]> git.ipfire.org Git - thirdparty/openssh-portable.git/log
thirdparty/openssh-portable.git
10 years agoupstream commit
djm@openbsd.org [Sat, 23 Jul 2016 02:54:08 +0000 (02:54 +0000)] 
upstream commit

fix pledge violation with ssh -f; reported by Valentin
Kozamernik ok dtucker@

Upstream-ID: a61db7988db88d9dac3c4dd70e18876a8edf84aa

10 years agoupstream commit
djm@openbsd.org [Fri, 22 Jul 2016 07:00:46 +0000 (07:00 +0000)] 
upstream commit

improve wording; suggested by jmc@

Upstream-ID: 55cb0a24c8e0618b3ceec80998dc82c85db2d2f8

10 years agoupstream commit
dtucker@openbsd.org [Fri, 22 Jul 2016 05:46:11 +0000 (05:46 +0000)] 
upstream commit

Lower loglevel for "Authenticated with partial success"
message similar to other similar level.  bz#2599, patch from cgallek at
gmail.com, ok markus@

Upstream-ID: 3faab814e947dc7b2e292edede23e94c608cb4dd

10 years agoretry waitpid on EINTR failure
Damien Miller [Fri, 22 Jul 2016 04:06:36 +0000 (14:06 +1000)] 
retry waitpid on EINTR failure

patch from Jakub Jelen on bz#2581; ok dtucker@

10 years agoupstream commit
djm@openbsd.org [Fri, 22 Jul 2016 03:47:36 +0000 (03:47 +0000)] 
upstream commit

constify a few functions' arguments; patch from Jakub
Jelen bz#2581

Upstream-ID: f2043f51454ea37830ff6ad60c8b32b4220f448d

10 years agoupstream commit
djm@openbsd.org [Fri, 22 Jul 2016 03:39:13 +0000 (03:39 +0000)] 
upstream commit

move debug("%p", key) to before key is free'd; probable
undefined behaviour on strict compilers; reported by Jakub Jelen bz#2581

Upstream-ID: 767f323e1f5819508a0e35e388ec241bac2f953a

10 years agoupstream commit
djm@openbsd.org [Fri, 22 Jul 2016 03:35:11 +0000 (03:35 +0000)] 
upstream commit

reverse the order in which -J/JumpHost proxies are visited to
be more intuitive and document

reported by and manpage bits naddy@

Upstream-ID: 3a68fd6a841fd6cf8cedf6552a9607ba99df179a

10 years agoupstream commit
dtucker@openbsd.org [Thu, 21 Jul 2016 01:39:35 +0000 (01:39 +0000)] 
upstream commit

Skip passwords longer than 1k in length so clients can't
easily DoS sshd by sending very long passwords, causing it to spend CPU
hashing them. feedback djm@, ok markus@.

Brought to our attention by tomas.kuthan at oracle.com, shilei-c at
360.cn and coredump at autistici.org

Upstream-ID: d0af7d4a2190b63ba1d38eec502bc4be0be9e333

10 years agoupstream commit
naddy@openbsd.org [Wed, 20 Jul 2016 10:45:27 +0000 (10:45 +0000)] 
upstream commit

Do not clobber the global jump_host variables when
parsing an inactive configuration.  ok djm@

Upstream-ID: 5362210944d91417d5976346d41ac0b244350d31

10 years agoupstream commit
jmc@openbsd.org [Tue, 19 Jul 2016 12:59:16 +0000 (12:59 +0000)] 
upstream commit

tweak previous;

Upstream-ID: f3c1a5b3f05dff366f60c028728a2b43f15ff534

10 years agoupstream commit
dtucker@openbsd.org [Tue, 19 Jul 2016 11:38:53 +0000 (11:38 +0000)] 
upstream commit

Allow wildcard for PermitOpen hosts as well as ports.
bz#2582, patch from openssh at mzpqnxow.com and jjelen at redhat.com.  ok
markus@

Upstream-ID: af0294e9b9394c4e16e991424ca0a47a7cc605f2

10 years agoupstream commit
markus@openbsd.org [Mon, 18 Jul 2016 11:35:33 +0000 (11:35 +0000)] 
upstream commit

Reduce timing attack against obsolete CBC modes by always
computing the MAC over a fixed size of data. Reported by Jean Paul
Degabriele, Kenny Paterson, Torben Hansen and Martin Albrecht. ok djm@

Upstream-ID: f20a13279b00ba0afbacbcc1f04e62e9d41c2912

10 years agoSearch users for one with a valid salt.
Darren Tucker [Thu, 21 Jul 2016 04:17:31 +0000 (14:17 +1000)] 
Search users for one with a valid salt.

If the root account is locked (eg password "!!" or "*LK*") keep looking
until we find a user with a valid salt to use for crypting passwords of
invalid users.  ok djm@

10 years agoExplicitly specify source files for regress tools.
Darren Tucker [Mon, 18 Jul 2016 07:22:49 +0000 (17:22 +1000)] 
Explicitly specify source files for regress tools.

Since adding $(REGRESSLIBS), $? is wrong because it includes only the
changed source files.  $< seems like it'd be right however it doesn't
seem to work on some non-GNU makes, so do what works everywhere.

10 years agoConditionally include err.h.
Darren Tucker [Mon, 18 Jul 2016 07:12:22 +0000 (17:12 +1000)] 
Conditionally include err.h.

10 years agoRemove local implementation of err, errx.
Darren Tucker [Mon, 18 Jul 2016 06:26:26 +0000 (16:26 +1000)] 
Remove local implementation of err, errx.

We now have a shared implementation in libopenbsd-compat.

10 years agoupstream commit
djm@openbsd.org [Mon, 18 Jul 2016 06:08:01 +0000 (06:08 +0000)] 
upstream commit

Add some unsigned overflow checks for extra_pad. None of
these are reachable with the amount of padding that we use internally.
bz#2566, pointed out by Torben Hansen. ok markus@

Upstream-ID: 4d4be8450ab2fc1b852d5884339f8e8c31c3fd76

10 years agoAdd dependency on libs for unit tests.
Darren Tucker [Mon, 18 Jul 2016 05:43:25 +0000 (15:43 +1000)] 
Add dependency on libs for unit tests.

Makes "./configure && make tests" work again.  ok djm@

10 years agoCorrect location for kexfuzz in clean target.
Darren Tucker [Mon, 18 Jul 2016 03:47:39 +0000 (13:47 +1000)] 
Correct location for kexfuzz in clean target.

10 years agoHandle PAM_MAXTRIES from modules.
Darren Tucker [Sun, 17 Jul 2016 23:33:25 +0000 (09:33 +1000)] 
Handle PAM_MAXTRIES from modules.

bz#2249: handle the case where PAM returns PAM_MAXTRIES by ceasing to offer
password and keyboard-interative authentication methods.  Should prevent
"sshd ignoring max retries" warnings in the log.  ok djm@

It probably won't trigger with keyboard-interactive in the default
configuration because the retry counter is stored in module-private
storage which goes away with the sshd PAM process (see bz#688).  On the
other hand, those cases probably won't log a warning either.

10 years agoupstream commit
djm@openbsd.org [Sun, 17 Jul 2016 04:20:16 +0000 (04:20 +0000)] 
upstream commit

support UTF-8 characters in ssh(1) banners using
schwarze@'s safe fmprintf printer; bz#2058

feedback schwarze@ ok dtucker@

Upstream-ID: a72ce4e3644c957643c9524eea2959e41b91eea7

10 years agoupstream commit
jmc@openbsd.org [Sat, 16 Jul 2016 06:57:55 +0000 (06:57 +0000)] 
upstream commit

- add proxyjump to the options list - formatting fixes -
update usage()

ok djm

Upstream-ID: 43d318e14ce677a2eec8f21ef5ba2f9f68a59457

10 years agoupstream commit
dtucker@openbsd.org [Fri, 15 Jul 2016 05:01:58 +0000 (05:01 +0000)] 
upstream commit

Reduce the syslog level of some relatively common protocol
events from LOG_CRIT by replacing fatal() calls with logdie().  Part of
bz#2585, ok djm@

Upstream-ID: 9005805227c94edf6ac02a160f0e199638d288e5

10 years agomissing openssl/dh.h
Damien Miller [Fri, 15 Jul 2016 09:14:48 +0000 (19:14 +1000)] 
missing openssl/dh.h

10 years agocast to avoid type warning in error message
Damien Miller [Fri, 15 Jul 2016 08:47:07 +0000 (18:47 +1000)] 
cast to avoid type warning in error message

10 years agoMove VA_COPY macro into compat header.
Darren Tucker [Fri, 15 Jul 2016 04:48:30 +0000 (14:48 +1000)] 
Move VA_COPY macro into compat header.

Some AIX compilers unconditionally undefine va_copy but don't set it back
to an internal function, causing link errors.  In some compat code we
already use VA_COPY instead so move the two existing instances into the
shared header and use for sshbuf-getput-basic.c too.  Should fix building
with at lease some versions of AIX's compiler.  bz#2589, ok djm@

10 years agodisable ciphers not supported by OpenSSL
Damien Miller [Fri, 15 Jul 2016 04:45:34 +0000 (14:45 +1000)] 
disable ciphers not supported by OpenSSL

bz#2466 ok dtucker@

10 years agoadd a --disable-pkcs11 knob
Damien Miller [Fri, 15 Jul 2016 03:54:31 +0000 (13:54 +1000)] 
add a --disable-pkcs11 knob

10 years agofix newline escaping for unsupported_algorithms
Damien Miller [Fri, 15 Jul 2016 03:44:38 +0000 (13:44 +1000)] 
fix newline escaping for unsupported_algorithms

The hmac-ripemd160 was incorrect and could lead to broken
Makefiles on systems that lacked support for it, but I made
all the others consistent too.

10 years agoupstream commit
djm@openbsd.org [Fri, 15 Jul 2016 00:24:30 +0000 (00:24 +0000)] 
upstream commit

Add a ProxyJump ssh_config(5) option and corresponding -J
ssh(1) command-line flag to allow simplified indirection through a SSH
bastion or "jump host".

These options construct a proxy command that connects to the
specified jump host(s) (more than one may be specified) and uses
port-forwarding to establish a connection to the next destination.

This codifies the safest way of indirecting connections through SSH
servers and makes it easy to use.

ok markus@

Upstream-ID: fa899cb8b26d889da8f142eb9774c1ea36b04397

10 years agoMap umac_ctx struct name too.
Darren Tucker [Fri, 15 Jul 2016 02:56:39 +0000 (12:56 +1000)] 
Map umac_ctx struct name too.

Prevents size mismatch linker warnings on Solaris 11.

10 years agoMitigate timing of disallowed users PAM logins.
Darren Tucker [Fri, 15 Jul 2016 03:49:44 +0000 (13:49 +1000)] 
Mitigate timing of disallowed users PAM logins.

When sshd decides to not allow a login (eg PermitRootLogin=no) and
it's using PAM, it sends a fake password to PAM so that the timing for
the failure is not noticeably different whether or not the password
is correct.  This behaviour can be detected by sending a very long
password string which is slower to hash than the fake password.

Mitigate by constructing an invalid password that is the same length
as the one from the client and thus takes the same time to hash.
Diff from djm@

10 years agoDetermine appropriate salt for invalid users.
Darren Tucker [Fri, 15 Jul 2016 03:32:45 +0000 (13:32 +1000)] 
Determine appropriate salt for invalid users.

When sshd is processing a non-PAM login for a non-existent user it uses
the string from the fakepw structure as the salt for crypt(3)ing the
password supplied by the client.  That string has a Blowfish prefix, so on
systems that don't understand that crypt will fail fast due to an invalid
salt, and even on those that do it may have significantly different timing
from the hash methods used for real accounts (eg sha512).  This allows
user enumeration by, eg, sending large password strings.  This was noted
by EddieEzra.Harari at verint.com (CVE-2016-6210).

To mitigate, use the same hash algorithm that root uses for hashing
passwords for users that do not exist on the system.  ok djm@

10 years agoOpenSSL 1.1.x not currently supported.
Darren Tucker [Thu, 14 Jul 2016 11:19:59 +0000 (21:19 +1000)] 
OpenSSL 1.1.x not currently supported.

10 years agoCheck for VIS_ALL.
Darren Tucker [Thu, 14 Jul 2016 02:25:24 +0000 (12:25 +1000)] 
Check for VIS_ALL.

If we don't have it, set BROKEN_STRNVIS to activate the compat replacement.

10 years agoupstream commit
dtucker@openbsd.org [Thu, 14 Jul 2016 01:24:21 +0000 (01:24 +0000)] 
upstream commit

Correct equal in test.

Upstream-Regress-ID: 4e32f7a5c57a619c4e8766cb193be2a1327ec37a

10 years agoupstream commit
tb@openbsd.org [Mon, 11 Jul 2016 21:38:13 +0000 (21:38 +0000)] 
upstream commit

Add missing "recvfd" pledge promise: Raf Czlonka reported
ssh coredumps when Control* keywords were set in ssh_config. This patch also
fixes similar problems with scp and sftp.

ok deraadt, looks good to millert

Upstream-ID: ca2099eade1ef3e87a79614fefa26a0297ad8a3b

10 years agoupstream commit
tedu@openbsd.org [Mon, 11 Jul 2016 03:19:44 +0000 (03:19 +0000)] 
upstream commit

obsolete note about fascistloggin is obsolete. ok djm
dtucker

Upstream-ID: dae60df23b2bb0e89f42661ddd96a7b0d1b7215a

10 years agoAdd compat code for missing wcwidth.
Darren Tucker [Thu, 14 Jul 2016 00:59:09 +0000 (10:59 +1000)] 
Add compat code for missing wcwidth.

