]> git.ipfire.org Git - thirdparty/openssh-portable.git/log
thirdparty/openssh-portable.git
15 years ago - markus@cvs.openbsd.org 2010/02/08 10:52:47
Damien Miller [Wed, 24 Feb 2010 06:31:20 +0000 (17:31 +1100)] 
   - markus@cvs.openbsd.org 2010/02/08 10:52:47
     [regress/agent-pkcs11.sh]
     test for PKCS#11 support (currently disabled)

15 years ago - djm@cvs.openbsd.org 2010/02/24 06:21:56
Damien Miller [Wed, 24 Feb 2010 06:29:34 +0000 (17:29 +1100)] 
   - djm@cvs.openbsd.org 2010/02/24 06:21:56
     [regress/test-exec.sh]
     wait for sshd to fully stop in cleanup() function; avoids races in tests
     that do multiple start_sshd/cleanup cycles; "I hate pidfiles" deraadt@

15 years ago - djm@cvs.openbsd.org 2010/02/09 06:29:02
Damien Miller [Wed, 24 Feb 2010 06:28:45 +0000 (17:28 +1100)] 
   - djm@cvs.openbsd.org 2010/02/09 06:29:02
     [regress/Makefile]
     turn on all the malloc(3) checking options when running regression
     tests. this has caught a few bugs for me in the past; ok dtucker@

15 years ago - djm@cvs.openbsd.org 2010/02/09 04:57:36
Damien Miller [Wed, 24 Feb 2010 06:26:38 +0000 (17:26 +1100)] 
   - djm@cvs.openbsd.org 2010/02/09 04:57:36
     [regress/addrmatch.sh]
     clean up droppings

15 years ago - dtucker@cvs.openbsd.org 2010/01/11 02:53:44
Damien Miller [Wed, 24 Feb 2010 06:25:58 +0000 (17:25 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/11 02:53:44
     [regress/forwarding.sh]
     regress test for stdio forwarding

15 years ago - dtucker@cvs.openbsd.org 2009/11/09 04:20:04
Damien Miller [Wed, 24 Feb 2010 06:24:56 +0000 (17:24 +1100)] 
   - dtucker@cvs.openbsd.org 2009/11/09 04:20:04
     [regress/Makefile]
     add regression test for ssh-keygen pubkey conversions

15 years ago - djm@cvs.openbsd.org 2010/02/11 20:37:47
Damien Miller [Wed, 24 Feb 2010 06:17:58 +0000 (17:17 +1100)] 
   - djm@cvs.openbsd.org 2010/02/11 20:37:47
     [pathnames.h]
     correct comment

15 years ago - (djm) [pkcs11.h ssh-pkcs11-client.c ssh-pkcs11-helper.c ssh-pkcs11.c]
Damien Miller [Wed, 24 Feb 2010 06:16:08 +0000 (17:16 +1100)] 
 - (djm) [pkcs11.h ssh-pkcs11-client.c ssh-pkcs11-helper.c ssh-pkcs11.c]
   [ssh-pkcs11.h] Add $OpenBSD$ RCS idents so we can sync portable

15 years ago- (djm) [configure.ac] Enable PKCS#11 support only when we find a working
Damien Miller [Thu, 11 Feb 2010 23:11:34 +0000 (10:11 +1100)] 
- (djm) [configure.ac] Enable PKCS#11 support only when we find a working
  dlopen()

15 years ago - (djm) [ssh-pkcs11-client.c ssh-pkcs11-helper.c ssh-pkcs11.c]
Damien Miller [Thu, 11 Feb 2010 23:06:28 +0000 (10:06 +1100)] 
 - (djm) [ssh-pkcs11-client.c ssh-pkcs11-helper.c ssh-pkcs11.c]
   Use ssh_get_progname to fill __progname

15 years ago - (djm) [ssh-pkcs11-client.c ssh-pkcs11-helper.c ssh-pkcs11.c]
Damien Miller [Thu, 11 Feb 2010 22:49:06 +0000 (09:49 +1100)] 
 - (djm) [ssh-pkcs11-client.c ssh-pkcs11-helper.c ssh-pkcs11.c]
   Make it compile on OSX

15 years ago - (djm) [INSTALL Makefile.in README.smartcard configure.ac scard-opensc.c]
Damien Miller [Thu, 11 Feb 2010 22:34:22 +0000 (09:34 +1100)] 
 - (djm) [INSTALL Makefile.in README.smartcard configure.ac scard-opensc.c]
   [scard.c scard.h pkcs11.h scard/Makefile.in scard/Ssh.bin.uu scard/Ssh.java]
   Remove obsolete smartcard support

15 years ago - jmc@cvs.openbsd.org 2010/02/11 13:23:29
Damien Miller [Thu, 11 Feb 2010 22:26:23 +0000 (09:26 +1100)] 
   - jmc@cvs.openbsd.org 2010/02/11 13:23:29
     [ssh.1]
     libarary -> library;

