]>
git.ipfire.org Git - thirdparty/openssh-portable.git/log
dtucker@openbsd.org [Wed, 22 Jul 2026 00:37:24 +0000 (00:37 +0000)]
upstream: Automatically detect IPv6 support
and test IPv6 parsing if found. This should always be enabled on OpenBSD,
but allows us to use the same test in Portable without modifications
that make syncs harder.
OpenBSD-Regress-ID:
80dce2465e9414695d878a9af18a3d75711f7861
dtucker@openbsd.org [Tue, 21 Jul 2026 23:43:15 +0000 (23:43 +0000)]
upstream: Factor out all of the IPv6 addresses into variables.
This lets us skip them in Portable on platforms that don't support IPv6
all in one place, removing diffs from within the tests themselves and
making syncs easier.
OpenBSD-Regress-ID:
be5d2d67c28f8134f84e8baab09f303be8ceb626
Darren Tucker [Tue, 21 Jul 2026 22:44:39 +0000 (08:44 +1000)]
Sync missed case-insensitivity changes.
Darren Tucker [Tue, 14 Jul 2026 08:30:40 +0000 (18:30 +1000)]
Add obsd79 target.
Darren Tucker [Tue, 14 Jul 2026 08:29:26 +0000 (18:29 +1000)]
Wording.
djm@openbsd.org [Tue, 21 Jul 2026 06:18:23 +0000 (06:18 +0000)]
upstream: verify that ChannelTimeout in a Match block is effective
OpenBSD-Regress-ID:
30770cad71ca060aaaa05e4bdd0ea8941b768c6b
djm@openbsd.org [Tue, 21 Jul 2026 06:18:09 +0000 (06:18 +0000)]
upstream: verify that RekeyLimit in a Match block is effective
OpenBSD-Regress-ID:
23084bcf86071a7fe0c121552ec6e0b208cc7e28
dtucker@openbsd.org [Thu, 16 Jul 2026 09:07:18 +0000 (09:07 +0000)]
upstream: Use -Ohashalg to restrict output to specfic hash instead
of awk.
OpenBSD-Regress-ID:
aa5fac0e3ee8f518794d3361d537090c6e3f0bec
djm@openbsd.org [Tue, 21 Jul 2026 06:17:42 +0000 (06:17 +0000)]
upstream: fix ChannelTimeout and RekeyLimit not being applied in
sshd_config Match blocks; reported by Alex Harrison
OpenBSD-Commit-ID:
2d8866b841fc92e6e079e3f37590ba5948531b3d
djm@openbsd.org [Tue, 21 Jul 2026 05:21:29 +0000 (05:21 +0000)]
upstream: s/= - 1/= -1/; from serity---
OpenBSD-Commit-ID:
d003b300b0062d8e5951b84e8e09bd8d98cfe562
djm@openbsd.org [Thu, 16 Jul 2026 04:12:50 +0000 (04:12 +0000)]
upstream: move to a better place
OpenBSD-Commit-ID:
0c70f26de19babb2557a7a95ae7057d996a2c3f8
djm@openbsd.org [Tue, 14 Jul 2026 04:43:13 +0000 (04:43 +0000)]
upstream: use crypto_api.h #define constants for lengths; no
binary change
OpenBSD-Commit-ID:
6527baa1f07b7fdf42ca84531a13ae3ff2c0dbc8
djm@openbsd.org [Tue, 14 Jul 2026 01:05:05 +0000 (01:05 +0000)]
upstream: make authorized_keys "restrict" keyword apply correctly
to tunnel forwarding (which is administratively disabled by default).
Reported by Erichen, Institute of Computing Technology,
Chinese Academy of Sciences
OpenBSD-Commit-ID:
5b3cc987a64749c94b20e12755db32a83f8f01e6
naddy@openbsd.org [Sat, 11 Jul 2026 11:16:47 +0000 (11:16 +0000)]
upstream: in sshd config dump mode, write all directives in mixed
case for consistency
ok djm@
OpenBSD-Commit-ID:
55647b13194d0aaa7095b89455d4c44ddeb53e7d
naddy@openbsd.org [Sat, 11 Jul 2026 11:15:03 +0000 (11:15 +0000)]
upstream: read ~/.ssh/id_mldsa44_ed25519 private key files by
default
ok djm@
OpenBSD-Commit-ID:
c45683d341d7dce6c126903bf9a37393f2b75839
naddy@openbsd.org [Fri, 10 Jul 2026 17:21:19 +0000 (17:21 +0000)]
upstream: document mldsa44-
ed25519 host key and public key
algorithm
OpenBSD-Commit-ID:
c519ba7408cfb2700d184c9441de4ff01ecda726
djm@openbsd.org [Thu, 9 Jul 2026 02:22:10 +0000 (02:22 +0000)]
upstream: when signing hostkey proofs for a client UpdateHostKeys
request, allow each hostkey to perform at most one signature operation. ok
dtucker@
OpenBSD-Commit-ID:
ad4149015634f8156ba723656035ec26140875e8
djm@openbsd.org [Thu, 9 Jul 2026 02:20:19 +0000 (02:20 +0000)]
upstream: setproctitle(3) to identify sshd-session when its
acting as a post- authentication monitor; ok dtucker@
OpenBSD-Commit-ID:
a3c36a005a61ccaeb974afd7b9290b826e1620ba
djm@openbsd.org [Thu, 9 Jul 2026 01:16:37 +0000 (01:16 +0000)]
upstream: delete list of ssh_config(5) options under
documentation of -o and instead just direct readers to the actual
ssh_config(5) manpage.
ok deraadt@
OpenBSD-Commit-ID:
bed2058af847c2149e0e457202a8c4ee7000ad33
djm@openbsd.org [Thu, 9 Jul 2026 01:15:34 +0000 (01:15 +0000)]
upstream: enable the ssh-mldsa44-
ed25519 @openssh.com signature
scheme (and its corresponding certificate form) in the lowest-priority
position.
"what took you so long" deraadt@
OpenBSD-Commit-ID:
b7be74df494323a7021cf230f11eff824d2810d0
djm@openbsd.org [Tue, 7 Jul 2026 04:04:16 +0000 (04:04 +0000)]
upstream: prefer fstat to stat when it's trivial to do so
OpenBSD-Commit-ID:
3af5548ba2112045db392a14c959ca309605bdb9
dtucker@openbsd.org [Sun, 12 Jul 2026 11:19:33 +0000 (11:19 +0000)]
upstream: Add tests for ecdsa 256, 384 and 521 keys in DNS
fingerprints. Dynamically generate the required zone file.
OpenBSD-Regress-ID:
61acdf25efc8c5d3bb0156fd3a53bf8159d3e13a
djm@openbsd.org [Sun, 12 Jul 2026 08:40:00 +0000 (08:40 +0000)]
upstream: check sshd_config output case insensitively
OpenBSD-Regress-ID:
dafa6c3e723cf39ca5e552304372bc085c348102
dtucker@openbsd.org [Sun, 12 Jul 2026 06:10:32 +0000 (06:10 +0000)]
upstream: Add SSHFP tests for
ed25519 key type.
OpenBSD-Regress-ID:
a4bc60d0f398b148a29df3594d5f36de0e4e5ea2
dtucker@openbsd.org [Sat, 11 Jul 2026 09:59:10 +0000 (09:59 +0000)]
upstream: Restructure the SSHFP test in preparation for adding
other key types: - change the DNS names to be rsa.* for the existing RSA
fingerprints. - verify that all required SSHFP records exist in DNS. - only
run the RSA tests if the build supports RSA.
OpenBSD-Regress-ID:
03e4087c3bd09ad8bede788f76f0ab59b732639e
Damien Miller [Wed, 8 Jul 2026 01:07:01 +0000 (11:07 +1000)]
remove README.tun
it's badly out of date, has already been deleted upstream and is not
well-adapted for portable.
