd6e
OpenBSD-Commit-ID: 9acf6b8403db2ded4cc4d25e13bfe24835307439
In the seccomp sandbox, restrict use of mremap(2) to only permit
its use with the MREMAP_MAYMOVE flag and specifically not the
MREMAP_FIXED flag, as the latter may have some use as part of an
attack chain.

Reported by: Mohammad Hossein Abedini <mhmd.abedinii@gmail.com>

ok deraadt@
Disable this as a compilation error for -Werror builds until we
clean them all up.
no-op for some time now

OK djm@

OpenBSD-Commit-ID: c272de443c8fb72f470a5e1fa482d5dae5536e85
OpenBSD-Commit-ID: 272127bb56551ff1e6d18352627a77fad003ff27
page (-O control commands, -Q query options, and private key file names) into
tagged lists to make them more readable; no content change intended. OK
naddy@; general direction requested by deraadt@.

OpenBSD-Commit-ID: 63c5cb7ad90fa401f7e97ce8d4c7e0d6f40530ec
with the pre-existing code to validate it is an absolute path.  Here's a bit
of history:  sshd became the first fork+exec privsep daemon (I did some
arm-twisting). That privsep has recently turned into fork+exec different
binaries but the SIGHUP restart code still want to re-run the binary from the
original path. The rc startup sequence always passes an absolute path.  sshd
was paranoid and validated it.  That made hand-restarts of sshd without
absolute paths not work.  getexecpath(3) improves the ergonomics. ok djm

OpenBSD-Commit-ID: b84759d60f689f94a4fb45f43a7436ce62e35487
required

The -p option causes the mkdir and lmkdir commands to create any missing
intermediate directories. If '-p' is specified, it is not considered an
error if a directory already exists.

With / OK djm@

OpenBSD-Commit-ID: 72e4d4cf2e254959af5a0885e3f3a176846f4345
job and others added 29 commits October 1, 2026 08:50
maximum payload length

From a report by Oleh Konko (1seal)

OK djm@

OpenBSD-Commit-ID: a0d3e7aa432777c28bfe23e5447ac117d6c151d9
> avoid race between multiple processes attempting to
>
> establish multiplexing control socket by moving socket creation earlier in
> ssh(1)'s life. Patch from Jens Rosenboom via bz3971

It caused problems with ControlPersist sessions.

Reported by semarie@ job@

OpenBSD-Commit-ID: b78a34d605c47cb145e16a3bba295caa0e9db680
reachable in normal operation since a nul would cause a filename mismatch,
but potentially possible if being used an unusual configuration such as a
custom filter.

Reported by Chua Wei Xun <weixun.chua at e-cq.net>, ok djm@

OpenBSD-Commit-ID: 1fb35933acdc11dd66bdba780bd9e100bda69079
is invalid; avoids max-pk-ok feature presenting a username validity oracle

analysis and patch from Chris Rohlf in collaboration with Claude and
Anthropic Research

OpenBSD-Commit-ID: c05d01b1724c76c9e30ed5e0f06686820f94bce8
server for SSH_FXP_REALPATH or SSH2_FXP_READDIR replies, as these can be used
in some situations to decide the destination path for recursive transfers.

Report and patch from Junghoon Cho

OpenBSD-Commit-ID: ad357002a1b75c87113f01086a9f0c12c36082d8
being incorrectly reported as 256. The private key length for these composite
keys is 512 bits. This value is only used for display.

Spotted by Yiyue Wang

OpenBSD-Commit-ID: 5ba7c8a9a457434ca0652042e1c5940bbc6ef5e0
accepted when writing an OpenSSH-format private key or when loading one. This
limit is set pretty high (1<<20), but ensures that a service that is passed a
bad key with an ridiculously high number of rounds will _eventually_ complete
parsing it.

Also bump the default number of KDF rounds from 24 to 32 (this is a
linear increase, not like bcrypt(3) which is exponential).

Pointed out by Aris Adamantiadis

OpenBSD-Commit-ID: 843ff37b066b2879f4579a784e42a3c9d22b2ddc
OpenBSD-Commit-ID: 0d17bf0ad02c8c0d897d9d01d1e4eb0f65ea749c
old way of performing a remote-to-remote copy that was basically executed scp
on the remote host. It barely worked (needing agent forwarding enabled or
usable credentials on the remote host) and has largely been replaced by a
better SFTP-protocol remote-to-remote copy that runs through the host
performing the copy.

We'll disable this option in a release or two; ok dtucker@

OpenBSD-Commit-ID: dc273300651e581c3db18edf21f2b05ceac60fd7
blocks and make it first-match-wins as documented. bz4013

OpenBSD-Commit-ID: e2efc85b42bbf7067ece4f1ab12d7d02ec6c3e12
spotted while fixing bz4013

OpenBSD-Commit-ID: 35ef4524da0d03a439751f7bcd4847f76d93ec7f
Native ARM32 runners are no longer supported by Github.
It can no longer install the sudo package and is covered by the
selfhosted VMs.
supplied user name, disallowing '$' and '\'. Reported by SecBuddyF KeenLab
Tencent (CodeBuddy Security).

OpenBSD-Commit-ID: 13671c178f492af63b5c1296f284818c7809ed9a
It can cause problems on some platforms, in particular NetBSD <11 since
it will cause function pointer comparisons in atomicio to fail and some
things including scp to hang.  Previously we had a workaround but that
was removed in a765b86.  See NetBSD bug 45200 and pkgsrc bug pkg/60563.
On platforms that require root privilege for the post-authentication
sshd-session process (e.g. OpenServer 5, QNX 6), disable and restrict
a number of features that assume user privilege.

This includes GatewayPorts, StreamLocalForwarding and -R forwardings
binding to ports <1024
Also add a deprecation warning when the lack FD passing support and also
requires root for the post-auth sshd-session process
OpenBSD-Regress-ID: 3fdaea9d640ce1d4950223b66f26f6f1ab46f4c9
OpenBSD-Regress-ID: be34cb5cf08f1025413df248cb7a65e18ca3e2a1
OpenBSD-Commit-ID: 907104c6a6e058860522bf752663d71b37bfa43f
  Seems to be straighforward with no conflicts in the hpn-ssh code.
  When OpenSSH uses PACKET_MAX_SIZE we just need to replace it with
  packet_max_size. See the comment in packet.c for rational.
  This worked previously because of a mixup on my end. However,
  removing the -s option from scp means that my shame is now
  on display for all to see. The solution is to remove the sftp
  arm which never should have been tested anyway because
  we don't support resume in sftp.
@rapier1
rapier1 merged commit 2c7cc55 into master Oct 8, 2026
181 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants