]> git.ipfire.org Git - thirdparty/openssh-portable.git/log
thirdparty/openssh-portable.git
14 years ago - (djm) [version.h] crank version V_5_8 anongit/V_5_8 github-selfhosted/V_5_8 github/V_5_8 V_5_8_P2
Damien Miller [Thu, 5 May 2011 01:56:53 +0000 (11:56 +1000)] 
 - (djm) [version.h] crank version

14 years ago - Release 5.8p2
Damien Miller [Tue, 3 May 2011 00:04:42 +0000 (10:04 +1000)] 
 - Release 5.8p2

14 years ago - (djm) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec]
Damien Miller [Tue, 3 May 2011 00:04:19 +0000 (10:04 +1000)] 
 - (djm) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec]
   [contrib/suse/openssh.spec] Prepare for 5.8p2 release.

14 years ago - (djm) closefrom() before running ssh-rand-helper; leftover fds noticed
Damien Miller [Tue, 3 May 2011 00:00:07 +0000 (10:00 +1000)] 
 - (djm) closefrom() before running ssh-rand-helper; leftover fds noticed
   by tmraz AT redhat.com

14 years ago - (dtucker) [contrib/cygwin/ssh-host-config] From Corinna: revamp of the
Darren Tucker [Mon, 21 Feb 2011 10:42:00 +0000 (21:42 +1100)] 
 - (dtucker) [contrib/cygwin/ssh-host-config] From Corinna: revamp of the
   Cygwin-specific service installer script ssh-host-config.  The actual
   functionality is the same, the revisited version is just more
   exact when it comes to check for problems which disallow to run
   certain aspects of the script.  So, part of this script and the also
   rearranged service helper script library "csih" is to check if all
   the tools required to run the script are available on the system.
   The new script also is more thorough to inform the user why the
   script failed.  Patch from vinschen at redhat com.

14 years ago - (dtucker) [contrib/cygwin/ssh-{host,user}-config] Add ECDSA key
Darren Tucker [Sun, 6 Feb 2011 02:31:44 +0000 (13:31 +1100)] 
 - (dtucker) [contrib/cygwin/ssh-{host,user}-config]  Add ECDSA key
   generation and simplify.  Patch from Corinna Vinschen.

14 years ago - (dtucker) [openbsd-compat/port-linux.c] Bug #1851: fix syntax error in
Darren Tucker [Sun, 6 Feb 2011 02:24:13 +0000 (13:24 +1100)] 
 - (dtucker) [openbsd-compat/port-linux.c] Bug #1851: fix syntax error in
   selinux code.  Patch from Leonardo Chiquitto.

14 years ago - (djm) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec] V_5_8_P1
Damien Miller [Fri, 4 Feb 2011 00:57:48 +0000 (11:57 +1100)] 
 - (djm) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec]
   [contrib/suse/openssh.spec] update versions in docs and spec files.
 - Release OpenSSH 5.8p1

14 years ago - djm@cvs.openbsd.org 2011/02/04 00:44:43
Damien Miller [Fri, 4 Feb 2011 00:48:56 +0000 (11:48 +1100)] 
   - djm@cvs.openbsd.org 2011/02/04 00:44:43
     [version.h]
     openssh-5.8

14 years ago - djm@cvs.openbsd.org 2011/02/04 00:44:21
Damien Miller [Fri, 4 Feb 2011 00:48:33 +0000 (11:48 +1100)] 
   - djm@cvs.openbsd.org 2011/02/04 00:44:21
     [key.c]
     fix uninitialised nonce variable; reported by Mateusz Kocielski

14 years ago - djm@cvs.openbsd.org 2011/01/31 21:42:15
Damien Miller [Fri, 4 Feb 2011 00:48:13 +0000 (11:48 +1100)] 
   - djm@cvs.openbsd.org 2011/01/31 21:42:15
     [PROTOCOL.mux]
     cut'n'pasto; from bert.wesarg AT googlemail.com

14 years ago20110128
Damien Miller [Fri, 4 Feb 2011 00:43:04 +0000 (11:43 +1100)] 
20110128
 - (djm) [openbsd-compat/port-linux.c] Check whether SELinux is enabled
   before attempting setfscreatecon(). Check whether matchpathcon()
   succeeded before using its result. Patch from cjwatson AT debian.org;
   bz#1851

14 years agocherry-pick
Damien Miller [Fri, 4 Feb 2011 00:42:11 +0000 (11:42 +1100)] 
cherry-pick

20110125
 - (djm) [configure.ac Makefile.in ssh.c openbsd-compat/port-linux.c
   openbsd-compat/port-linux.h] Move SELinux-specific code from ssh.c to
   port-linux.c to avoid compilation errors. Add -lselinux to ssh when
   building with SELinux support to avoid linking failure; report from
   amk AT spamfence.net; ok dtucker

14 years ago - (djm) [openbsd-compat/port-linux.c] Check whether SELinux is enabled
Damien Miller [Thu, 27 Jan 2011 23:30:18 +0000 (10:30 +1100)] 
 - (djm) [openbsd-compat/port-linux.c] Check whether SELinux is enabled
   before attempting setfscreatecon(). Check whether matchpathcon()
   succeeded before using its result. Patch from cjwatson AT debian.org;
   bz#1851

14 years ago20110127
Tim Rice [Wed, 26 Jan 2011 20:38:57 +0000 (12:38 -0800)] 
20110127
 - (tim) [configure.ac] Consistent M4 quoting throughout, updated obsolete
   AC_TRY_COMPILE with AC_COMPILE_IFELSE, updated obsolete AC_TRY_LINK with
   AC_LINK_IFELSE, updated obsolete AC_TRY_RUN with AC_RUN_IFELSE, misc white
   space changes for consistency/readability. Makes autoconf 2.68 happy.
   "Nice work" djm

14 years ago20110127
Tim Rice [Wed, 26 Jan 2011 20:32:12 +0000 (12:32 -0800)] 
20110127
 - (tim) [config.guess config.sub] Sync with upstream.

14 years ago - (djm) [configure.ac Makefile.in ssh.c openbsd-compat/port-linux.c
Damien Miller [Tue, 25 Jan 2011 01:16:15 +0000 (12:16 +1100)] 
 - (djm) [configure.ac Makefile.in ssh.c openbsd-compat/port-linux.c
   openbsd-compat/port-linux.h] Move SELinux-specific code from ssh.c to
   port-linux.c to avoid compilation errors. Add -lselinux to ssh when
   building with SELinux support to avoid linking failure; report from
   amk AT spamfence.net; ok dtucker

14 years ago - (djm) Release 5.7p1 V_5_7_P1
Damien Miller [Sat, 22 Jan 2011 09:25:11 +0000 (20:25 +1100)] 
 - (djm) Release 5.7p1

14 years agotrim entries older than 5.5p1
Damien Miller [Sat, 22 Jan 2011 09:24:34 +0000 (20:24 +1100)] 
trim entries older than 5.5p1

14 years ago - (djm) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec]
Damien Miller [Sat, 22 Jan 2011 09:23:10 +0000 (20:23 +1100)] 
 - (djm) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec]
   [contrib/suse/openssh.spec] update versions in docs and spec files.

14 years ago - OpenBSD CVS Sync
Damien Miller [Sat, 22 Jan 2011 09:21:33 +0000 (20:21 +1100)] 
 - OpenBSD CVS Sync
   - djm@cvs.openbsd.org 2011/01/22 09:18:53
     [version.h]
     crank to OpenSSH-5.7

14 years ago - (dtucker) [configure.ac openbsd-compat/openssl-compat.{c,h}] Add
Darren Tucker [Fri, 21 Jan 2011 22:37:01 +0000 (09:37 +1100)] 
 - (dtucker) [configure.ac openbsd-compat/openssl-compat.{c,h}] Add
   RSA_get_default_method() for the benefit of openssl versions that don't
   have it (at least openssl-engine-0.9.6b).  Found and tested by Kevin Brott,
   ok djm@.