If we don't have wcwidth force fallback implementations of nl_langinfo
and mbtowc.  Based on advice from Ingo Schwarze.

10 years agofix missing include for systems with err.h
Damien Miller [Wed, 13 Jul 2016 23:48:48 +0000 (09:48 +1000)] 
fix missing include for systems with err.h

10 years agoMove err.h replacements into compat lib.
Darren Tucker [Wed, 13 Jul 2016 04:42:35 +0000 (14:42 +1000)] 
Move err.h replacements into compat lib.

Move implementations of err.h replacement functions into their own file
in the libopenbsd-compat so we can use them in kexfuzz.c too.  ok djm@

10 years agoCheck for wchar.h and langinfo.h
Darren Tucker [Mon, 11 Jul 2016 07:23:38 +0000 (17:23 +1000)] 
Check for wchar.h and langinfo.h

Wrap includes in the appropriate #ifdefs.

10 years agowhitelist more architectures for seccomp-bpf
Damien Miller [Fri, 8 Jul 2016 03:59:13 +0000 (13:59 +1000)] 
whitelist more architectures for seccomp-bpf

bz#2590 - testing and patch from Jakub Jelen

10 years agoupstream commit
guenther@openbsd.org [Mon, 4 Jul 2016 18:01:44 +0000 (18:01 +0000)] 
upstream commit

DEBUGLIBS has been broken since the gcc4 switch, so delete
it.  CFLAGS contains -g by default anyway

problem noted by Edgar Pettijohn (edgar (at) pettijohn-web.com)
ok millert@ kettenis@ deraadt@

Upstream-Regress-ID: 4a0bb72f95c63f2ae9daa8a040ac23914bddb542

10 years agoupstream commit
djm@openbsd.org [Fri, 8 Jul 2016 03:44:42 +0000 (03:44 +0000)] 
upstream commit

Improve crypto ordering for Encrypt-then-MAC (EtM) mode
MAC algorithms.

Previously we were computing the MAC, decrypting the packet and then
checking the MAC. This gave rise to the possibility of creating a
side-channel oracle in the decryption step, though no such oracle has
been identified.

This adds a mac_check() function that computes and checks the MAC in
one pass, and uses it to advance MAC checking for EtM algorithms to
before payload decryption.

Reported by Jean Paul Degabriele, Kenny Paterson, Torben Hansen and
Martin Albrecht. feedback and ok markus@

Upstream-ID: 1999bb67cab47dda5b10b80d8155fe83d4a1867b

10 years agoupstream commit
guenther@openbsd.org [Mon, 4 Jul 2016 18:01:44 +0000 (18:01 +0000)] 
upstream commit

DEBUGLIBS has been broken since the gcc4 switch, so
delete it.  CFLAGS contains -g by default anyway

problem noted by Edgar Pettijohn (edgar (at) pettijohn-web.com)
ok millert@ kettenis@ deraadt@

Upstream-ID: 96c5054e3e1f170c6276902d5bc65bb3b87a2603

10 years agoupstream commit
dtucker@openbsd.org [Thu, 30 Jun 2016 05:17:05 +0000 (05:17 +0000)] 
upstream commit

Explicitly check for 100% completion to avoid potential
floating point rounding error, which could cause progressmeter to report 99%
on completion. While there invert the test so the 100% case is clearer.  with
& ok djm@

Upstream-ID: a166870c5878e422f3c71ff802e2ccd7032f715d

10 years agoupstream commit
jmc@openbsd.org [Wed, 29 Jun 2016 17:14:28 +0000 (17:14 +0000)] 
upstream commit

sort the -o list;

Upstream-ID: 1a97465ede8790b4d47cb618269978e07f41f8ac

10 years agoupstream commit
djm@openbsd.org [Thu, 23 Jun 2016 05:17:51 +0000 (05:17 +0000)] 
upstream commit

fix AuthenticationMethods during configuration re-parse;
reported by Juan Francisco Cantero Hurtado

Upstream-ID: 8ffa1dac25c7577eca8238e825317ab20848f9b4

10 years agoupstream commit
djm@openbsd.org [Sun, 19 Jun 2016 07:48:02 +0000 (07:48 +0000)] 
upstream commit

revert 1.34; causes problems loading public keys

reported by semarie@

Upstream-ID: b393794f8935c8b15d98a407fe7721c62d2ed179

10 years agoupstream commit
jmc@openbsd.org [Fri, 17 Jun 2016 06:33:30 +0000 (06:33 +0000)] 
upstream commit

grammar fix;