Damien Miller [Wed, 8 Jul 2026 00:27:56 +0000 (10:27 +1000)]
add some parentheses to clarify a && || condition
Spotted by Harish Yadav
djm@openbsd.org [Tue, 7 Jul 2026 02:17:18 +0000 (02:17 +0000)]
upstream: unused variables
OpenBSD-Commit-ID:
03fc22fb427b7547ee7844907cf3257bce7fdc3c
djm@openbsd.org [Tue, 7 Jul 2026 01:00:22 +0000 (01:00 +0000)]
upstream: fix GSSAPI option names, that I somehow screwed up while
refactoring servconf.c bz3974 patch from Colin Watson
OpenBSD-Commit-ID:
be39ad3dbe36d9ecdb86f3811da5dfbdc9bcb1e6
Darren Tucker [Mon, 6 Jul 2026 11:14:53 +0000 (21:14 +1000)]
Add 10.4 branch to status page.
Damien Miller [Mon, 6 Jul 2026 07:56:53 +0000 (17:56 +1000)]
depend
Damien Miller [Mon, 6 Jul 2026 07:56:10 +0000 (17:56 +1000)]
crank version numbers
djm@openbsd.org [Mon, 6 Jul 2026 07:54:26 +0000 (07:54 +0000)]
upstream: openssh-10.4
OpenBSD-Commit-ID:
ce7b0749e5139c70410ee92a13d368d7d34262b5
djm@openbsd.org [Mon, 6 Jul 2026 07:53:30 +0000 (07:53 +0000)]
upstream: Fix multiple RFC 4462 (GSSAPIAuthentication) compliance
problems
1) Remove an early failure return for GSSAPI authentication attempts
made for invalid accounts that yielded different behaviour for
valid vs invalid accounts.
2) Fix a situation where some GSSAPI requestes were not correctly
subjected to MaxAuthTries.
3) Fix a moderate pre-authentication resource DoS related to #2.
Add missing logging for error cases.
Report and fixes from Manfred Kaiser, milCERT AT
OpenBSD-Commit-ID:
ca0acdd64eea435d6f89534538a9eb404a5629d3
djm@openbsd.org [Mon, 6 Jul 2026 07:49:58 +0000 (07:49 +0000)]
upstream: fix ownership and lifetime of several bits of client
state that need to persist for the life of the connection, especially the
cached hostkey that was being incorrectly freed early on some paths, possibly
allowing its use after free.
Reported by Zhenpeng (Leo) Lin from depthfirst.com
OpenBSD-Commit-ID:
faaa6ad72e7d69d41fa8b197b606265b7d9bc73f
djm@openbsd.org [Mon, 6 Jul 2026 07:44:48 +0000 (07:44 +0000)]
upstream: Fix cases in GSSAPI and keyboard-interactive
authentication where the minimum per-attempt delay was not being enforced.
Reported by Orange Cyberdefense Vulnerability Team
OpenBSD-Commit-ID:
c40bd35cc2428fcaccad7a141703c28baa6da01e
dtucker@openbsd.org [Sun, 5 Jul 2026 02:46:44 +0000 (02:46 +0000)]
upstream: void functions should not return anything. Patch from Tim
Rice.
OpenBSD-Commit-ID:
bb5021b2b45d9d3f54a012d569872805d107f59c
djm@openbsd.org [Sun, 5 Jul 2026 00:16:21 +0000 (00:16 +0000)]
upstream: fix inverted test that broke ssh-add with keys on stdin. From
Laurence Tratt
OpenBSD-Commit-ID:
bcef522cfa587c7cf035660bb347cff36b65bfbd
Damien Miller [Fri, 3 Jul 2026 04:20:02 +0000 (14:20 +1000)]
grammar fix; from Daniel O'Connor
Damien Miller [Fri, 3 Jul 2026 04:16:29 +0000 (14:16 +1000)]
more config option details in README.privsep
Damien Miller [Fri, 3 Jul 2026 04:10:16 +0000 (14:10 +1000)]
more README.privsep polish
Damien Miller [Fri, 3 Jul 2026 03:33:16 +0000 (13:33 +1000)]
tweak; from dlg@
Damien Miller [Fri, 3 Jul 2026 02:49:26 +0000 (12:49 +1000)]
tweak previous
Damien Miller [Fri, 3 Jul 2026 02:31:27 +0000 (12:31 +1000)]
revise README.privsep for multi-binary model
This rewrites most of the privsep description to more accurately capture
recent changes in how sshd managed privilege across its lifecycle,
including describing the roles of the sshd-session and sshd-auth
helper binaries.