14 years ago - (djm) [configure.ac] Disable ECC on OpenSSL <0.9.8g. Releases prior to
Damien Miller [Wed, 19 Jan 2011 12:12:27 +0000 (23:12 +1100)] 
 - (djm) [configure.ac] Disable ECC on OpenSSL <0.9.8g. Releases prior to
   0.9.8 lacked it, and 0.9.8a through 0.9.8d have proven buggy in pre-
   release testing (random crashes and failure to load ECC keys).
   ok dtucker@

14 years ago - (tim) [contrib/caldera/openssh.spec] Use CFLAGS from Makefile instead
Tim Rice [Wed, 19 Jan 2011 04:47:04 +0000 (20:47 -0800)] 
 - (tim) [contrib/caldera/openssh.spec] Use CFLAGS from Makefile instead
   of RPM so build completes. Signatures were changed to .asc since 4.1p1.

14 years ago- (dtucker) [LICENCE Makefile.in audit-bsm.c audit-linux.c audit.c audit.h
Darren Tucker [Mon, 17 Jan 2011 10:15:27 +0000 (21:15 +1100)] 
- (dtucker) [LICENCE Makefile.in audit-bsm.c audit-linux.c audit.c audit.h
   configure.ac defines.h loginrec.c]  Bug #1402: add linux audit subsystem
   support, based on patches from Tomas Mraz and jchadima at redhat.

14 years ago - (dtucker) [openbsd-compat/port-linux.c] Fix minor bug caught by -Werror on
Darren Tucker [Mon, 17 Jan 2011 07:50:22 +0000 (18:50 +1100)] 
 - (dtucker) [openbsd-compat/port-linux.c] Fix minor bug caught by -Werror on
   the tinderbox.

14 years ago - (tim) [regress/agent-getpeereid.sh] shell portability fix.
Tim Rice [Mon, 17 Jan 2011 06:53:56 +0000 (22:53 -0800)] 
 - (tim) [regress/agent-getpeereid.sh] shell portability fix.

14 years ago - (djm) [configure.ac regress/agent-getpeereid.sh regress/multiplex.sh]
Damien Miller [Mon, 17 Jan 2011 05:17:09 +0000 (16:17 +1100)] 
 - (djm) [configure.ac regress/agent-getpeereid.sh regress/multiplex.sh]
   [regress/sftp-glob.sh regress/test-exec.sh] Rework how feature tests are
   disabled on platforms that do not support them; add a "config_defined()"
   shell function that greps for defines in config.h and use them to decide
   on feature tests.
   Convert a couple of existing grep's over config.h to use the new function
   Add a define "FILESYSTEM_NO_BACKSLASH" for filesystem that can't represent
   backslash characters in filenames, enable it for Cygwin and use it to turn
   of tests for quotes backslashes in sftp-glob.sh.
   based on discussion with vinschen AT redhat.com and dtucker@; ok dtucker@

14 years ago - (dtucker) [openbsd-compat/port-linux.c] Bug #1838: Add support for the new
Darren Tucker [Mon, 17 Jan 2011 00:55:59 +0000 (11:55 +1100)] 
 - (dtucker) [openbsd-compat/port-linux.c] Bug #1838: Add support for the new
   Linux OOM-killer magic values that changed in 2.6.36 kernels, with fallback
   to the old values.  Feedback from vapier at gentoo org and djm, ok djm.

14 years ago - (djm) [regress/agent-getpeereid.sh] leave stdout attached when running
Damien Miller [Mon, 17 Jan 2011 00:52:40 +0000 (11:52 +1100)] 
 - (djm) [regress/agent-getpeereid.sh] leave stdout attached when running
   ssh-add to avoid $SUDO failures on Linux

14 years ago - (djm) [regress/agent-ptrace.sh] Fix false failure on OS X by adding
Damien Miller [Mon, 17 Jan 2011 00:20:18 +0000 (11:20 +1100)] 
 - (djm) [regress/agent-ptrace.sh] Fix false failure on OS X by adding
   its unique snowflake of a gdb error to the ones we look for.