15 years ago - markus@cvs.openbsd.org 2010/02/10 23:20:38
Damien Miller [Thu, 11 Feb 2010 22:26:02 +0000 (09:26 +1100)] 
   - markus@cvs.openbsd.org 2010/02/10 23:20:38
     [ssh-add.1 ssh-keygen.1 ssh.1 ssh_config.5]
     pkcs#11 is no longer optional; improve wording; ok jmc@

15 years ago - djm@cvs.openbsd.org 2010/02/09 06:18:46
Damien Miller [Thu, 11 Feb 2010 22:25:29 +0000 (09:25 +1100)] 
   - djm@cvs.openbsd.org 2010/02/09 06:18:46
     [auth.c]
     unbreak ChrootDirectory+internal-sftp by skipping check for executable
     shell when chrooting; reported by danh AT wzrd.com; ok dtucker@

15 years ago - djm@cvs.openbsd.org 2010/02/09 03:56:28
Damien Miller [Thu, 11 Feb 2010 22:23:40 +0000 (09:23 +1100)] 
   - djm@cvs.openbsd.org 2010/02/09 03:56:28
     [buffer.c buffer.h]
     constify the arguments to buffer_len, buffer_ptr and buffer_dump

15 years ago - djm@cvs.openbsd.org 2010/02/09 00:50:59
Damien Miller [Thu, 11 Feb 2010 22:22:57 +0000 (09:22 +1100)] 
   - djm@cvs.openbsd.org 2010/02/09 00:50:59
     [ssh-keygen.c]
     fix -Wall

15 years ago - djm@cvs.openbsd.org 2010/02/09 00:50:36
Damien Miller [Thu, 11 Feb 2010 22:22:31 +0000 (09:22 +1100)] 
   - djm@cvs.openbsd.org 2010/02/09 00:50:36
     [ssh-agent.c]
     fallout from PKCS#11: unbreak -D

15 years ago - jmc@cvs.openbsd.org 2010/02/08 22:03:05
Damien Miller [Thu, 11 Feb 2010 22:22:04 +0000 (09:22 +1100)] 
   - jmc@cvs.openbsd.org 2010/02/08 22:03:05
     [ssh-add.1 ssh-keygen.1 ssh.1 ssh.c]
     tweak previous; ok markus

15 years ago - markus@cvs.openbsd.org 2010/02/08 10:50:20
Damien Miller [Thu, 11 Feb 2010 22:21:02 +0000 (09:21 +1100)] 
   - markus@cvs.openbsd.org 2010/02/08 10:50:20
     [pathnames.h readconf.c readconf.h scp.1 sftp.1 ssh-add.1 ssh-add.c]
     [ssh-agent.c ssh-keygen.1 ssh-keygen.c ssh.1 ssh.c ssh_config.5]
     replace our obsolete smartcard code with PKCS#11.
        ftp://ftp.rsasecurity.com/pub/pkcs/pkcs-11/v2-20/pkcs-11v2-20.pdf
     ssh(1) and ssh-keygen(1) use dlopen(3) directly to talk to a PKCS#11
     provider (shared library) while ssh-agent(1) delegates PKCS#11 to
     a forked a ssh-pkcs11-helper process.
     PKCS#11 is currently a compile time option.
     feedback and ok djm@; inspired by patches from Alon Bar-Lev
`

15 years ago - djm@cvs.openbsd.org 2010/02/02 22:49:34
Damien Miller [Thu, 11 Feb 2010 20:35:08 +0000 (07:35 +1100)] 
   - djm@cvs.openbsd.org 2010/02/02 22:49:34
     [bufaux.c]
     make buffer_get_string_ret() really non-fatal in all cases (it was
     using buffer_get_int(), which could fatal() on buffer empty);
     ok markus dtucker

15 years ago - (djm) add -lselinux to LIBS before calling AC_CHECK_FUNCS for
Damien Miller [Tue, 9 Feb 2010 23:19:29 +0000 (10:19 +1100)] 
 - (djm) add -lselinux to LIBS before calling AC_CHECK_FUNCS for
   getseuserbyname; patch from calebcase AT gmail.com via
   cjwatson AT debian.org

15 years agoThis should have gone in with the multiplexing merge, but I dropped it
Damien Miller [Tue, 9 Feb 2010 23:17:49 +0000 (10:17 +1100)] 
This should have gone in with the multiplexing merge, but I dropped it
at the time.