Upstream-ID: 5d5b21c80f1e81db367333ce0bb3e5874fb3e463

10 years agoupstream commit
djm@openbsd.org [Fri, 17 Jun 2016 05:06:23 +0000 (05:06 +0000)] 
upstream commit

translate OpenSSL error codes to something more
meaninful; bz#2522 reported by Jakub Jelen, ok dtucker@

Upstream-ID: 4cb0795a366381724314e6515d57790c5930ffe5

10 years agoupstream commit
djm@openbsd.org [Fri, 17 Jun 2016 05:03:40 +0000 (05:03 +0000)] 
upstream commit

ban AuthenticationMethods="" and accept
AuthenticationMethods=any for the default behaviour of not requiring multiple
authentication

bz#2398 from Jakub Jelen; ok dtucker@

Upstream-ID: fabd7f44d59e4518d241d0d01e226435cc23cf27

10 years agoupstream commit
dtucker@openbsd.org [Thu, 16 Jun 2016 11:00:17 +0000 (11:00 +0000)] 
upstream commit

Include stdarg.h for va_copy as per man page.

Upstream-ID: 105d6b2f1af2fbd9d91c893c436ab121434470bd

10 years agoupstream commit
jmc@openbsd.org [Thu, 16 Jun 2016 06:10:45 +0000 (06:10 +0000)] 
upstream commit

keys stored in openssh format can have comments too; diff
from yonas yanfa, tweaked a bit;

ok djm

Upstream-ID: 03d48536da6e51510d73ade6fcd44ace731ceb27

10 years agoget_remote_name_or_ip inside LOGIN_NEEDS_UTMPX
Darren Tucker [Mon, 20 Jun 2016 05:55:34 +0000 (15:55 +1000)] 
get_remote_name_or_ip inside LOGIN_NEEDS_UTMPX

Apply the same get_remote_name_or_ip -> session_get_remote_name_or_ip
change as commit 95767262 to the code inside #ifdef LOGIN_NEEDS_UTMPX.
Fixes build on AIX.

10 years agoRemove duplicate code from PAM. ok djm@
Darren Tucker [Fri, 17 Jun 2016 04:34:09 +0000 (14:34 +1000)] 
Remove duplicate code from PAM.  ok djm@

10 years agoupstream commit
dtucker@openbsd.org [Wed, 15 Jun 2016 00:40:40 +0000 (00:40 +0000)] 
upstream commit

Remove "POSSIBLE BREAK-IN ATTEMPT!" from log message
about forward and reverse DNS not matching.  We haven't supported IP-based
auth methods for a very long time so it's now misleading.  part of bz#2585,
ok markus@

Upstream-ID: 5565ef0ee0599b27f0bd1d3bb1f8a323d8274e29

10 years agoMove platform_disable_tracing into its own file.
Darren Tucker [Wed, 15 Jun 2016 01:22:38 +0000 (11:22 +1000)] 
Move platform_disable_tracing into its own file.

Prevents link errors resolving the extern "options" when platform.o
gets linked into ssh-agent when building --with-pam.

10 years agoTrack skipped upstream commit IDs.
Darren Tucker [Tue, 14 Jun 2016 03:55:12 +0000 (13:55 +1000)] 
Track skipped upstream commit IDs.

There are a small number of "upstream" commits that do not correspond to
a file in -portable.  This file tracks those so that we can reconcile
OpenBSD and Portable to ensure that no commits are accidentally missed.

If you add something to .skipped-commit-ids please also add an upstream
ID line in the following format when you commit it.

    Upstream-ID: 321065a95a7ccebdd5fd08482a1e19afbf524e35
    Upstream-ID: d4f699a421504df35254cf1c6f1a7c304fb907ca
    Upstream-ID: aafe246655b53b52bc32c8a24002bc262f4230f7
    Upstream-ID: 8fa9cd1dee3c3339ae329cf20fb591db6d605120
    Upstream-ID: f31327a48dd4103333cc53315ec53fe65ed8a17a
    Upstream-ID: edbfde98c40007b7752a4ac106095e060c25c1ef
    Upstream-ID: 052fd565e3ff2d8cec3bc957d1788f50c827f8e2
    Upstream-ID: 7cf73737f357492776223da1c09179fa6ba74660
    Upstream-ID: 180d84674be1344e45a63990d60349988187c1ae
    Upstream-ID: f6ae971186ba68d066cd102e57d5b0b2c211a5ee

