Repository navigation
Conversation
The original upstream location of x11-ssh-askpass is gone. Replace with its archive.org page for now, similar to what Debian uses.
OpenBSD-Commit-ID: 0750536f5669c41097e2178d54ca518ef9580770
This has been removed in OS X SDK >= 27, so if it's not present then don't enable the corresponding sandbox.
Only display the last 50 lines to keep log volume down.
On Ubuntu 26.04, we need the crypt(4) from libcrypt to support the "yescrypt" and other advanced password format.
The Yubico PPA doesn't have the full set of versions+arch packages, so continue if a given install fails. Should fix tests on ubuntu-26.04-arm.
Azerbaijani and Crimean Tatar also have the i/I problem. bz3991; ok dtucker
The Yubico PPA does not have ubuntu 26.04 arm64 binaries.
Fixes redefinition warning on recent Linuxes where the declarations for le32toh and friends are behind _DEFAULT_SOURCE.
During the refactor of server option parsing, the ability to set PAMServiceName in Match blocks was accidentally disabled. Reported by Kanishka De Silva; ok markus
some platforms. ok djm@ OpenBSD-Commit-ID: 020416d345c31e967f07a3e483d2e5b8e5bfa5c7
ok schwarze@ sthen@ krw@ OpenBSD-Commit-ID: adef73df2ccb7eac0e16a521f4dce6b8a72696b7
ssh-mldsa44-ed25519, so use it instead of the vendored "@openssh.com" name. Note: this replaces the vendored name, which was only marked as experimental and not enabled by default.cw If you have ssh-mldsa44-ed25519@openssh.com keys manually configured in sshd, then you will need to remove them from sshd_config and restart. OpenBSD-Commit-ID: bace7031444413274b6414df576c00f38801fd6e
OpenBSD-Commit-ID: 9acf6b8403db2ded4cc4d25e13bfe24835307439
In the seccomp sandbox, restrict use of mremap(2) to only permit its use with the MREMAP_MAYMOVE flag and specifically not the MREMAP_FIXED flag, as the latter may have some use as part of an attack chain. Reported by: Mohammad Hossein Abedini <mhmd.abedinii@gmail.com> ok deraadt@
Disable this as a compilation error for -Werror builds until we clean them all up.
no-op for some time now OK djm@ OpenBSD-Commit-ID: c272de443c8fb72f470a5e1fa482d5dae5536e85
OpenBSD-Commit-ID: 272127bb56551ff1e6d18352627a77fad003ff27
page (-O control commands, -Q query options, and private key file names) into tagged lists to make them more readable; no content change intended. OK naddy@; general direction requested by deraadt@. OpenBSD-Commit-ID: 63c5cb7ad90fa401f7e97ce8d4c7e0d6f40530ec
with the pre-existing code to validate it is an absolute path. Here's a bit of history: sshd became the first fork+exec privsep daemon (I did some arm-twisting). That privsep has recently turned into fork+exec different binaries but the SIGHUP restart code still want to re-run the binary from the original path. The rc startup sequence always passes an absolute path. sshd was paranoid and validated it. That made hand-restarts of sshd without absolute paths not work. getexecpath(3) improves the ergonomics. ok djm OpenBSD-Commit-ID: b84759d60f689f94a4fb45f43a7436ce62e35487
required The -p option causes the mkdir and lmkdir commands to create any missing intermediate directories. If '-p' is specified, it is not considered an error if a directory already exists. With / OK djm@ OpenBSD-Commit-ID: 72e4d4cf2e254959af5a0885e3f3a176846f4345
maximum payload length From a report by Oleh Konko (1seal) OK djm@ OpenBSD-Commit-ID: a0d3e7aa432777c28bfe23e5447ac117d6c151d9
> avoid race between multiple processes attempting to > > establish multiplexing control socket by moving socket creation earlier in > ssh(1)'s life. Patch from Jens Rosenboom via bz3971 It caused problems with ControlPersist sessions. Reported by semarie@ job@ OpenBSD-Commit-ID: b78a34d605c47cb145e16a3bba295caa0e9db680