15 years ago - djm@cvs.openbsd.org 2010/01/30 21:12:08
Damien Miller [Tue, 2 Feb 2010 06:02:07 +0000 (17:02 +1100)] 
   - djm@cvs.openbsd.org 2010/01/30 21:12:08
     [channels.c]
     fake local addr:port when stdio fowarding as some servers (Tectia at
     least) validate that they are well-formed;
     reported by imorgan AT nas.nasa.gov
     ok dtucker

15 years ago - djm@cvs.openbsd.org 2010/01/30 21:08:33
Damien Miller [Tue, 2 Feb 2010 06:01:46 +0000 (17:01 +1100)] 
   - djm@cvs.openbsd.org 2010/01/30 21:08:33
     [sshd.8]
     debug output goes to stderr, not "the system log"; ok markus dtucker

15 years ago - djm@cvs.openbsd.org 2010/01/30 02:54:53
Damien Miller [Sat, 30 Jan 2010 06:42:01 +0000 (17:42 +1100)] 
   - djm@cvs.openbsd.org 2010/01/30 02:54:53
     [mux.c]
     don't mark channel as read failed if it is already closing; suppresses
     harmless error messages when connecting to SSH.COM Tectia server
     report by imorgan AT nas.nasa.gov

15 years ago - djm@cvs.openbsd.org 2010/01/29 20:16:17
Damien Miller [Sat, 30 Jan 2010 06:36:33 +0000 (17:36 +1100)] 
   - djm@cvs.openbsd.org 2010/01/29 20:16:17
     [mux.c]
     kill correct channel (was killing already-dead mux channel, not
     its session channel)

15 years ago - djm@cvs.openbsd.org 2010/01/29 00:20:41
Damien Miller [Sat, 30 Jan 2010 06:30:04 +0000 (17:30 +1100)] 
   - djm@cvs.openbsd.org 2010/01/29 00:20:41
     [sshd.c]
     set FD_CLOEXEC on sock_in/sock_out; bz#1706 from jchadima AT redhat.com
     ok dtucker@

15 years ago - djm@cvs.openbsd.org 2010/01/28 00:21:18
Damien Miller [Sat, 30 Jan 2010 06:28:34 +0000 (17:28 +1100)] 
   - djm@cvs.openbsd.org 2010/01/28 00:21:18
     [clientloop.c]
     downgrade an error() to a debug() - this particular case can be hit in
     normal operation for certain sequences of mux slave vs session closure
     and is harmless

15 years ago - (dtucker) [openbsd-compat/openssl-compat.c] Bug #1707: Call OPENSSL_config()
Darren Tucker [Thu, 28 Jan 2010 23:54:11 +0000 (10:54 +1100)] 
 - (dtucker) [openbsd-compat/openssl-compat.c] Bug #1707: Call OPENSSL_config()
   after registering the hardware engines, which causes the openssl.cnf file to
   be processed.  See OpenSSL's man page for OPENSSL_config(3) for details.
   Patch from Solomon Peachy, ok djm@.

15 years ago - djm@cvs.openbsd.org 2010/01/27 19:21:39
Damien Miller [Wed, 27 Jan 2010 19:27:54 +0000 (06:27 +1100)] 
   - djm@cvs.openbsd.org 2010/01/27 19:21:39
     [sftp.c]
     add missing "p" flag to getopt optstring;
     bz#1704 from imorgan AT nas.nasa.gov

15 years ago - djm@cvs.openbsd.org 2010/01/27 13:26:17
Damien Miller [Wed, 27 Jan 2010 19:26:59 +0000 (06:26 +1100)] 
   - djm@cvs.openbsd.org 2010/01/27 13:26:17
     [mux.c]
     fix bug introduced in mux rewrite:

     In a mux master, when a socket to a mux slave closes before its server
     session (as may occur when the slave has been signalled), gracefully
     close the server session rather than deleting its channel immediately.
     A server may have more messages on that channel to send (e.g. an exit
     message) that will fatal() the client if they are sent to a channel that
     has been prematurely deleted.

     spotted by imorgan AT nas.nasa.gov

15 years ago - djm@cvs.openbsd.org 2010/01/26 02:15:20
Damien Miller [Wed, 27 Jan 2010 19:26:20 +0000 (06:26 +1100)] 
   - djm@cvs.openbsd.org 2010/01/26 02:15:20
     [mux.c]
     -Wuninitialized and remove a // comment; from portable
     (Id sync only)

15 years ago - djm@cvs.openbsd.org 2010/01/26 01:28:35
Damien Miller [Tue, 26 Jan 2010 02:26:22 +0000 (13:26 +1100)] 
   - djm@cvs.openbsd.org 2010/01/26 01:28:35
     [channels.c channels.h clientloop.c clientloop.h mux.c nchan.c ssh.c]
     rewrite ssh(1) multiplexing code to a more sensible protocol.