14 years ago - (djm) [regress/Makefile] use $TEST_SSH_KEYGEN instead of the one in
Damien Miller [Sun, 16 Jan 2011 23:51:40 +0000 (10:51 +1100)] 
 - (djm) [regress/Makefile] use $TEST_SSH_KEYGEN instead of the one in
   $PATH, fix cleanup of droppings; reported by openssh AT
   roumenpetrov.info; ok dtucker@

14 years ago - djm@cvs.openbsd.org 2011/01/16 12:05:59
Damien Miller [Sun, 16 Jan 2011 12:18:33 +0000 (23:18 +1100)] 
   - djm@cvs.openbsd.org 2011/01/16 12:05:59
     [clientloop.c]
     a couple more tweaks to the post-close protocol 1 stderr/stdout flush:
     now that we use atomicio(), convert them from while loops to if statements
     add test and cast to compile cleanly with -Wsigned

14 years ago - djm@cvs.openbsd.org 2011/01/16 11:50:36
Damien Miller [Sun, 16 Jan 2011 12:17:45 +0000 (23:17 +1100)] 
   - djm@cvs.openbsd.org 2011/01/16 11:50:36
     [sshconnect.c]
     reset the SIGPIPE handler when forking to execute child processes;
     ok dtucker@

14 years ago - djm@cvs.openbsd.org 2011/01/16 11:50:05
Damien Miller [Sun, 16 Jan 2011 12:16:53 +0000 (23:16 +1100)] 
   - djm@cvs.openbsd.org 2011/01/16 11:50:05
     [clientloop.c]
     Use atomicio when flushing protocol 1 std{out,err} buffers at
     session close. This was a latent bug exposed by setting a SIGCHLD
     handler and spotted by kevin.brott AT gmail.com; ok dtucker@

14 years ago - (dtucker) [Makefile.in configure.ac regress/kextype.sh] Skip sha256-based
Darren Tucker [Sun, 16 Jan 2011 07:28:09 +0000 (18:28 +1100)] 
 - (dtucker) [Makefile.in configure.ac regress/kextype.sh] Skip sha256-based
   on configurations that don't have it.

14 years agonot February yet...
Darren Tucker [Sun, 16 Jan 2011 07:24:04 +0000 (18:24 +1100)] 
not February yet...

14 years ago - (tim) [regress/cert-hostkey.sh] Add missing TEST_SSH_ECC guard around some
Tim Rice [Fri, 14 Jan 2011 06:36:14 +0000 (22:36 -0800)] 
 - (tim) [regress/cert-hostkey.sh] Add missing TEST_SSH_ECC guard around some
   ecdsa bits.

14 years ago - (tim) [regress/cert-hostkey.sh] Typo. Missing $ on variable name.
Tim Rice [Fri, 14 Jan 2011 06:20:27 +0000 (22:20 -0800)] 
 - (tim) [regress/cert-hostkey.sh] Typo. Missing $ on variable name.

14 years ago - (djm) [Makefile.in] Use shell test to disable ecdsa key generating in
Damien Miller [Fri, 14 Jan 2011 03:47:37 +0000 (14:47 +1100)] 
 - (djm) [Makefile.in] Use shell test to disable ecdsa key generating in
   host-key-force target rather than a substitution that is replaced with a
   comment so that the Makefile.in is still a syntactically valid Makefile
   (useful to run the distprep target)

14 years ago - djm@cvs.openbsd.org 2011/01/13 21:55:25
Damien Miller [Fri, 14 Jan 2011 01:01:50 +0000 (12:01 +1100)] 
   - djm@cvs.openbsd.org 2011/01/13 21:55:25
     [PROTOCOL.mux]
     correct protocol names and add a couple of missing protocol number
     defines; patch from bert.wesarg AT googlemail.com

14 years ago - djm@cvs.openbsd.org 2011/01/13 21:54:53
Damien Miller [Fri, 14 Jan 2011 01:01:29 +0000 (12:01 +1100)] 
   - djm@cvs.openbsd.org 2011/01/13 21:54:53
     [mux.c]
     correct error messages; patch from bert.wesarg AT googlemail.com

14 years ago - (djm) [regress/kextype.sh] Testing diffie-hellman-group-exchange-sha256
Damien Miller [Thu, 13 Jan 2011 11:05:14 +0000 (22:05 +1100)] 
 - (djm) [regress/kextype.sh] Testing diffie-hellman-group-exchange-sha256
   should not depend on ECC support