Also 100% more ASCII art
Darren Tucker [Thu, 2 Jul 2026 00:05:43 +0000 (10:05 +1000)]
Need clang >= 19 for constexpr in hardened_malloc.
Darren Tucker [Thu, 25 Jun 2026 08:43:48 +0000 (18:43 +1000)]
Tabs -> spaces.
Zoltan Fridrich [Wed, 16 Apr 2025 13:11:59 +0000 (15:11 +0200)]
Provide better error for non-supported private keys
Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
djm@openbsd.org [Wed, 1 Jul 2026 01:14:39 +0000 (01:14 +0000)]
upstream: more missing mldsa44-
ed25519 , based on GHPR696 from Loganaden
Velvindron
OpenBSD-Commit-ID:
f32e17df54fa66b0e936f1aeb3963f949e4a9bb8
djm@openbsd.org [Wed, 1 Jul 2026 01:08:51 +0000 (01:08 +0000)]
upstream: whitespace
OpenBSD-Commit-ID:
730e54174b2182c7011cc87a0fdae595cd9bcc2d
djm@openbsd.org [Wed, 1 Jul 2026 01:06:54 +0000 (01:06 +0000)]
upstream: simplify SIGINFO output: remove list of active channels (too
verbose) and just display destination and connection duration; requested
deraadt@
OpenBSD-Commit-ID:
cb36192cd53483f8e452ea91bc42be7bbb2fffa3
djm@openbsd.org [Wed, 1 Jul 2026 00:52:31 +0000 (00:52 +0000)]
upstream: Tighten up the introduction a little:
Mention Match as a conditional directive (previously it only
mentioned Host)
Try to use consistent language in the introduction to refer to
configuration directives (previously it used "parameters" and
"keywords" interchangeably).
Mention that comments may appear at the end of the line too, and that
whitespace at the beginning/end of lines is not significant.
OpenBSD-Commit-ID:
e08f34413eeced47478c14d5005726f9bdd5d80e
dtucker@openbsd.org [Wed, 1 Jul 2026 00:52:23 +0000 (00:52 +0000)]
upstream: Move negative-FD checks to before first use. CID 909998,
ok djm@
OpenBSD-Commit-ID:
f0208911d27fd5bd66cd608c7b6fb5a36002d6a5
djm@openbsd.org [Wed, 1 Jul 2026 00:04:46 +0000 (00:04 +0000)]
upstream: ssh -o doesn't support Host or Include options, they are only
valid in the config file. bz3968 from xspielinbox
OpenBSD-Commit-ID:
cbecf11f2eea63e3cf6752e9bbe59091ba60cd32
djm@openbsd.org [Tue, 30 Jun 2026 23:55:32 +0000 (23:55 +0000)]
upstream: mention mldsa44-
ed25519 in usage(); based on GHPR695 from
Loganaden Velvindron
OpenBSD-Commit-ID:
4af2400312b6ca232a68a758160ca5c64ca6a168
tb@openbsd.org [Tue, 30 Jun 2026 03:42:53 +0000 (03:42 +0000)]
upstream: ssherr-libcrypto: avoid use of deprecated
ERR_load_crypto_strings()
Follow regress and use unchecked OPENSSL_init_crypto() because
ERR_load_crypto_strings() has been deprecated in OpenSSL 1.1.0.
This call can in principle fail, in which case there's a fallback
to generic error strings.
There is still use of OpenSSL 3.x-deprecated API in here. That's
a problem for someone else to solve.
ok djm
OpenBSD-Commit-ID:
3e9dc94caa83b361775b83a92425e858f8680c05
djm@openbsd.org [Tue, 30 Jun 2026 02:30:19 +0000 (02:30 +0000)]
upstream: another ruser_name/ruser_group vs attrib_to_stat() ordering
screwup. Coverity CID 910530 via dtucker@
OpenBSD-Commit-ID:
d8c4656119f09304e79fcf2ab32299ed68006a29
djm@openbsd.org [Tue, 30 Jun 2026 00:10:48 +0000 (00:10 +0000)]
upstream: set FD_CLOEXEC on the fds between sftp and its ssh
process, avoids risk of subcommands that write on odd fds breaking the
connection. GHPR693 from Manuel Einfalt; feedback deraadt@ ok dtucker@
OpenBSD-Commit-ID:
91b12cd66580dab6b3bfe5e507a1a8310c8f9149
djm@openbsd.org [Tue, 30 Jun 2026 00:09:01 +0000 (00:09 +0000)]
upstream: check key and IV length received in privsep state
transfer exactly match the expected sizes for the selected cipher; partially
redundant to similar checks in cipher_init(), but nice to be more exact.