     The new multiplexing code uses channels for the listener and
     accepted control sockets to make the mux master non-blocking, so
     no stalls when processing messages from a slave.

     avoid use of fatal() in mux master protocol parsing so an errant slave
     process cannot take down a running master.

     implement requesting of port-forwards over multiplexed sessions. Any
     port forwards requested by the slave are added to those the master has
     established.

     add support for stdio forwarding ("ssh -W host:port ...") in mux slaves.

     document master/slave mux protocol so that other tools can use it to
     control a running ssh(1). Note: there are no guarantees that this
     protocol won't be incompatibly changed (though it is versioned).

     feedback Salvador Fandino, dtucker@
     channel changes ok markus@

15 years ago - dtucker@cvs.openbsd.org 2010/01/18 01:50:27
Damien Miller [Tue, 26 Jan 2010 01:53:06 +0000 (12:53 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/18 01:50:27
     [roaming_client.c]
     s/long long unsigned/unsigned long long/, from tim via portable
     (Id sync only, change already in portable)

15 years ago - tedu@cvs.openbsd.org 2010/01/17 21:49:09
Damien Miller [Tue, 26 Jan 2010 01:51:13 +0000 (12:51 +1100)] 
   - tedu@cvs.openbsd.org 2010/01/17 21:49:09
     [ssh-agent.1]
     Correct and clarify ssh-add's password asking behavior.
     Improved text dtucker and ok jmc

15 years ago - (tim) [configure.ac] Due to constraints in Windows Sockets in terms of
Tim Rice [Fri, 22 Jan 2010 18:25:15 +0000 (10:25 -0800)] 
 - (tim) [configure.ac] Due to constraints in Windows Sockets in terms of
   socket inheritance, reduce the default SO_RCVBUF/SO_SNDBUF buffer size
   in Cygwin to 65535. Patch from Corinna Vinschen.

15 years agoReword comment in last commit for additional clearity.
Tim Rice [Mon, 18 Jan 2010 06:49:57 +0000 (22:49 -0800)] 
Reword comment in last commit for additional clearity.

15 years ago - (tim) [configure.ac] Use the C99-conforming functions snprintf() and
Tim Rice [Mon, 18 Jan 2010 01:05:39 +0000 (17:05 -0800)] 
 - (tim) [configure.ac] Use the C99-conforming functions snprintf() and
   vsnprintf() named _xsnprintf() and _xvsnprintf() on SVR5 systems.

15 years ago - (tim) [configure.ac] OpenServer 5 needs BROKEN_GETADDRINFO too.
Tim Rice [Sun, 17 Jan 2010 20:48:22 +0000 (12:48 -0800)] 
 - (tim) [configure.ac] OpenServer 5 needs BROKEN_GETADDRINFO too.

15 years agoOops, forgot to document second change to roaming_client.c
Tim Rice [Sun, 17 Jan 2010 15:12:40 +0000 (07:12 -0800)] 
Oops, forgot to document second change to roaming_client.c
 s/long long unsigned/unsigned long long/ to keep USL compilers happy.

15 years ago - (tim) [roaming_client.c] Use of <sys/queue.h> is not really portable so
Tim Rice [Sun, 17 Jan 2010 00:48:39 +0000 (16:48 -0800)] 
 - (tim) [roaming_client.c] Use of <sys/queue.h> is not really portable so
   we use "openbsd-compat/sys-queue.h"

15 years ago - (tim) [configure.ac] Define BROKEN_GETADDRINFO on SVR5 systems. The native
Tim Rice [Sat, 16 Jan 2010 20:23:25 +0000 (12:23 -0800)] 
 - (tim) [configure.ac] Define BROKEN_GETADDRINFO on SVR5 systems. The native
   getaddrinfo() is too old and limited for addr_pton() in addrmatch.c.

15 years ago - (tim) [regress/portnum.sh] Shell portability fix.
Tim Rice [Sat, 16 Jan 2010 19:37:53 +0000 (11:37 -0800)] 
 - (tim) [regress/portnum.sh] Shell portability fix.

15 years ago - (dtucker) [openbsd-compat/openbsd-compat.h] Typo.
Darren Tucker [Sat, 16 Jan 2010 12:58:37 +0000 (23:58 +1100)] 
 - (dtucker) [openbsd-compat/openbsd-compat.h] Typo.

15 years ago - (dtucker) [openbsd-compat/pwcache.c] Shrink ifdef area to prevent unused
Darren Tucker [Sat, 16 Jan 2010 02:53:52 +0000 (13:53 +1100)] 
 - (dtucker) [openbsd-compat/pwcache.c] Shrink ifdef area to prevent unused
   variable warnings.

15 years ago - markus@cvs.openbsd.org 2010/01/15 09:24:23
Darren Tucker [Sat, 16 Jan 2010 02:43:50 +0000 (13:43 +1100)] 
   - markus@cvs.openbsd.org 2010/01/15 09:24:23
     [sftp-common.c]
     unused

15 years ago - (dtucker) [openbsd-compat/openbsd-compat.h] Fix prototypes, spotted by
Darren Tucker [Sat, 16 Jan 2010 02:30:30 +0000 (13:30 +1100)] 
 - (dtucker) [openbsd-compat/openbsd-compat.h] Fix prototypes, spotted by
   Tim.

15 years ago - (dtucker) [openbsd-compat/openbsd-compat.h] Prototypes for user_from_uid
Darren Tucker [Sat, 16 Jan 2010 00:53:07 +0000 (11:53 +1100)] 
 - (dtucker) [openbsd-compat/openbsd-compat.h] Prototypes for user_from_uid
   and group_from_gid.

