]> git.ipfire.org Git - thirdparty/openssh-portable.git/log
thirdparty/openssh-portable.git
14 years ago20110128
Damien Miller [Fri, 4 Feb 2011 00:43:04 +0000 (11:43 +1100)] 
20110128
 - (djm) [openbsd-compat/port-linux.c] Check whether SELinux is enabled
   before attempting setfscreatecon(). Check whether matchpathcon()
   succeeded before using its result. Patch from cjwatson AT debian.org;
   bz#1851

14 years agocherry-pick
Damien Miller [Fri, 4 Feb 2011 00:42:11 +0000 (11:42 +1100)] 
cherry-pick

20110125
 - (djm) [configure.ac Makefile.in ssh.c openbsd-compat/port-linux.c
   openbsd-compat/port-linux.h] Move SELinux-specific code from ssh.c to
   port-linux.c to avoid compilation errors. Add -lselinux to ssh when
   building with SELinux support to avoid linking failure; report from
   amk AT spamfence.net; ok dtucker

14 years ago - (djm) [openbsd-compat/port-linux.c] Check whether SELinux is enabled
Damien Miller [Thu, 27 Jan 2011 23:30:18 +0000 (10:30 +1100)] 
 - (djm) [openbsd-compat/port-linux.c] Check whether SELinux is enabled
   before attempting setfscreatecon(). Check whether matchpathcon()
   succeeded before using its result. Patch from cjwatson AT debian.org;
   bz#1851

14 years ago20110127
Tim Rice [Wed, 26 Jan 2011 20:38:57 +0000 (12:38 -0800)] 
20110127
 - (tim) [configure.ac] Consistent M4 quoting throughout, updated obsolete
   AC_TRY_COMPILE with AC_COMPILE_IFELSE, updated obsolete AC_TRY_LINK with
   AC_LINK_IFELSE, updated obsolete AC_TRY_RUN with AC_RUN_IFELSE, misc white
   space changes for consistency/readability. Makes autoconf 2.68 happy.
   "Nice work" djm

14 years ago20110127
Tim Rice [Wed, 26 Jan 2011 20:32:12 +0000 (12:32 -0800)] 
20110127
 - (tim) [config.guess config.sub] Sync with upstream.

14 years ago - (djm) [configure.ac Makefile.in ssh.c openbsd-compat/port-linux.c
Damien Miller [Tue, 25 Jan 2011 01:16:15 +0000 (12:16 +1100)] 
 - (djm) [configure.ac Makefile.in ssh.c openbsd-compat/port-linux.c
   openbsd-compat/port-linux.h] Move SELinux-specific code from ssh.c to
   port-linux.c to avoid compilation errors. Add -lselinux to ssh when
   building with SELinux support to avoid linking failure; report from
   amk AT spamfence.net; ok dtucker

14 years ago - (djm) Release 5.7p1 V_5_7_P1
Damien Miller [Sat, 22 Jan 2011 09:25:11 +0000 (20:25 +1100)] 
 - (djm) Release 5.7p1

14 years agotrim entries older than 5.5p1
Damien Miller [Sat, 22 Jan 2011 09:24:34 +0000 (20:24 +1100)] 
trim entries older than 5.5p1

14 years ago - (djm) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec]
Damien Miller [Sat, 22 Jan 2011 09:23:10 +0000 (20:23 +1100)] 
 - (djm) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec]
   [contrib/suse/openssh.spec] update versions in docs and spec files.

14 years ago - OpenBSD CVS Sync
Damien Miller [Sat, 22 Jan 2011 09:21:33 +0000 (20:21 +1100)] 
 - OpenBSD CVS Sync
   - djm@cvs.openbsd.org 2011/01/22 09:18:53
     [version.h]
     crank to OpenSSH-5.7

14 years ago - (dtucker) [configure.ac openbsd-compat/openssl-compat.{c,h}] Add
Darren Tucker [Fri, 21 Jan 2011 22:37:01 +0000 (09:37 +1100)] 
 - (dtucker) [configure.ac openbsd-compat/openssl-compat.{c,h}] Add
   RSA_get_default_method() for the benefit of openssl versions that don't
   have it (at least openssl-engine-0.9.6b).  Found and tested by Kevin Brott,
   ok djm@.

14 years ago - (djm) [configure.ac] Disable ECC on OpenSSL <0.9.8g. Releases prior to
Damien Miller [Wed, 19 Jan 2011 12:12:27 +0000 (23:12 +1100)] 
 - (djm) [configure.ac] Disable ECC on OpenSSL <0.9.8g. Releases prior to
   0.9.8 lacked it, and 0.9.8a through 0.9.8d have proven buggy in pre-
   release testing (random crashes and failure to load ECC keys).
   ok dtucker@

14 years ago - (tim) [contrib/caldera/openssh.spec] Use CFLAGS from Makefile instead
Tim Rice [Wed, 19 Jan 2011 04:47:04 +0000 (20:47 -0800)] 
 - (tim) [contrib/caldera/openssh.spec] Use CFLAGS from Makefile instead
   of RPM so build completes. Signatures were changed to .asc since 4.1p1.

14 years ago- (dtucker) [LICENCE Makefile.in audit-bsm.c audit-linux.c audit.c audit.h
Darren Tucker [Mon, 17 Jan 2011 10:15:27 +0000 (21:15 +1100)] 
- (dtucker) [LICENCE Makefile.in audit-bsm.c audit-linux.c audit.c audit.h
   configure.ac defines.h loginrec.c]  Bug #1402: add linux audit subsystem
   support, based on patches from Tomas Mraz and jchadima at redhat.

14 years ago - (dtucker) [openbsd-compat/port-linux.c] Fix minor bug caught by -Werror on
Darren Tucker [Mon, 17 Jan 2011 07:50:22 +0000 (18:50 +1100)] 
 - (dtucker) [openbsd-compat/port-linux.c] Fix minor bug caught by -Werror on
   the tinderbox.

14 years ago - (tim) [regress/agent-getpeereid.sh] shell portability fix.
Tim Rice [Mon, 17 Jan 2011 06:53:56 +0000 (22:53 -0800)] 
 - (tim) [regress/agent-getpeereid.sh] shell portability fix.

14 years ago - (djm) [configure.ac regress/agent-getpeereid.sh regress/multiplex.sh]
Damien Miller [Mon, 17 Jan 2011 05:17:09 +0000 (16:17 +1100)] 
 - (djm) [configure.ac regress/agent-getpeereid.sh regress/multiplex.sh]
   [regress/sftp-glob.sh regress/test-exec.sh] Rework how feature tests are
   disabled on platforms that do not support them; add a "config_defined()"
   shell function that greps for defines in config.h and use them to decide
   on feature tests.
   Convert a couple of existing grep's over config.h to use the new function
   Add a define "FILESYSTEM_NO_BACKSLASH" for filesystem that can't represent
   backslash characters in filenames, enable it for Cygwin and use it to turn
   of tests for quotes backslashes in sftp-glob.sh.
   based on discussion with vinschen AT redhat.com and dtucker@; ok dtucker@

14 years ago - (dtucker) [openbsd-compat/port-linux.c] Bug #1838: Add support for the new
Darren Tucker [Mon, 17 Jan 2011 00:55:59 +0000 (11:55 +1100)] 
 - (dtucker) [openbsd-compat/port-linux.c] Bug #1838: Add support for the new
   Linux OOM-killer magic values that changed in 2.6.36 kernels, with fallback
   to the old values.  Feedback from vapier at gentoo org and djm, ok djm.

14 years ago - (djm) [regress/agent-getpeereid.sh] leave stdout attached when running
Damien Miller [Mon, 17 Jan 2011 00:52:40 +0000 (11:52 +1100)] 
 - (djm) [regress/agent-getpeereid.sh] leave stdout attached when running
   ssh-add to avoid $SUDO failures on Linux

14 years ago - (djm) [regress/agent-ptrace.sh] Fix false failure on OS X by adding
Damien Miller [Mon, 17 Jan 2011 00:20:18 +0000 (11:20 +1100)] 
 - (djm) [regress/agent-ptrace.sh] Fix false failure on OS X by adding
   its unique snowflake of a gdb error to the ones we look for.

14 years ago - (djm) [regress/Makefile] use $TEST_SSH_KEYGEN instead of the one in
Damien Miller [Sun, 16 Jan 2011 23:51:40 +0000 (10:51 +1100)] 
 - (djm) [regress/Makefile] use $TEST_SSH_KEYGEN instead of the one in
   $PATH, fix cleanup of droppings; reported by openssh AT
   roumenpetrov.info; ok dtucker@

14 years ago - djm@cvs.openbsd.org 2011/01/16 12:05:59
Damien Miller [Sun, 16 Jan 2011 12:18:33 +0000 (23:18 +1100)] 
   - djm@cvs.openbsd.org 2011/01/16 12:05:59
     [clientloop.c]
     a couple more tweaks to the post-close protocol 1 stderr/stdout flush:
     now that we use atomicio(), convert them from while loops to if statements
     add test and cast to compile cleanly with -Wsigned

14 years ago - djm@cvs.openbsd.org 2011/01/16 11:50:36
Damien Miller [Sun, 16 Jan 2011 12:17:45 +0000 (23:17 +1100)] 
   - djm@cvs.openbsd.org 2011/01/16 11:50:36
     [sshconnect.c]
     reset the SIGPIPE handler when forking to execute child processes;
     ok dtucker@

14 years ago - djm@cvs.openbsd.org 2011/01/16 11:50:05
Damien Miller [Sun, 16 Jan 2011 12:16:53 +0000 (23:16 +1100)] 
   - djm@cvs.openbsd.org 2011/01/16 11:50:05
     [clientloop.c]
     Use atomicio when flushing protocol 1 std{out,err} buffers at
     session close. This was a latent bug exposed by setting a SIGCHLD
     handler and spotted by kevin.brott AT gmail.com; ok dtucker@

14 years ago - (dtucker) [Makefile.in configure.ac regress/kextype.sh] Skip sha256-based
Darren Tucker [Sun, 16 Jan 2011 07:28:09 +0000 (18:28 +1100)] 
 - (dtucker) [Makefile.in configure.ac regress/kextype.sh] Skip sha256-based
   on configurations that don't have it.

14 years agonot February yet...
Darren Tucker [Sun, 16 Jan 2011 07:24:04 +0000 (18:24 +1100)] 
not February yet...

14 years ago - (tim) [regress/cert-hostkey.sh] Add missing TEST_SSH_ECC guard around some
Tim Rice [Fri, 14 Jan 2011 06:36:14 +0000 (22:36 -0800)] 
 - (tim) [regress/cert-hostkey.sh] Add missing TEST_SSH_ECC guard around some
   ecdsa bits.

14 years ago - (tim) [regress/cert-hostkey.sh] Typo. Missing $ on variable name.
Tim Rice [Fri, 14 Jan 2011 06:20:27 +0000 (22:20 -0800)] 
 - (tim) [regress/cert-hostkey.sh] Typo. Missing $ on variable name.

14 years ago - (djm) [Makefile.in] Use shell test to disable ecdsa key generating in
Damien Miller [Fri, 14 Jan 2011 03:47:37 +0000 (14:47 +1100)] 
 - (djm) [Makefile.in] Use shell test to disable ecdsa key generating in
   host-key-force target rather than a substitution that is replaced with a
   comment so that the Makefile.in is still a syntactically valid Makefile
   (useful to run the distprep target)

14 years ago - djm@cvs.openbsd.org 2011/01/13 21:55:25
Damien Miller [Fri, 14 Jan 2011 01:01:50 +0000 (12:01 +1100)] 
   - djm@cvs.openbsd.org 2011/01/13 21:55:25
     [PROTOCOL.mux]
     correct protocol names and add a couple of missing protocol number
     defines; patch from bert.wesarg AT googlemail.com

14 years ago - djm@cvs.openbsd.org 2011/01/13 21:54:53
Damien Miller [Fri, 14 Jan 2011 01:01:29 +0000 (12:01 +1100)] 
   - djm@cvs.openbsd.org 2011/01/13 21:54:53
     [mux.c]
     correct error messages; patch from bert.wesarg AT googlemail.com

14 years ago - (djm) [regress/kextype.sh] Testing diffie-hellman-group-exchange-sha256
Damien Miller [Thu, 13 Jan 2011 11:05:14 +0000 (22:05 +1100)] 
 - (djm) [regress/kextype.sh] Testing diffie-hellman-group-exchange-sha256
   should not depend on ECC support

14 years ago - (djm) [myproposal.h] Fix reversed OPENSSL_VERSION_NUMBER test and bad
Damien Miller [Thu, 13 Jan 2011 11:00:20 +0000 (22:00 +1100)] 
 - (djm) [myproposal.h] Fix reversed OPENSSL_VERSION_NUMBER test and bad
   #define that was causing diffie-hellman-group-exchange-sha256 to be
   incorrectly disabled

14 years ago - (djm) [regress/Makefile] add a few more generated files to the clean
Damien Miller [Thu, 13 Jan 2011 10:08:27 +0000 (21:08 +1100)] 
 - (djm) [regress/Makefile] add a few more generated files to the clean
   target

14 years ago - (djm) [entropy.c] cast OPENSSL_VERSION_NUMBER to u_long to avoid
Damien Miller [Thu, 13 Jan 2011 10:05:27 +0000 (21:05 +1100)] 
 - (djm) [entropy.c] cast OPENSSL_VERSION_NUMBER to u_long to avoid
   gcc warning on platforms where it defaults to int

14 years ago - (tim) [Makefile.in configure.ac opensshd.init.in] Add support for generating
Tim Rice [Thu, 13 Jan 2011 06:35:43 +0000 (22:35 -0800)] 
 - (tim) [Makefile.in configure.ac opensshd.init.in] Add support for generating
   ecdsa keys. ok djm.