GHPR from jmestwa-coder; ok dtucker@
OpenBSD-Commit-ID:
d4a9deef194cc44189e835ac59b7b800b9b5c281
djm@openbsd.org [Mon, 29 Jun 2026 23:00:00 +0000 (23:00 +0000)]
upstream: revert bits that weren't ready for commit yet
OpenBSD-Commit-ID:
ee8a219f02db32778444356ad2d93b983a38a704
djm@openbsd.org [Mon, 29 Jun 2026 22:56:44 +0000 (22:56 +0000)]
upstream: Move user/group name lookup to correct place; coverity
CID 910530 via dtucker@
OpenBSD-Commit-ID:
03ba9f8c720eea38436e4fef4c40814eae1b1fe3
djm@openbsd.org [Mon, 29 Jun 2026 09:14:25 +0000 (09:14 +0000)]
upstream: fix ineffective max file size check when loading
blobs/keys from files and add another one on a patch that was not covered by
the existing ones. From Tess Gauthier via bz3969 and bz3970
OpenBSD-Commit-ID:
c0dec6c587853349113df85b6dc528dc15079af0
djm@openbsd.org [Mon, 29 Jun 2026 08:59:31 +0000 (08:59 +0000)]
upstream: check strdup() return to avoid NULL deref on failure.
bz3948 from RuiHe-MO
OpenBSD-Commit-ID:
2b1fbfb2e1f3359150feadfdf05acaa1c7d211e8
djm@openbsd.org [Mon, 29 Jun 2026 08:57:06 +0000 (08:57 +0000)]
upstream: s/calloc/xcalloc/ to reduce noise from AI bug detectors
that don't understand context
OpenBSD-Commit-ID:
dcef5b1804620f2aed108267bbf5023a81230e14
djm@openbsd.org [Mon, 29 Jun 2026 08:48:22 +0000 (08:48 +0000)]
upstream: fix "ls -n", which was still displaying user/group names
rather than numeric uids/gids. Based on patch from Tamilan in bz3953
OpenBSD-Commit-ID:
65dd2ecb870b727e872cf9df544f8767426d2cc0
djm@openbsd.org [Mon, 29 Jun 2026 08:21:50 +0000 (08:21 +0000)]
upstream: move documentation of the Include directive to near the
start of the options list, alongside that for Match and Host which are
similar insofar as they all affect configuration parsing rather than altering
the configuration directly. from xspielinbox via bz3968
OpenBSD-Commit-ID:
1cde8af8d40dbbe3ea49cf56c5d408946c875230
djm@openbsd.org [Mon, 29 Jun 2026 08:19:21 +0000 (08:19 +0000)]
upstream: mention RefuseConnection, VersionAddendum and
WarnWeakCrypto along with other options. from xspielinbox via bz3968
OpenBSD-Commit-ID:
5d4ef72dc703a74e64175e4611961ea338379d66
djm@openbsd.org [Mon, 29 Jun 2026 08:16:46 +0000 (08:16 +0000)]
upstream: correct directive name (s/Host/Match) in error message
from xspielinbox via bz3968
OpenBSD-Commit-ID:
3aec5cc9d349bcef12abc951490474f1217b4aeb
djm@openbsd.org [Mon, 29 Jun 2026 07:56:19 +0000 (07:56 +0000)]
upstream: report errors in fill_default_options() properly, based on
GHPR649 by Zoltán Fridrich
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
OpenBSD-Commit-ID:
10137e31df74c3100e3abc7d008b1645ca5b45af
djm@openbsd.org [Mon, 29 Jun 2026 07:46:22 +0000 (07:46 +0000)]
upstream: don't use deprecated ERR_load_crypto_strings()
GHPR650 from Mike Frysinger
OpenBSD-Regress-ID:
bfe86d9be1db4569c091f3d763cba04ddbb86ec0
Damien Miller [Mon, 29 Jun 2026 07:21:01 +0000 (17:21 +1000)]
don't leak rrset on fail; GHPR681 from metsw24-max
ok dtucker