10 years agoRemove now-defunct .cvsignore files. ok djm
Darren Tucker [Tue, 14 Jun 2016 03:51:01 +0000 (13:51 +1000)] 
Remove now-defunct .cvsignore files. ok djm

10 years agoupstream commit
dtucker@openbsd.org [Wed, 8 Jun 2016 02:13:01 +0000 (02:13 +0000)] 
upstream commit

Back out rev 1.28 "Check min and max sizes sent by the
client" change. It caused "key_verify failed for server_host_key" in clients
that send a DH-GEX min value less that DH_GRP_MIN, eg old OpenSSH and PuTTY.
ok djm@

Upstream-ID: 452979d3ca5c1e9dff063287ea0a5314dd091f65

10 years agoUse Solaris setpflags(__PROC_PROTECT, ...).
Darren Tucker [Tue, 14 Jun 2016 00:48:27 +0000 (10:48 +1000)] 
Use Solaris setpflags(__PROC_PROTECT, ...).

Where possible, use Solaris setpflags to disable process tracing on
ssh-agent and sftp-server.  bz#2584, based on a patch from huieying.lee
at oracle.com, ok djm.

10 years agoShorten prctl code a tiny bit.
Darren Tucker [Tue, 14 Jun 2016 00:43:53 +0000 (10:43 +1000)] 
Shorten prctl code a tiny bit.

10 years agoMove prctl PR_SET_DUMPABLE into platform.c.
Darren Tucker [Thu, 9 Jun 2016 06:23:07 +0000 (16:23 +1000)] 
Move prctl PR_SET_DUMPABLE into platform.c.

This should make it easier to add additional platform support such as
Solaris (bz#2584).

10 years agoupstream commit
dtucker@openbsd.org [Fri, 3 Jun 2016 04:10:41 +0000 (04:10 +0000)] 
upstream commit

Add a test for ssh(1)'s config file parsing.

Upstream-Regress-ID: 558b7f4dc45cc3761cc3d3e889b9f3c5bc91e601

10 years agoupstream commit
dtucker@openbsd.org [Fri, 3 Jun 2016 03:47:59 +0000 (03:47 +0000)] 
upstream commit

Add 'sshd' to the test ID as I'm about to add a similar
 set for ssh.

Upstream-Regress-ID: aea7a9c3bac638530165c801ce836875b228ae7a

10 years agoupstream commit
schwarze@openbsd.org [Mon, 30 May 2016 12:14:08 +0000 (12:14 +0000)] 
upstream commit

stricter malloc.conf(5) options for utf8 tests

Upstream-Regress-ID: 111efe20a0fb692fa1a987f6e823310f9b25abf6

10 years agoupstream commit
schwarze@openbsd.org [Mon, 30 May 2016 12:05:56 +0000 (12:05 +0000)] 
upstream commit

Fix two rare edge cases: 1. If vasprintf() returns < 0,
 do not access a NULL pointer in snmprintf(), and do not free() the pointer
 returned from vasprintf() because on some systems other than OpenBSD, it
 might be a bogus pointer. 2. If vasprintf() returns == 0, return 0 and ""
 rather than -1 and NULL.

Besides, free(dst) is pointless after failure (not a bug).

One half OK martijn@, the other half OK deraadt@;
committing quickly before people get hurt.

Upstream-Regress-ID: b164f20923812c9bac69856dbc1385eb1522cba4

10 years agoupstream commit
schwarze@openbsd.org [Thu, 26 May 2016 19:14:25 +0000 (19:14 +0000)] 
upstream commit

test the new utf8 module

Upstream-Regress-ID: c923d05a20e84e4ef152cbec947fdc4ce6eabbe3

10 years agoupstream commit
dtucker@openbsd.org [Tue, 3 May 2016 15:30:46 +0000 (15:30 +0000)] 
upstream commit

Set umask to prevent "Bad owner or permissions" errors.

Upstream-Regress-ID: 8fdf2fc4eb595ccd80c443f474d639f851145417

10 years agoupstream commit
djm@openbsd.org [Tue, 3 May 2016 14:41:04 +0000 (14:41 +0000)] 
upstream commit

support doas

Upstream-Regress-ID: 8d5572b27ea810394eeda432d8b4e9e1064a7c38

10 years agoupstream commit
djm@openbsd.org [Tue, 3 May 2016 13:48:33 +0000 (13:48 +0000)] 
upstream commit

unit tests for sshbuf_dup_string()

Upstream-Regress-ID: 7521ff150dc7f20511d1c2c48fd3318e5850a96d

10 years agoupstream commit
jmc@openbsd.org [Fri, 3 Jun 2016 06:44:12 +0000 (06:44 +0000)] 
upstream commit

tweak previous;

Upstream-ID: 92979f1a0b63e041a0e5b08c9ed0ba9b683a3698

10 years agoupstream commit
dtucker@openbsd.org [Fri, 3 Jun 2016 04:09:38 +0000 (04:09 +0000)] 
upstream commit

Allow ExitOnForwardFailure and ClearAllForwardings to be
 overridden when using ssh -W (but still default to yes in that case).
 bz#2577, ok djm@.