15 years ago - (dtucker) [openbsd-compat/pwcache.c] Pull in includes.h and thus defines.h
Darren Tucker [Sat, 16 Jan 2010 00:48:27 +0000 (11:48 +1100)] 
 - (dtucker) [openbsd-compat/pwcache.c] Pull in includes.h and thus defines.h
   so we correctly detect whether or not we have a native user_from_uid.

15 years agotypo
Darren Tucker [Fri, 15 Jan 2010 02:12:10 +0000 (13:12 +1100)] 
typo

15 years ago - (dtucker) [configure.ac openbsd-compat/{Makefile.in,pwcache.c} Portability
Darren Tucker [Fri, 15 Jan 2010 01:38:30 +0000 (12:38 +1100)] 
 - (dtucker) [configure.ac openbsd-compat/{Makefile.in,pwcache.c} Portability
   for pwcache.  Also, added caching of negative hits.

15 years ago - (dtucker) [openbsd-compat.c/pwcache.c] Pull in pwcache.c from OpenBSD (no
Darren Tucker [Fri, 15 Jan 2010 01:14:45 +0000 (12:14 +1100)] 
 - (dtucker) [openbsd-compat.c/pwcache.c] Pull in pwcache.c from OpenBSD (no
   changes yet but there will be some to come).

15 years ago - guenther@cvs.openbsd.org 2010/01/15 00:05:22
Darren Tucker [Fri, 15 Jan 2010 00:46:03 +0000 (11:46 +1100)] 
   - guenther@cvs.openbsd.org 2010/01/15 00:05:22
     [sftp.c]
     Reset SIGTERM to SIG_DFL before executing ssh, so that even if sftp
     inherited SIGTERM as ignored it will still be able to kill the ssh it
     starts.
     ok dtucker@

15 years ago - dtucker@cvs.openbsd.org 2010/01/14 23:41:49
Darren Tucker [Fri, 15 Jan 2010 00:45:33 +0000 (11:45 +1100)] 
  - dtucker@cvs.openbsd.org 2010/01/14 23:41:49
     [sftp-common.c]
     use user_from{uid,gid} to lookup up ids since it keeps a small cache.
     ok djm

15 years ago - djm@cvs.openbsd.org 2010/01/13 23:47:26
Darren Tucker [Fri, 15 Jan 2010 00:44:46 +0000 (11:44 +1100)] 
   - djm@cvs.openbsd.org 2010/01/13 23:47:26
     [auth.c]
     when using ChrootDirectory, make sure we test for the existence of the
     user's shell inside the chroot; bz #1679, patch from alex AT rtfs.hu;
     ok dtucker

15 years ago - jmc@cvs.openbsd.org 2010/01/13 12:48:34
Darren Tucker [Fri, 15 Jan 2010 00:42:51 +0000 (11:42 +1100)] 
   - jmc@cvs.openbsd.org 2010/01/13 12:48:34
     [sftp.1 sftp.c]
     sftp.1: put ls -h in the right place
     sftp.c: as above, plus add -p to get/put, and shorten their arg names
     to keep the help usage nicely aligned
     ok djm

15 years ago - (djm) [platform.h] Add missing prototype for
Damien Miller [Thu, 14 Jan 2010 01:44:16 +0000 (12:44 +1100)] 
 - (djm) [platform.h] Add missing prototype for
   platform_krb5_get_principal_name

15 years ago - (tim) [defines.h] openbsd-compat/readpassphrase.c now needs _NSIG.
Tim Rice [Wed, 13 Jan 2010 23:44:34 +0000 (15:44 -0800)] 
 - (tim) [defines.h] openbsd-compat/readpassphrase.c now needs _NSIG.
   feedback and ok dtucker@

15 years ago - (dtucker) [sftp-common.c] Wrap include of util.h in an ifdef.
Darren Tucker [Wed, 13 Jan 2010 12:00:38 +0000 (23:00 +1100)] 
 - (dtucker) [sftp-common.c] Wrap include of util.h in an ifdef.

15 years ago - djm@cvs.openbsd.org 2010/01/13 04:10:50
Darren Tucker [Wed, 13 Jan 2010 11:45:03 +0000 (22:45 +1100)] 
   - djm@cvs.openbsd.org 2010/01/13 04:10:50
     [sftp.c]
     don't append a space after inserting a completion of a directory (i.e.
     a path ending in '/') for a slightly better user experience; ok dtucker@

15 years ago - djm@cvs.openbsd.org 2010/01/13 03:48:13
Darren Tucker [Wed, 13 Jan 2010 11:44:29 +0000 (22:44 +1100)] 
   - djm@cvs.openbsd.org 2010/01/13 03:48:13
     [servconf.c servconf.h sshd.c]
     avoid run-time failures when specifying hostkeys via a relative
     path by prepending the cwd in these cases; bz#1290; ok dtucker@