14 years ago - (tim) [Makefile.in] test the ECC bits if we have the capability. ok djm
Tim Rice [Thu, 13 Jan 2011 03:06:31 +0000 (19:06 -0800)] 
 - (tim) [Makefile.in] test the ECC bits if we have the capability. ok djm

14 years ago - (djm) [misc.c] include time.h for nanosleep() prototype
Damien Miller [Thu, 13 Jan 2011 01:21:34 +0000 (12:21 +1100)] 
 - (djm) [misc.c] include time.h for nanosleep() prototype

14 years ago - (djm) [configure.ac] Fix broken test for gcc >= 4.4 with per-compiler
Damien Miller [Wed, 12 Jan 2011 05:00:37 +0000 (16:00 +1100)] 
 - (djm) [configure.ac] Fix broken test for gcc >= 4.4 with per-compiler
   flag tests that don't depend on gcc version at all; suggested by and
   ok dtucker@

14 years ago - (djm) [configure.ac] Turn on -Wno-unused-result for gcc >= 4.4 to avoid
Damien Miller [Wed, 12 Jan 2011 02:34:02 +0000 (13:34 +1100)] 
 - (djm) [configure.ac] Turn on -Wno-unused-result for gcc >= 4.4 to avoid
   silly warnings on write() calls we don't care succeed or not.

14 years ago - djm@cvs.openbsd.org 2011/01/12 01:53:14
Damien Miller [Wed, 12 Jan 2011 02:32:03 +0000 (13:32 +1100)] 
   - djm@cvs.openbsd.org 2011/01/12 01:53:14
     avoid some integer overflows mostly with GLOB_APPEND and GLOB_DOOFFS
     and sanity check arguments (these will be unnecessary when we switch
     struct glob members from being type into to size_t in the future);
     "looks ok" tedu@ feedback guenther@

14 years ago - nicm@cvs.openbsd.org 2010/10/08 21:48:42
Damien Miller [Wed, 12 Jan 2011 02:30:18 +0000 (13:30 +1100)] 
   - nicm@cvs.openbsd.org 2010/10/08 21:48:42
     [openbsd-compat/glob.c]
     Extend GLOB_LIMIT to cover readdir and stat and bump the malloc limit
     from ARG_MAX to 64K.
     Fixes glob-using programs (notably ftp) able to be triggered to hit
     resource limits.
     Idea from a similar NetBSD change, original problem reported by jasper@.
     ok millert tedu jasper

14 years ago - djm@cvs.openbsd.org 2011/01/11 06:13:10
Damien Miller [Tue, 11 Jan 2011 06:20:29 +0000 (17:20 +1100)] 
   - djm@cvs.openbsd.org 2011/01/11 06:13:10
     [clientloop.c ssh-keygen.c sshd.c]
     some unsigned long long casts that make things a bit easier for
     portable without resorting to dropping PRIu64 formats everywhere

14 years ago - djm@cvs.openbsd.org 2011/01/11 06:06:09
Damien Miller [Tue, 11 Jan 2011 06:20:05 +0000 (17:20 +1100)] 
   - djm@cvs.openbsd.org 2011/01/11 06:06:09
     [sshlogin.c]
     fd leak on error paths; from zinovik@
     NB. Id sync only; we use loginrec.c that was also audited and fixed
     recently

14 years ago - djm@cvs.openbsd.org 2011/01/08 10:51:51
Damien Miller [Tue, 11 Jan 2011 06:18:56 +0000 (17:18 +1100)] 
   - djm@cvs.openbsd.org 2011/01/08 10:51:51
     [clientloop.c]
     use host and not options.hostname, as the latter may have unescaped
     substitution characters

14 years ago - (djm) [platform.c] Some missing includes that show up under -Werror
Damien Miller [Tue, 11 Jan 2011 06:02:23 +0000 (17:02 +1100)] 
 - (djm) [platform.c] Some missing includes that show up under -Werror

14 years ago - (tim) [regress/host-expand.sh] Fix for building outside of read only
Tim Rice [Mon, 10 Jan 2011 20:56:26 +0000 (12:56 -0800)] 
 - (tim) [regress/host-expand.sh] Fix for building outside of read only
   source tree.

14 years ago - (djm) [Makefile.in] list ssh_host_ecdsa key in PATHSUBS; spotted by
Damien Miller [Sat, 8 Jan 2011 22:19:50 +0000 (09:19 +1100)] 
 - (djm) [Makefile.in] list ssh_host_ecdsa key in PATHSUBS; spotted by
   openssh AT roumenpetrov.info

14 years ago - (djm) [regress/keytype.sh] s/echo -n/echon/ to repair failing regress
Damien Miller [Sat, 8 Jan 2011 10:58:20 +0000 (21:58 +1100)] 
 - (djm) [regress/keytype.sh] s/echo -n/echon/ to repair failing regress
   test on OSX and others. Reported by imorgan AT nas.nasa.gov

14 years ago - djm@cvs.openbsd.org 2011/01/06 23:01:35
Damien Miller [Thu, 6 Jan 2011 23:02:52 +0000 (10:02 +1100)] 
   - djm@cvs.openbsd.org 2011/01/06 23:01:35
     [sshconnect.c]
     reset SIGCHLD handler to SIG_DFL when execuring LocalCommand;
     ok markus@