reachable in normal operation since a nul would cause a filename mismatch, but potentially possible if being used an unusual configuration such as a custom filter. Reported by Chua Wei Xun <weixun.chua at e-cq.net>, ok djm@ OpenBSD-Commit-ID: 1fb35933acdc11dd66bdba780bd9e100bda69079
is invalid; avoids max-pk-ok feature presenting a username validity oracle analysis and patch from Chris Rohlf in collaboration with Claude and Anthropic Research OpenBSD-Commit-ID: c05d01b1724c76c9e30ed5e0f06686820f94bce8
server for SSH_FXP_REALPATH or SSH2_FXP_READDIR replies, as these can be used in some situations to decide the destination path for recursive transfers. Report and patch from Junghoon Cho OpenBSD-Commit-ID: ad357002a1b75c87113f01086a9f0c12c36082d8
being incorrectly reported as 256. The private key length for these composite keys is 512 bits. This value is only used for display. Spotted by Yiyue Wang OpenBSD-Commit-ID: 5ba7c8a9a457434ca0652042e1c5940bbc6ef5e0
accepted when writing an OpenSSH-format private key or when loading one. This limit is set pretty high (1<<20), but ensures that a service that is passed a bad key with an ridiculously high number of rounds will _eventually_ complete parsing it. Also bump the default number of KDF rounds from 24 to 32 (this is a linear increase, not like bcrypt(3) which is exponential). Pointed out by Aris Adamantiadis OpenBSD-Commit-ID: 843ff37b066b2879f4579a784e42a3c9d22b2ddc
OpenBSD-Commit-ID: 0d17bf0ad02c8c0d897d9d01d1e4eb0f65ea749c
old way of performing a remote-to-remote copy that was basically executed scp on the remote host. It barely worked (needing agent forwarding enabled or usable credentials on the remote host) and has largely been replaced by a better SFTP-protocol remote-to-remote copy that runs through the host performing the copy. We'll disable this option in a release or two; ok dtucker@ OpenBSD-Commit-ID: dc273300651e581c3db18edf21f2b05ceac60fd7
blocks and make it first-match-wins as documented. bz4013 OpenBSD-Commit-ID: e2efc85b42bbf7067ece4f1ab12d7d02ec6c3e12
spotted while fixing bz4013 OpenBSD-Commit-ID: 35ef4524da0d03a439751f7bcd4847f76d93ec7f
Native ARM32 runners are no longer supported by Github.
It can no longer install the sudo package and is covered by the selfhosted VMs.
supplied user name, disallowing '$' and '\'. Reported by SecBuddyF KeenLab Tencent (CodeBuddy Security). OpenBSD-Commit-ID: 13671c178f492af63b5c1296f284818c7809ed9a
It can cause problems on some platforms, in particular NetBSD <11 since it will cause function pointer comparisons in atomicio to fail and some things including scp to hang. Previously we had a workaround but that was removed in a765b86. See NetBSD bug 45200 and pkgsrc bug pkg/60563.
On platforms that require root privilege for the post-authentication sshd-session process (e.g. OpenServer 5, QNX 6), disable and restrict a number of features that assume user privilege. This includes GatewayPorts, StreamLocalForwarding and -R forwardings binding to ports <1024
Also add a deprecation warning when the lack FD passing support and also requires root for the post-auth sshd-session process
OpenBSD-Regress-ID: 3fdaea9d640ce1d4950223b66f26f6f1ab46f4c9
OpenBSD-Regress-ID: be34cb5cf08f1025413df248cb7a65e18ca3e2a1
OpenBSD-Commit-ID: 907104c6a6e058860522bf752663d71b37bfa43f
Seems to be straighforward with no conflicts in the hpn-ssh code.
When OpenSSH uses PACKET_MAX_SIZE we just need to replace it with packet_max_size. See the comment in packet.c for rational.
This worked previously because of a mixup on my end. However, removing the -s option from scp means that my shame is now on display for all to see. The solution is to remove the sftp arm which never should have been tested anyway because we don't support resume in sftp.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No functionality changes. Straightforward port process. Passes all regression and CI tests.