15 years ago - djm@cvs.openbsd.org 2010/01/13 01:40:16
Darren Tucker [Wed, 13 Jan 2010 11:44:06 +0000 (22:44 +1100)] 
   - djm@cvs.openbsd.org 2010/01/13 01:40:16
     [sftp.c sftp-server.c sftp.1 sftp-common.c sftp-common.h]
     support '-h' (human-readable units) for sftp's ls command, just like
     ls(1); ok dtucker@

15 years ago - dtucker@cvs.openbsd.org 2010/01/13 01:20:20
Darren Tucker [Wed, 13 Jan 2010 11:43:33 +0000 (22:43 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/13 01:20:20
     [canohost.c ssh-keysign.c sshconnect2.c]
     Make HostBased authentication work with a ProxyCommand.  bz #1569, patch
     from imorgan at nas nasa gov, ok djm@

15 years ago - dtucker@cvs.openbsd.org 2010/01/13 01:10:56
Darren Tucker [Wed, 13 Jan 2010 11:43:05 +0000 (22:43 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/13 01:10:56
     [key.c]
     Ignore and log any Protocol 1 keys where the claimed size is not equal to
     the actual size.  Noted by Derek Martin, ok djm@

15 years ago - (dtucker) OpenBSD CVS Sync
Darren Tucker [Wed, 13 Jan 2010 11:42:34 +0000 (22:42 +1100)] 
 - (dtucker) OpenBSD CVS Sync
   - dtucker@cvs.openbsd.org 2010/01/13 00:19:04
     [sshconnect.c auth.c]
     Fix a couple of typos/mispellings in comments

15 years ago - (dtucker) [openbsd-compat/readpassphrase.c] Update to OpenBSD's r1.22.
Darren Tucker [Wed, 13 Jan 2010 10:32:44 +0000 (21:32 +1100)] 
 - (dtucker) [openbsd-compat/readpassphrase.c] Update to OpenBSD's r1.22.
   Fixes bz #1590, where sometimes you could not interrupt a connection while
   ssh was prompting for a passphrase or password.

15 years ago - (dtucker) [openbsd-compat/readpassphrase.c] Update to OpenBSD's r1.21.
Darren Tucker [Wed, 13 Jan 2010 07:32:59 +0000 (18:32 +1100)] 
 - (dtucker) [openbsd-compat/readpassphrase.c] Update to OpenBSD's r1.21.

15 years ago - (dtucker) [openbsd-compat/readpassphrase.c] Resync against OpenBSD's r1.18: ...
Darren Tucker [Wed, 13 Jan 2010 07:27:32 +0000 (18:27 +1100)] 
 - (dtucker) [openbsd-compat/readpassphrase.c] Resync against OpenBSD's r1.18:    missing restore of SIGTTOU and some whitespace.

15 years ago - (dtucker) [monitor_fdpass.c] Wrap poll.h include in ifdefs.
Darren Tucker [Tue, 12 Jan 2010 23:54:46 +0000 (10:54 +1100)] 
 - (dtucker) [monitor_fdpass.c] Wrap poll.h include in ifdefs.

15 years ago - dtucker@cvs.openbsd.org 2010/01/12 08:33:17
Darren Tucker [Tue, 12 Jan 2010 08:51:48 +0000 (19:51 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/12 08:33:17
     [session.c]
     Add explicit stat so we reliably detect nologin with bad perms.
     ok djm markus

15 years ago - djm@cvs.openbsd.org 2010/01/12 01:36:08
Darren Tucker [Tue, 12 Jan 2010 08:45:59 +0000 (19:45 +1100)] 
   - djm@cvs.openbsd.org 2010/01/12 01:36:08
     [buffer.h bufaux.c]
     add a buffer_get_string_ptr_ret() that does the same as
     buffer_get_string_ptr() but does not fatal() on error; ok dtucker@

15 years ago - dtucker@cvs.openbsd.org 2010/01/12 01:31:05
Darren Tucker [Tue, 12 Jan 2010 08:45:26 +0000 (19:45 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/12 01:31:05
     [session.c]
     Do not allow logins if /etc/nologin exists but is not readable by the user
     logging in.  Noted by Jan.Pechanec at Sun, ok djm@ deraadt@

15 years ago - djm@cvs.openbsd.org 2010/01/12 00:59:29
Darren Tucker [Tue, 12 Jan 2010 08:43:46 +0000 (19:43 +1100)] 
   - djm@cvs.openbsd.org 2010/01/12 00:59:29
     [roaming_common.c]
     delete with extreme prejudice a debug() that fired with every keypress;
     ok dtucker deraadt

15 years ago - djm@cvs.openbsd.org 2010/01/12 00:58:25
Darren Tucker [Tue, 12 Jan 2010 08:43:12 +0000 (19:43 +1100)] 
   - djm@cvs.openbsd.org 2010/01/12 00:58:25
     [monitor_fdpass.c]
     avoid spinning when fd passing on nonblocking sockets by calling poll()
     in the EINTR/EAGAIN path, much like we do in atomicio; ok dtucker@

15 years ago - dtucker@cvs.openbsd.org 2010/01/12 00:16:47
Darren Tucker [Tue, 12 Jan 2010 08:42:29 +0000 (19:42 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/12 00:16:47
     [authfile.c]
     Fix bug introduced in r1.78 (incorrect brace location) that broke key auth.
     Patch from joachim joachimschipper nl.