14 years ago - djm@cvs.openbsd.org 2011/01/06 22:46:21
Damien Miller [Thu, 6 Jan 2011 22:54:20 +0000 (09:54 +1100)] 
   - djm@cvs.openbsd.org 2011/01/06 22:46:21
     [regress/Makefile regress/host-expand.sh]
     regress test for LocalCommand %n expansion from bert.wesarg AT
     googlemail.com; ok markus@

14 years ago - djm@cvs.openbsd.org 2011/01/06 22:23:02
Damien Miller [Thu, 6 Jan 2011 22:51:52 +0000 (09:51 +1100)] 
   - djm@cvs.openbsd.org 2011/01/06 22:23:02
     [clientloop.c]
     when exiting due to ServerAliveTimeout, mention the hostname that caused
     it (useful with backgrounded controlmaster)

14 years ago - djm@cvs.openbsd.org 2011/01/06 22:23:53
Damien Miller [Thu, 6 Jan 2011 22:51:17 +0000 (09:51 +1100)] 
   - djm@cvs.openbsd.org 2011/01/06 22:23:53
     [ssh.c]
     unbreak %n expansion in LocalCommand; patch from bert.wesarg AT
     googlemail.com; ok markus@

14 years ago - (djm) [regress/cert-hostkey.sh regress/cert-userkey.sh] fix shell test
Damien Miller [Thu, 6 Jan 2011 22:50:08 +0000 (09:50 +1100)] 
 - (djm) [regress/cert-hostkey.sh regress/cert-userkey.sh] fix shell test
   for no-ECC case. Patch from cristian.ionescu-idbohrn AT axis.com

14 years ago - otto@cvs.openbsd.org 2011/01/04 20:44:13
Damien Miller [Thu, 6 Jan 2011 11:44:44 +0000 (22:44 +1100)] 
   - otto@cvs.openbsd.org 2011/01/04 20:44:13
     [ssh-keyscan.c]
     handle ecdsa-sha2 with various key lengths; hint and ok djm@

14 years ago - djm@cvs.openbsd.org 2010/12/24 21:41:48
Damien Miller [Thu, 6 Jan 2011 11:44:18 +0000 (22:44 +1100)] 
   - djm@cvs.openbsd.org 2010/12/24 21:41:48
     [auth-options.c]
     don't send the actual forced command in a debug message; ok markus deraadt

14 years ago - djm@cvs.openbsd.org 2010/12/15 00:49:27
Damien Miller [Thu, 6 Jan 2011 11:43:44 +0000 (22:43 +1100)] 
   - djm@cvs.openbsd.org 2010/12/15 00:49:27
     [readpass.c]
     fix ControlMaster=ask regression
     reset SIGCHLD handler before fork (and restore it after) so we don't miss
     the the askpass child's exit status. Correct test for exit status/signal to
     account for waitpid() failure; with claudio@ ok claudio@ markus@

14 years ago - markus@cvs.openbsd.org 2010/12/14 11:59:06
Damien Miller [Thu, 6 Jan 2011 11:42:04 +0000 (22:42 +1100)] 
   - markus@cvs.openbsd.org 2010/12/14 11:59:06
     [sshconnect.c]
     don't mention key type in key-changed-warning, since we also print
     this warning if a new key type appears. ok djm@

14 years ago - jmc@cvs.openbsd.org 2010/12/09 14:13:33
Damien Miller [Thu, 6 Jan 2011 11:41:21 +0000 (22:41 +1100)] 
   - jmc@cvs.openbsd.org 2010/12/09 14:13:33
     [scp.1 scp.c]
     scp.1: grammer fix
     scp.c: add -3 to usage()

14 years ago - markus@cvs.openbsd.org 2010/12/08 22:46:03
Damien Miller [Thu, 6 Jan 2011 11:40:30 +0000 (22:40 +1100)] 
   - markus@cvs.openbsd.org 2010/12/08 22:46:03
     [scp.1 scp.c]
     add a new -3 option to scp: Copies between two remote hosts are
     transferred through the local host.  Without this option the data
     is copied directly between the two remote hosts. ok djm@ (bugzilla #1837)

14 years ago - (djm) [configure.ac Makefile.in] Use mandoc as preferred manpage
Damien Miller [Mon, 3 Jan 2011 21:16:27 +0000 (08:16 +1100)] 
 - (djm) [configure.ac Makefile.in] Use mandoc as preferred manpage
   formatter if it is present, followed by nroff and groff respectively.
   Fixes distprep target on OpenBSD (which has bumped groff/nroff to ports
   in favour of mandoc). feedback and ok tim

14 years ago - (djm) [Makefile.in] revert local hack I didn't intend to commit
Damien Miller [Mon, 3 Jan 2011 03:48:14 +0000 (14:48 +1100)] 
 - (djm) [Makefile.in] revert local hack I didn't intend to commit