14 years ago - (djm) [myproposal.h] Fix reversed OPENSSL_VERSION_NUMBER test and bad
Damien Miller [Thu, 13 Jan 2011 11:00:20 +0000 (22:00 +1100)] 
 - (djm) [myproposal.h] Fix reversed OPENSSL_VERSION_NUMBER test and bad
   #define that was causing diffie-hellman-group-exchange-sha256 to be
   incorrectly disabled

14 years ago - (djm) [regress/Makefile] add a few more generated files to the clean
Damien Miller [Thu, 13 Jan 2011 10:08:27 +0000 (21:08 +1100)] 
 - (djm) [regress/Makefile] add a few more generated files to the clean
   target

14 years ago - (djm) [entropy.c] cast OPENSSL_VERSION_NUMBER to u_long to avoid
Damien Miller [Thu, 13 Jan 2011 10:05:27 +0000 (21:05 +1100)] 
 - (djm) [entropy.c] cast OPENSSL_VERSION_NUMBER to u_long to avoid
   gcc warning on platforms where it defaults to int

14 years ago - (tim) [Makefile.in configure.ac opensshd.init.in] Add support for generating
Tim Rice [Thu, 13 Jan 2011 06:35:43 +0000 (22:35 -0800)] 
 - (tim) [Makefile.in configure.ac opensshd.init.in] Add support for generating
   ecdsa keys. ok djm.

14 years ago - (tim) [Makefile.in] test the ECC bits if we have the capability. ok djm
Tim Rice [Thu, 13 Jan 2011 03:06:31 +0000 (19:06 -0800)] 
 - (tim) [Makefile.in] test the ECC bits if we have the capability. ok djm

14 years ago - (djm) [misc.c] include time.h for nanosleep() prototype
Damien Miller [Thu, 13 Jan 2011 01:21:34 +0000 (12:21 +1100)] 
 - (djm) [misc.c] include time.h for nanosleep() prototype

14 years ago - (djm) [configure.ac] Fix broken test for gcc >= 4.4 with per-compiler
Damien Miller [Wed, 12 Jan 2011 05:00:37 +0000 (16:00 +1100)] 
 - (djm) [configure.ac] Fix broken test for gcc >= 4.4 with per-compiler
   flag tests that don't depend on gcc version at all; suggested by and
   ok dtucker@

14 years ago - (djm) [configure.ac] Turn on -Wno-unused-result for gcc >= 4.4 to avoid
Damien Miller [Wed, 12 Jan 2011 02:34:02 +0000 (13:34 +1100)] 
 - (djm) [configure.ac] Turn on -Wno-unused-result for gcc >= 4.4 to avoid
   silly warnings on write() calls we don't care succeed or not.

14 years ago - djm@cvs.openbsd.org 2011/01/12 01:53:14
Damien Miller [Wed, 12 Jan 2011 02:32:03 +0000 (13:32 +1100)] 
   - djm@cvs.openbsd.org 2011/01/12 01:53:14
     avoid some integer overflows mostly with GLOB_APPEND and GLOB_DOOFFS
     and sanity check arguments (these will be unnecessary when we switch
     struct glob members from being type into to size_t in the future);
     "looks ok" tedu@ feedback guenther@

14 years ago - nicm@cvs.openbsd.org 2010/10/08 21:48:42
Damien Miller [Wed, 12 Jan 2011 02:30:18 +0000 (13:30 +1100)] 
   - nicm@cvs.openbsd.org 2010/10/08 21:48:42
     [openbsd-compat/glob.c]
     Extend GLOB_LIMIT to cover readdir and stat and bump the malloc limit
     from ARG_MAX to 64K.
     Fixes glob-using programs (notably ftp) able to be triggered to hit
     resource limits.
     Idea from a similar NetBSD change, original problem reported by jasper@.
     ok millert tedu jasper