Upstream-ID: 4b20c419e93ca11a861c81c284090cfabc8c54d4

10 years agoupstream commit
dtucker@openbsd.org [Fri, 3 Jun 2016 03:14:41 +0000 (03:14 +0000)] 
upstream commit

Move the host and port used by ssh -W into the Options
 struct. This will make future changes a bit easier.  ok djm@

Upstream-ID: 151bce5ecab2fbedf0d836250a27968d30389382

10 years agoupstream commit
dtucker@openbsd.org [Wed, 1 Jun 2016 04:19:49 +0000 (04:19 +0000)] 
upstream commit

Check min and max sizes sent by the client against what
 we support before passing them to the monitor.  ok djm@

Upstream-ID: 750627e8117084215412bff00a25b1586ab17ece

10 years agoupstream commit
dtucker@openbsd.org [Tue, 31 May 2016 23:46:14 +0000 (23:46 +0000)] 
upstream commit

Ensure that the client's proposed DH-GEX max value is at
 least as big as the minimum the server will accept.  ok djm@

Upstream-ID: b4b84fa04aab2de7e79a6fee4a6e1c189c0fe775

10 years agoAdd compat bits to utf8.c.
Darren Tucker [Mon, 6 Jun 2016 01:36:13 +0000 (11:36 +1000)] 
Add compat bits to utf8.c.

10 years agoFix utf->utf8 typo.
Darren Tucker [Mon, 6 Jun 2016 01:33:43 +0000 (11:33 +1000)] 
Fix utf->utf8 typo.

10 years agoupstream commit
schwarze@openbsd.org [Mon, 30 May 2016 18:34:41 +0000 (18:34 +0000)] 
upstream commit

Backout rev. 1.43 for now.

The function update_progress_meter() calls refresh_progress_meter()
which calls snmprintf() which calls malloc(); but update_progress_meter()
acts as the SIGALRM signal handler.

"malloc(): error: recursive call" reported by sobrado@.

Upstream-ID: aaae57989431e5239c101f8310f74ccc83aeb93e

10 years agoupstream commit
schwarze@openbsd.org [Mon, 30 May 2016 12:57:21 +0000 (12:57 +0000)] 
upstream commit

Even when only writing an unescaped character, the dst
 buffer may need to grow, or it would be overrun; issue found by tb@ with
 malloc.conf(5) 'C'.

While here, reserve an additional byte for the terminating NUL
up front such that we don't have to realloc() later just for that.

OK tb@

Upstream-ID: 30ebcc0c097c4571b16f0a78b44969f170db0cff

10 years agoupstream commit
schwarze@openbsd.org [Mon, 30 May 2016 12:05:56 +0000 (12:05 +0000)] 
upstream commit

Fix two rare edge cases: 1. If vasprintf() returns < 0,
 do not access a NULL pointer in snmprintf(), and do not free() the pointer
 returned from vasprintf() because on some systems other than OpenBSD, it
 might be a bogus pointer. 2. If vasprintf() returns == 0, return 0 and ""
 rather than -1 and NULL.

Besides, free(dst) is pointless after failure (not a bug).

One half OK martijn@, the other half OK deraadt@;
committing quickly before people get hurt.

Upstream-ID: b7bcd2e82fc168a8eff94e41f5db336ed986fed0

10 years agoupstream commit
schwarze@openbsd.org [Wed, 25 May 2016 23:48:45 +0000 (23:48 +0000)] 
upstream commit

To prevent screwing up terminal settings when printing to
 the terminal, for ASCII and UTF-8, escape bytes not forming characters and
 bytes forming non-printable characters with vis(3) VIS_OCTAL. For other
 character sets, abort printing of the current string in these cases.  In
 particular, * let scp(1) respect the local user's LC_CTYPE locale(1); *
 sanitize data received from the remote host; * sanitize filenames, usernames,
 and similar data even locally; * take character display widths into account
 for the progressmeter.

This is believed to be sufficient to keep the local terminal safe
on OpenBSD, but bad things can still happen on other systems with
state-dependent locales because many places in the code print
unencoded ASCII characters into the output stream.