14 years ago - (djm) [configure.ac] Check whether libdes is needed when building
Damien Miller [Sun, 2 Jan 2011 10:53:07 +0000 (21:53 +1100)] 
 - (djm) [configure.ac] Check whether libdes is needed when building
   with Heimdal krb5 support. On OpenBSD this library no longer exists,
   so linking it unconditionally causes a build failure; ok dtucker

14 years ago - (djm) [loginrec.c] Fix some fd leaks on error paths. ok dtucker
Damien Miller [Sun, 2 Jan 2011 10:43:59 +0000 (21:43 +1100)] 
 - (djm) [loginrec.c] Fix some fd leaks on error paths. ok dtucker

14 years ago - djm@cvs.openbsd.org 2010/12/08 04:02:47
Damien Miller [Sun, 26 Dec 2010 03:26:45 +0000 (14:26 +1100)] 
   - djm@cvs.openbsd.org 2010/12/08 04:02:47
     [ssh_config.5 sshd_config.5]
     explain that IPQoS arguments are separated by whitespace; iirc requested
     by jmc@ a while back

14 years agoId sync
Darren Tucker [Sat, 4 Dec 2010 23:34:08 +0000 (10:34 +1100)] 
Id sync

14 years ago - djm@cvs.openbsd.org 2010/12/04 00:21:19
Darren Tucker [Sat, 4 Dec 2010 22:45:50 +0000 (09:45 +1100)] 
   - djm@cvs.openbsd.org 2010/12/04 00:21:19
     [regress/sftp-cmds.sh]
     adjust for hard-link support

14 years ago - (dtucker) [regress/Makefile] Id sync.
Darren Tucker [Sat, 4 Dec 2010 22:29:31 +0000 (09:29 +1100)] 
 - (dtucker) [regress/Makefile] Id sync.

14 years ago - djm@cvs.openbsd.org 2010/12/04 13:31:37
Darren Tucker [Sat, 4 Dec 2010 22:03:31 +0000 (09:03 +1100)] 
   - djm@cvs.openbsd.org 2010/12/04 13:31:37
     [hostfile.c]
     fix fd leak; spotted and ok dtucker

14 years ago - djm@cvs.openbsd.org 2010/12/04 00:18:01
Darren Tucker [Sat, 4 Dec 2010 22:02:47 +0000 (09:02 +1100)] 
   - djm@cvs.openbsd.org 2010/12/04 00:18:01
     [sftp-server.c sftp.1 sftp-client.h sftp.c PROTOCOL sftp-client.c]
     add a protocol extension to support a hard link operation. It is
     available through the "ln" command in the client. The old "ln"
     behaviour of creating a symlink is available using its "-s" option
     or through the preexisting "symlink" command; based on a patch from
     miklos AT szeredi.hu in bz#1555; ok markus@

14 years ago - djm@cvs.openbsd.org 2010/12/03 23:55:27
Darren Tucker [Sat, 4 Dec 2010 22:01:47 +0000 (09:01 +1100)] 
   - djm@cvs.openbsd.org 2010/12/03 23:55:27
     [auth-rsa.c]
     move check for revoked keys to run earlier (in auth_rsa_key_allowed)
     bz#1829; patch from ldv AT altlinux.org; ok markus@

14 years ago - (dtucker) OpenBSD CVS Sync
Darren Tucker [Sat, 4 Dec 2010 22:00:30 +0000 (09:00 +1100)] 
 - (dtucker) OpenBSD CVS Sync
   - djm@cvs.openbsd.org 2010/12/03 23:49:26
     [schnorr.c]
     check that g^x^q === 1 mod p; recommended by JPAKE author Feng Hao
     (this code is still disabled, but apprently people are treating it as
     a reference implementation)

14 years ago - (dtucker) openbsd-compat/openssl-compat.c] remove sleep leftover from
Darren Tucker [Sat, 4 Dec 2010 21:46:05 +0000 (08:46 +1100)] 
 - (dtucker) openbsd-compat/openssl-compat.c] remove sleep leftover from
   debugging.  Spotted by djm.

14 years ago - (dtucker) [configure.ac moduli.c openbsd-compat/openssl-compat.{c,h}] Add
Darren Tucker [Sat, 4 Dec 2010 12:20:50 +0000 (23:20 +1100)] 
 - (dtucker) [configure.ac moduli.c openbsd-compat/openssl-compat.{c,h}]  Add
   shims for the new, non-deprecated OpenSSL key generation functions for
   platforms that don't have the new interfaces.