Damien Miller [Mon, 29 Jun 2026 07:18:58 +0000 (17:18 +1000)]
check sockaddr length; GHPR681 from metsw24-max
ok dtucker
Damien Miller [Mon, 29 Jun 2026 07:17:28 +0000 (17:17 +1000)]
return result of raise(2); GHPR681 from metsw24-max
ok dtucker
Damien Miller [Mon, 29 Jun 2026 07:16:55 +0000 (17:16 +1000)]
use size_t for lengths; GHPR681 from metsw24-max
ok dtucker
Damien Miller [Mon, 29 Jun 2026 07:15:10 +0000 (17:15 +1000)]
fix leak of error path; GHPR681 from metsw24-max
ok dtucker
djm@openbsd.org [Mon, 29 Jun 2026 07:36:37 +0000 (07:36 +0000)]
upstream: don't print an error message when trying to load a host
private key when PKCS#11 keys are in use, as these don't need the private
half on the filesystem. GHPR664 from Ingo Franzki
OpenBSD-Commit-ID:
c93352e218cb1b74af04e8dc3a42eddec1f312c0
djm@openbsd.org [Mon, 29 Jun 2026 02:13:05 +0000 (02:13 +0000)]
upstream: make ssh-add open it's connection to the agent after it
has finished getopt() processing and not before. This allows the -v flag to
work properly.
ok jca@
OpenBSD-Commit-ID:
b9ac820018875aeb5b43ae2119a70c16a5cd2aef
djm@openbsd.org [Mon, 29 Jun 2026 02:08:55 +0000 (02:08 +0000)]
upstream: Fix bounds checking when signing messages of length
greater than will fit in a size_t. In OpenSSH, messages sizes are bounded by
SSHBUF_SIZE_MAX so this was unreachable. From Swival scanner.
OpenBSD-Commit-ID:
31ab874abe21a528fa995d78023c5ad9444a31e1
djm@openbsd.org [Mon, 29 Jun 2026 01:58:29 +0000 (01:58 +0000)]
upstream: fix ECDSA order check for curves with cofactor != 1. All
supported EC curves have cofactor 1, so this is a nop. From Swival scanner
OpenBSD-Commit-ID:
4ae44cc97714fcb6d19fa56714ede56c1ef521e1
djm@openbsd.org [Mon, 29 Jun 2026 01:53:21 +0000 (01:53 +0000)]
upstream: avoid situation where sftp_download() could get stuck in
a loop if a broken server repeatedly returned zero length while reading a
file. Identified by Swival scanner
OpenBSD-Commit-ID:
53f1de5065ff01952d2abb51747c2418ce21cd96
djm@openbsd.org [Mon, 29 Jun 2026 01:47:21 +0000 (01:47 +0000)]
upstream: avoid download to server-controlled path when performing
download on the commandline. From Swival scanner
OpenBSD-Commit-ID:
d1b2c44305fdfe6d51eed9ecc727e59478bf311f
djm@openbsd.org [Sun, 28 Jun 2026 23:47:16 +0000 (23:47 +0000)]
upstream: resist that return ".." via remote glob during
remote/remote copies, similar to fixes for bz3871 for remote/local copies.
From Swival scanner
OpenBSD-Commit-ID:
c0c20a1b746db55c08e53658bf21ea9405b300a5
djm@openbsd.org [Sun, 28 Jun 2026 23:31:28 +0000 (23:31 +0000)]
upstream: avoid possible NULL deref; from Swival scanner
OpenBSD-Commit-ID:
62ea8e12b7cddee933596e72f8ab0f7364147c0f
djm@openbsd.org [Fri, 26 Jun 2026 06:17:13 +0000 (06:17 +0000)]
upstream: mention that ssh-keyscan output is only as trustworthy as
the network between it and the SSH server; ok markus@
OpenBSD-Commit-ID:
067845df7e8eb776408de5f23a2e6e7019945834
Darren Tucker [Wed, 24 Jun 2026 22:14:47 +0000 (08:14 +1000)]
Dropbear master -> main here too.