Using feedback from djm@ and martijn@,
various aspects discussed with many others.

deraadt@ says it should go in now, i probably already hesitated too long

Upstream-ID: e66afbc94ee396ddcaffd433b9a3b80f387647e0

10 years agoupstream commit
dtucker@openbsd.org [Tue, 24 May 2016 04:43:45 +0000 (04:43 +0000)] 
upstream commit

KNF compression proposal and simplify the client side a
 little.  ok djm@

Upstream-ID: aa814b694efe9e5af8a26e4c80a05526ae6d6605

10 years agoupstream commit
dtucker@openbsd.org [Tue, 24 May 2016 02:31:57 +0000 (02:31 +0000)] 
upstream commit

Back out 'plug memleak'.

Upstream-ID: 4faacdde136c24a961e24538de373660f869dbc0

10 years agoupstream commit
djm@openbsd.org [Mon, 23 May 2016 23:30:50 +0000 (23:30 +0000)] 
upstream commit

prefer agent-hosted keys to keys from PKCS#11; ok markus

Upstream-ID: 7417f7653d58d6306d9f8c08d0263d050e2fd8f4

10 years agoupstream commit
dtucker@openbsd.org [Mon, 23 May 2016 00:17:27 +0000 (00:17 +0000)] 
upstream commit

Plug mem leak in filter_proposal.  ok djm@

Upstream-ID: bf968da7cfcea2a41902832e7d548356a4e2af34

10 years agoUpdate vis.h and vis.c from OpenBSD.
Darren Tucker [Fri, 3 Jun 2016 06:03:44 +0000 (16:03 +1000)] 
Update vis.h and vis.c from OpenBSD.

This will be needed for the upcoming utf8 changes.

10 years agomodified: configure.ac
Tim Rice [Tue, 31 May 2016 18:13:22 +0000 (11:13 -0700)] 
modified:   configure.ac
whitspace clean up. No code changes.

10 years agowhitespace at EOL
Damien Miller [Tue, 31 May 2016 06:45:28 +0000 (16:45 +1000)] 
whitespace at EOL

10 years agoAdd missing ssh-host-config --name option
Darren Tucker [Mon, 30 May 2016 09:35:28 +0000 (19:35 +1000)] 
Add missing ssh-host-config --name option

Patch from vinschen@redhat.com.

10 years agoFix comment about sshpam_const and AIX.
Darren Tucker [Fri, 20 May 2016 00:01:58 +0000 (10:01 +1000)] 
Fix comment about sshpam_const and AIX.

From mschwager via github.

10 years agoDeny lstat syscalls in seccomp sandbox
Damien Miller [Thu, 19 May 2016 23:56:53 +0000 (09:56 +1000)] 
Deny lstat syscalls in seccomp sandbox

Avoids sandbox violations for some krb/gssapi libraries.

10 years agoupstream commit
djm@openbsd.org [Thu, 19 May 2016 07:45:32 +0000 (07:45 +0000)] 
upstream commit

fix type of ed25519 values

Upstream-ID: b32d0cb372bbe918ca2de56906901eae225a59b0

10 years agoupstream commit
markus@openbsd.org [Wed, 4 May 2016 14:32:26 +0000 (14:32 +0000)] 
upstream commit

add IdentityAgent; noticed & ok jmc@

Upstream-ID: 4ba9034b00a4cf1beae627f0728da897802df88a

10 years agoupstream commit
markus@openbsd.org [Wed, 4 May 2016 14:29:58 +0000 (14:29 +0000)] 
upstream commit

allow setting IdentityAgent to SSH_AUTH_SOCK; ok djm@

Upstream-ID: 20c508480d8db3eef18942c0fc39b1fcf25652ac

10 years agoupstream commit
markus@openbsd.org [Wed, 4 May 2016 14:22:33 +0000 (14:22 +0000)] 
upstream commit

move SSH_MSG_NONE, so we don't have to include ssh1.h;
 ok deraadt@

Upstream-ID: c2f97502efc761a41b18c17ddf460e138ca7994e

10 years agoinitialise salen in binresvport_sa
Damien Miller [Mon, 9 May 2016 23:51:06 +0000 (09:51 +1000)] 
initialise salen in binresvport_sa

avoids failures with UsePrivilegedPort=yes

patch from Juan Gallego

10 years agoupstream commit
markus@openbsd.org [Wed, 4 May 2016 14:04:40 +0000 (14:04 +0000)] 
upstream commit

missing const in prototypes (ssh1)

Upstream-ID: 789c6ad4928b5fa557369b88c3a6a34926082c05