14 years ago - (djm) [openbsd-compat/bindresvport.c] Use arc4random_uniform(range)
Damien Miller [Thu, 2 Dec 2010 23:50:26 +0000 (10:50 +1100)] 
 - (djm) [openbsd-compat/bindresvport.c] Use arc4random_uniform(range)
   instead of (arc4random() % range)

14 years ago - djm@cvs.openbsd.org 2010/11/29 23:45:51
Damien Miller [Wed, 1 Dec 2010 01:21:51 +0000 (12:21 +1100)] 
   - djm@cvs.openbsd.org 2010/11/29 23:45:51
     [auth.c hostfile.c hostfile.h ssh.c ssh_config.5 sshconnect.c]
     [sshconnect.h sshconnect2.c]
     automatically order the hostkeys requested by the client based on
     which hostkeys are already recorded in known_hosts. This avoids
     hostkey warnings when connecting to servers with new ECDSA keys
     that are preferred by default; with markus@

14 years ago - markus@cvs.openbsd.org 2010/11/29 18:57:04
Damien Miller [Wed, 1 Dec 2010 01:03:39 +0000 (12:03 +1100)] 
   - markus@cvs.openbsd.org 2010/11/29 18:57:04
     [authfile.c]
     correctly load comment for encrypted rsa1 keys;
     report/fix Joachim Schipper; ok djm@

14 years ago - djm@cvs.openbsd.org 2010/11/26 05:52:49
Damien Miller [Wed, 1 Dec 2010 01:03:19 +0000 (12:03 +1100)] 
   - djm@cvs.openbsd.org 2010/11/26 05:52:49
     [scp.c]
     Pass through ssh command-line flags and options when doing remote-remote
     transfers, e.g. to enable agent forwarding which is particularly useful
     in this case; bz#1837 ok dtucker@

14 years ago - djm@cvs.openbsd.org 2010/11/25 04:10:09
Damien Miller [Wed, 1 Dec 2010 01:02:59 +0000 (12:02 +1100)] 
   - djm@cvs.openbsd.org 2010/11/25 04:10:09
     [session.c]
     replace close() loop for fds 3->64 with closefrom();
     ok markus deraadt dtucker

14 years ago - djm@cvs.openbsd.org 2010/11/24 01:24:14
Damien Miller [Wed, 1 Dec 2010 01:02:35 +0000 (12:02 +1100)] 
   - djm@cvs.openbsd.org 2010/11/24 01:24:14
     [channels.c]
     remove a debug() that pollutes stderr on client connecting to a server
     in debug mode (channel_close_fds is called transitively from the session
     code post-fork); bz#1719, ok dtucker

14 years ago - djm@cvs.openbsd.org 2010/11/23 23:57:24
Damien Miller [Wed, 1 Dec 2010 01:02:14 +0000 (12:02 +1100)] 
   - djm@cvs.openbsd.org 2010/11/23 23:57:24
     [clientloop.c]
     avoid NULL deref on receiving a channel request on an unknown or invalid
     channel; report bz#1842 from jchadima AT redhat.com; ok dtucker@

14 years ago - djm@cvs.openbsd.org 2010/11/23 02:35:50
Damien Miller [Wed, 1 Dec 2010 01:01:51 +0000 (12:01 +1100)] 
   - djm@cvs.openbsd.org 2010/11/23 02:35:50
     [auth.c]
     use strict_modes already passed as function argument over referencing
     global options.strict_modes

14 years ago - djm@cvs.openbsd.org 2010/11/21 10:57:07
Damien Miller [Wed, 1 Dec 2010 01:01:21 +0000 (12:01 +1100)] 
   - djm@cvs.openbsd.org 2010/11/21 10:57:07
     [authfile.c]
     Refactor internals of private key loading and saving to work on memory
     buffers rather than directly on files. This will make a few things
     easier to do in the future; ok markus@

14 years ago - djm@cvs.openbsd.org 2010/11/21 01:01:13
Damien Miller [Wed, 1 Dec 2010 00:50:35 +0000 (11:50 +1100)] 
   - djm@cvs.openbsd.org 2010/11/21 01:01:13
     [clientloop.c misc.c misc.h ssh-agent.1 ssh-agent.c]
     honour $TMPDIR for client xauth and ssh-agent temporary directories;
     feedback and ok markus@

14 years ago - OpenBSD CVS Sync
Damien Miller [Wed, 1 Dec 2010 00:50:14 +0000 (11:50 +1100)] 
 - OpenBSD CVS Sync
   - deraadt@cvs.openbsd.org 2010/11/20 05:12:38
     [auth2-pubkey.c]
     clean up cases of ;;

14 years ago - (djm) [defines.h] Add IP DSCP defines
Damien Miller [Tue, 23 Nov 2010 23:50:04 +0000 (10:50 +1100)] 
 - (djm) [defines.h] Add IP DSCP defines

14 years ago - (dtucker) [packet.c] Remove redundant local declaration of "int tos".
Darren Tucker [Tue, 23 Nov 2010 23:46:37 +0000 (10:46 +1100)] 
 - (dtucker) [packet.c] Remove redundant local declaration of "int tos".