15 years ago - djm@cvs.openbsd.org 2010/01/11 10:51:07
Darren Tucker [Tue, 12 Jan 2010 08:41:57 +0000 (19:41 +1100)] 
   - djm@cvs.openbsd.org 2010/01/11 10:51:07
     [ssh-keygen.c]
     when converting keys, truncate key comments at 72 chars as per RFC4716;
     bz#1630 reported by tj AT castaglia.org; ok markus@

15 years ago - dtucker@cvs.openbsd.org 2010/01/11 04:46:45
Darren Tucker [Tue, 12 Jan 2010 08:41:22 +0000 (19:41 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/11 04:46:45
     [authfile.c sshconnect2.c]
     Do not prompt for a passphrase if we fail to open a keyfile, and log the
     reason the open failed to debug.
     bz #1693, found by tj AT castaglia org, ok djm@

15 years ago - dtucker@cvs.openbsd.org 2010/01/11 01:39:46
Darren Tucker [Tue, 12 Jan 2010 08:40:27 +0000 (19:40 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/11 01:39:46
     [ssh_config channels.c ssh.1 channels.h ssh.c]
     Add a 'netcat mode' (ssh -W).  This connects stdio on the client to a
     single port forward on the server.  This allows, for example, using ssh as
     a ProxyCommand to route connections via intermediate servers.
     bz #1618, man page help from jmc@, ok markus@

15 years ago - dtucker@cvs.openbsd.org 2010/01/10 07:15:56
Darren Tucker [Sun, 10 Jan 2010 08:27:17 +0000 (19:27 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/10 07:15:56
     [auth.c]
     Output a debug if we can't open an existing keyfile.  bz#1694, ok djm@

15 years ago - dtucker@cvs.openbsd.org 2010/01/10 03:51:17
Darren Tucker [Sun, 10 Jan 2010 08:26:43 +0000 (19:26 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/10 03:51:17
     [servconf.c]
     Add ChrootDirectory to sshd.c test-mode output

15 years ago - dtucker@cvs.openbsd.org 2010/01/09 23:04:13
Darren Tucker [Sat, 9 Jan 2010 23:31:12 +0000 (10:31 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/09 23:04:13
     [channels.c ssh.1 servconf.c sshd_config.5 sshd.c channels.h servconf.h
     ssh-keyscan.1 ssh-keyscan.c readconf.c sshconnect.c misc.c ssh.c
     readconf.h scp.1 sftp.1 ssh_config.5 misc.h]
     Remove RoutingDomain from ssh since it's now not needed.  It can be
     replaced with "route exec" or "nc -V" as a proxycommand.  "route exec"
     also ensures that trafic such as DNS lookups stays withing the specified
     routingdomain.  For example (from reyk):
     # route -T 2 exec /usr/sbin/sshd
     or inherited from the parent process
     $ route -T 2 exec sh
     $ ssh 10.1.2.3
     ok deraadt@ markus@ stevesk@ reyk@

15 years ago - (dtucker) [configure.ac misc.c readconf.c servconf.c ssh-keyscan.c]
Darren Tucker [Sat, 9 Jan 2010 23:26:57 +0000 (10:26 +1100)] 
 - (dtucker) [configure.ac misc.c readconf.c servconf.c ssh-keyscan.c]
   Remove hacks add for RoutingDomain in preparation for its removal.

15 years ago - (dtucker) [defines.h] Remove now-undeeded PRIu64 define.
Darren Tucker [Sat, 9 Jan 2010 11:33:37 +0000 (22:33 +1100)] 
 - (dtucker) [defines.h] Remove now-undeeded PRIu64 define.

15 years ago - dtucker@cvs.openbsd.org 2010/01/09 11:17:56
Darren Tucker [Sat, 9 Jan 2010 11:28:43 +0000 (22:28 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/09 11:17:56
     [sshd.c]
     Afer sshd receives a SIGHUP, ignore subsequent HUPs while sshd re-execs
     itself.  Prevents two HUPs in quick succession from resulting in sshd
     dying.  bz#1692, patch from Colin Watson via Ubuntu.