Darren Tucker [Wed, 24 Jun 2026 12:05:05 +0000 (22:05 +1000)]
Dropbear's master is now main.
dtucker@openbsd.org [Wed, 24 Jun 2026 11:59:09 +0000 (11:59 +0000)]
upstream: Avoid printf("%s", NULL) since it's not guaranteed to be safe
and will segfault on some -portable platforms.
OpenBSD-Commit-ID:
b49d588f8becf6363305aac42d7d9660fc7fe3ba
Darren Tucker [Wed, 24 Jun 2026 09:22:36 +0000 (19:22 +1000)]
Fix handling of rh-allow-sha1-signatures on Cygwin
The format of openssl.cnf has changed, so append to it instead of trying
to insert into it. Test that openssl can sign RSA with SHA1 before
proceeding.
Darren Tucker [Wed, 24 Jun 2026 09:05:12 +0000 (19:05 +1000)]
Make -j2 for faster builds.
Darren Tucker [Wed, 24 Jun 2026 09:04:48 +0000 (19:04 +1000)]
Set CYGWIN at top-level.
The ensures the symlinks created in any step (eg, logs) are native
symlinks and can be understood by the log upload step.
djm@openbsd.org [Wed, 24 Jun 2026 06:55:12 +0000 (06:55 +0000)]
upstream: mention a caveat regarding GSSAPIStrictAcceptorCheck in
some environments
OpenBSD-Commit-ID:
aa7158d8f22cb34063c1c2d3cbcf30a9489847c2
djm@openbsd.org [Wed, 24 Jun 2026 06:53:57 +0000 (06:53 +0000)]
upstream: add some logging to make debugging interactive/bulk
classification mistakes easier next time (though I think we've got them all
now, really)
OpenBSD-Commit-ID:
5fe3dd4e76ffba787a423e301095d55cf5b0f0dc
djm@openbsd.org [Wed, 24 Jun 2026 06:53:11 +0000 (06:53 +0000)]
upstream: add a missing channels type for bulk/interactive
classification bz3972; ok dtucker@
OpenBSD-Commit-ID:
9c9442ea14be74877e2c876b1fe9fa20d158dd97
Darren Tucker [Wed, 24 Jun 2026 02:19:53 +0000 (12:19 +1000)]
Set build options in /etc/mk.conf once at startup.
dtucker@openbsd.org [Mon, 22 Jun 2026 12:28:48 +0000 (12:28 +0000)]
upstream: Check return values from malloc.
OpenBSD-Regress-ID:
28c8ab94a4fa5d047cec9c865b10bbf3c9ccf6d1
dtucker@openbsd.org [Mon, 22 Jun 2026 12:08:33 +0000 (12:08 +0000)]
upstream: Check return value of sscanf.
OpenBSD-Regress-ID:
e06a8c769541b1aa7d663cc8859ddabd93847e81
tb@openbsd.org [Sun, 21 Jun 2026 19:23:56 +0000 (19:23 +0000)]
upstream: annotate tm_wday = -1 with /* sentinel for error */ per
timegm(3) manpage
suggested by deraadt
OpenBSD-Commit-ID:
2fa92f0b826f0ab9e5d1cb0b2243b8e2f80951b2
djm@openbsd.org [Fri, 19 Jun 2026 05:26:04 +0000 (05:26 +0000)]
upstream: remove cipher_set_keyiv() as nothing uses it from
Loganaden Velvindron
OpenBSD-Commit-ID:
2a6636388028e6f7aa6837d6484a369f3d9c0818
Darren Tucker [Mon, 22 Jun 2026 11:28:58 +0000 (21:28 +1000)]
Output Actions allowlist for uploading to Github.
Darren Tucker [Mon, 22 Jun 2026 09:00:15 +0000 (19:00 +1000)]
Add script to lookup and pin Actions to hashes.
Update recently changed Cygwin Actions and pin remaining unpinned ones.
El Mehdi Abenhazou [Wed, 3 Jun 2026 01:02:31 +0000 (02:02 +0100)]
ci: pin upstream.yml actions to full commit SHAs
Signed-off-by: El Mehdi Abenhazou <mehdiananas007@gmail.com>