14 years ago - (djm) [loginrec.c] Relax permission requirement on btmp logs to allow
Damien Miller [Tue, 23 Nov 2010 23:36:15 +0000 (10:36 +1100)] 
 - (djm) [loginrec.c] Relax permission requirement on btmp logs to allow
   group read/write. ok dtucker@

14 years ago - (dtucker) [platform.c session.c] Move the getluid call out of session.c and
Darren Tucker [Tue, 23 Nov 2010 23:09:13 +0000 (10:09 +1100)] 
 - (dtucker) [platform.c session.c] Move the getluid call out of session.c and
   into the platform-specific code  Only affects SCO, tested by and ok tim@.

14 years ago - (dtucker) Bug #1840: fix warning when configuring --with-ssl-engine, patch
Darren Tucker [Mon, 22 Nov 2010 06:59:00 +0000 (17:59 +1100)] 
 - (dtucker) Bug #1840: fix warning when configuring --with-ssl-engine, patch
   from vapier at gentoo org.

14 years ago - jmc@cvs.openbsd.org 2010/11/18 15:01:00
Damien Miller [Sat, 20 Nov 2010 04:21:03 +0000 (15:21 +1100)] 
   - jmc@cvs.openbsd.org 2010/11/18 15:01:00
     [scp.1 sftp.1 ssh.1 sshd_config.5]
     add IPQoS to the various -o lists, and zap some trailing whitespace;

14 years ago - jmc@cvs.openbsd.org 2010/11/15 07:40:14
Damien Miller [Sat, 20 Nov 2010 04:20:10 +0000 (15:20 +1100)] 
   - jmc@cvs.openbsd.org 2010/11/15 07:40:14
     [ssh_config.5]
     libary -> library;

14 years ago - djm@cvs.openbsd.org 2010/11/13 23:27:51
Damien Miller [Sat, 20 Nov 2010 04:19:38 +0000 (15:19 +1100)] 
   - djm@cvs.openbsd.org 2010/11/13 23:27:51
     [clientloop.c misc.c misc.h packet.c packet.h readconf.c readconf.h]
     [servconf.c servconf.h session.c ssh.c ssh_config.5 sshd_config.5]
     allow ssh and sshd to set arbitrary TOS/DSCP/QoS values instead of
     hardcoding lowdelay/throughput.

     bz#1733 patch from philipp AT redfish-solutions.com; ok markus@ deraadt@

14 years ago - djm@cvs.openbsd.org 2010/11/10 01:33:07
Damien Miller [Sat, 20 Nov 2010 04:15:49 +0000 (15:15 +1100)] 
   - djm@cvs.openbsd.org 2010/11/10 01:33:07
     [kexdhc.c kexdhs.c kexgexc.c kexgexs.c key.c moduli.c]
     use only libcrypto APIs that are retained with OPENSSL_NO_DEPRECATED.
     these have been around for years by this time. ok markus

14 years ago - djm@cvs.openbsd.org 2010/11/05 02:46:47
Damien Miller [Sat, 20 Nov 2010 04:14:29 +0000 (15:14 +1100)] 
   - djm@cvs.openbsd.org 2010/11/05 02:46:47
     [packet.c]
     whitespace KNF

14 years ago - (djm) [servconf.c ssh-add.c ssh-keygen.c] don't look for ECDSA keys on
Damien Miller [Thu, 11 Nov 2010 03:17:02 +0000 (14:17 +1100)] 
 - (djm) [servconf.c ssh-add.c ssh-keygen.c] don't look for ECDSA keys on
   platforms that don't support ECC. Fixes some spurious warnings reported
   by tim@

14 years ago - (tim) [configure.ac openbsd-compat/bsd-misc.h openbsd-compat/bsd-misc.c] Add
Tim Rice [Mon, 8 Nov 2010 22:26:23 +0000 (14:26 -0800)] 
 - (tim) [configure.ac openbsd-compat/bsd-misc.h openbsd-compat/bsd-misc.c] Add
   support for platforms missing isblank(). ok djm@

14 years ago - (tim) [regress/kextype.sh] Not all platforms have time in /usr/bin.
Tim Rice [Mon, 8 Nov 2010 17:15:14 +0000 (09:15 -0800)] 
 - (tim) [regress/kextype.sh] Not all platforms have time in /usr/bin.
   Feedback from dtucker@

14 years ago - (tim) [regress/kextype.sh] Shell portability fix.
Tim Rice [Sun, 7 Nov 2010 21:03:11 +0000 (13:03 -0800)] 
 - (tim) [regress/kextype.sh] Shell portability fix.

14 years ago - (tim) [regress/Makefile] Fixes to allow building/testing outside source
Tim Rice [Sun, 7 Nov 2010 21:00:27 +0000 (13:00 -0800)] 
 - (tim) [regress/Makefile] Fixes to allow building/testing outside source
   tree.