15 years ago - dtucker@cvs.openbsd.org 2010/01/09 11:13:02
Darren Tucker [Sat, 9 Jan 2010 11:28:03 +0000 (22:28 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/09 11:13:02
     [sftp.c]
     Prevent sftp from derefing a null pointer when given a "-" without a
     command.  Also, allow whitespace to follow a "-".  bz#1691, path from
     Colin Watson via Debian.  ok djm@ deraadt@

15 years ago - dtucker@cvs.openbsd.org 2010/01/09 05:17:00
Darren Tucker [Sat, 9 Jan 2010 11:27:06 +0000 (22:27 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/09 05:17:00
     [roaming_client.c]
     Remove a PRIu64 format string that snuck in with roaming.  ok djm@

15 years ago - djm@cvs.openbsd.org 2010/01/09 05:04:24
Darren Tucker [Sat, 9 Jan 2010 11:26:23 +0000 (22:26 +1100)] 
   - djm@cvs.openbsd.org 2010/01/09 05:04:24
     [mux.c sshpty.h clientloop.c sshtty.c]
     quell tc[gs]etattr warnings when forcing a tty (ssh -tt), since we
     usually don't actually have a tty to read/set; bz#1686 ok dtucker@

15 years ago - jmc@cvs.openbsd.org 2010/01/09 03:36:00
Darren Tucker [Sat, 9 Jan 2010 11:25:46 +0000 (22:25 +1100)] 
   - jmc@cvs.openbsd.org 2010/01/09 03:36:00
     [sftp-server.8]
     bad place to forget a comma...

15 years ago - djm@cvs.openbsd.org 2010/01/09 00:57:10
Darren Tucker [Sat, 9 Jan 2010 11:25:14 +0000 (22:25 +1100)] 
   - djm@cvs.openbsd.org 2010/01/09 00:57:10
     [PROTOCOL]
     tweak language

15 years ago - djm@cvs.openbsd.org 2010/01/09 00:20:26
Darren Tucker [Sat, 9 Jan 2010 11:24:33 +0000 (22:24 +1100)] 
   - djm@cvs.openbsd.org 2010/01/09 00:20:26
     [sftp-server.c sftp-server.8]
     add a 'read-only' mode to sftp-server(8) that disables open in write mode
     and all other fs-modifying protocol methods. bz#430 ok dtucker@

15 years ago - (dtucker) [loginrec.c] Use the SUSv3 specified name for the user name
Darren Tucker [Sat, 9 Jan 2010 07:18:04 +0000 (18:18 +1100)] 
 - (dtucker) [loginrec.c] Use the SUSv3 specified name for the user name
   when using utmpx.  Patch from Ed Schouten.

15 years ago - (dtucker) [roaming_client.c] Wrap inttypes.h in an ifdef.
Darren Tucker [Sat, 9 Jan 2010 05:40:48 +0000 (16:40 +1100)] 
 - (dtucker) [roaming_client.c] Wrap inttypes.h in an ifdef.

15 years ago - (dtucker) [defines.h] define PRIu64 for platforms that don't have it.
Darren Tucker [Fri, 8 Jan 2010 22:25:54 +0000 (09:25 +1100)] 
 - (dtucker) [defines.h] define PRIu64 for platforms that don't have it.

15 years ago - (dtucker) Wrap use of IPPROTO_IPV6 in an ifdef for platforms that don't
Darren Tucker [Fri, 8 Jan 2010 22:02:07 +0000 (09:02 +1100)] 
 - (dtucker) Wrap use of IPPROTO_IPV6 in an ifdef for platforms that don't
   have it.

15 years ago - dtucker@cvs.openbsd.org 2010/01/08 21:50:49
Darren Tucker [Fri, 8 Jan 2010 21:54:31 +0000 (08:54 +1100)] 
   - dtucker@cvs.openbsd.org 2010/01/08 21:50:49
     [sftp.c]
     Fix two warnings: possibly used unitialized and use a nul byte instead of
     NULL pointer.  ok djm@

15 years ago - (dtucker) [roaming_serv.c] Include includes.h for u_intXX_t types.
Darren Tucker [Fri, 8 Jan 2010 09:45:42 +0000 (20:45 +1100)] 
 - (dtucker) [roaming_serv.c] Include includes.h for u_intXX_t types.

15 years ago - (dtucker] [misc.c] Shrink the area covered by USE_ROUTINGDOMAIN more
Darren Tucker [Fri, 8 Jan 2010 09:09:01 +0000 (20:09 +1100)] 
 - (dtucker] [misc.c] Shrink the area covered by USE_ROUTINGDOMAIN more
   to eliminate an unused variable warning.

15 years ago - (dtucker) [misc.c] Move the routingdomain ifdef to allow the socket to
Darren Tucker [Fri, 8 Jan 2010 09:03:56 +0000 (20:03 +1100)] 
 - (dtucker) [misc.c] Move the routingdomain ifdef to allow the socket to
   be created.

15 years ago - (dtucker) [sftp.c] Expand ifdef for libedit to cover complete_is_remote
Darren Tucker [Fri, 8 Jan 2010 08:56:33 +0000 (19:56 +1100)] 
 - (dtucker) [sftp.c] Expand ifdef for libedit to cover complete_is_remote
   too.