14 years ago - djm@cvs.openbsd.org 2011/01/11 06:13:10
Damien Miller [Tue, 11 Jan 2011 06:20:29 +0000 (17:20 +1100)] 
   - djm@cvs.openbsd.org 2011/01/11 06:13:10
     [clientloop.c ssh-keygen.c sshd.c]
     some unsigned long long casts that make things a bit easier for
     portable without resorting to dropping PRIu64 formats everywhere

14 years ago - djm@cvs.openbsd.org 2011/01/11 06:06:09
Damien Miller [Tue, 11 Jan 2011 06:20:05 +0000 (17:20 +1100)] 
   - djm@cvs.openbsd.org 2011/01/11 06:06:09
     [sshlogin.c]
     fd leak on error paths; from zinovik@
     NB. Id sync only; we use loginrec.c that was also audited and fixed
     recently

14 years ago - djm@cvs.openbsd.org 2011/01/08 10:51:51
Damien Miller [Tue, 11 Jan 2011 06:18:56 +0000 (17:18 +1100)] 
   - djm@cvs.openbsd.org 2011/01/08 10:51:51
     [clientloop.c]
     use host and not options.hostname, as the latter may have unescaped
     substitution characters

14 years ago - (djm) [platform.c] Some missing includes that show up under -Werror
Damien Miller [Tue, 11 Jan 2011 06:02:23 +0000 (17:02 +1100)] 
 - (djm) [platform.c] Some missing includes that show up under -Werror

14 years ago - (tim) [regress/host-expand.sh] Fix for building outside of read only
Tim Rice [Mon, 10 Jan 2011 20:56:26 +0000 (12:56 -0800)] 
 - (tim) [regress/host-expand.sh] Fix for building outside of read only
   source tree.

14 years ago - (djm) [Makefile.in] list ssh_host_ecdsa key in PATHSUBS; spotted by
Damien Miller [Sat, 8 Jan 2011 22:19:50 +0000 (09:19 +1100)] 
 - (djm) [Makefile.in] list ssh_host_ecdsa key in PATHSUBS; spotted by
   openssh AT roumenpetrov.info

14 years ago - (djm) [regress/keytype.sh] s/echo -n/echon/ to repair failing regress
Damien Miller [Sat, 8 Jan 2011 10:58:20 +0000 (21:58 +1100)] 
 - (djm) [regress/keytype.sh] s/echo -n/echon/ to repair failing regress
   test on OSX and others. Reported by imorgan AT nas.nasa.gov

14 years ago - djm@cvs.openbsd.org 2011/01/06 23:01:35
Damien Miller [Thu, 6 Jan 2011 23:02:52 +0000 (10:02 +1100)] 
   - djm@cvs.openbsd.org 2011/01/06 23:01:35
     [sshconnect.c]
     reset SIGCHLD handler to SIG_DFL when execuring LocalCommand;
     ok markus@

14 years ago - djm@cvs.openbsd.org 2011/01/06 22:46:21
Damien Miller [Thu, 6 Jan 2011 22:54:20 +0000 (09:54 +1100)] 
   - djm@cvs.openbsd.org 2011/01/06 22:46:21
     [regress/Makefile regress/host-expand.sh]
     regress test for LocalCommand %n expansion from bert.wesarg AT
     googlemail.com; ok markus@

14 years ago - djm@cvs.openbsd.org 2011/01/06 22:23:02
Damien Miller [Thu, 6 Jan 2011 22:51:52 +0000 (09:51 +1100)] 
   - djm@cvs.openbsd.org 2011/01/06 22:23:02
     [clientloop.c]
     when exiting due to ServerAliveTimeout, mention the hostname that caused
     it (useful with backgrounded controlmaster)

14 years ago - djm@cvs.openbsd.org 2011/01/06 22:23:53
Damien Miller [Thu, 6 Jan 2011 22:51:17 +0000 (09:51 +1100)] 
   - djm@cvs.openbsd.org 2011/01/06 22:23:53
     [ssh.c]
     unbreak %n expansion in LocalCommand; patch from bert.wesarg AT
     googlemail.com; ok markus@

14 years ago - (djm) [regress/cert-hostkey.sh regress/cert-userkey.sh] fix shell test
Damien Miller [Thu, 6 Jan 2011 22:50:08 +0000 (09:50 +1100)] 
 - (djm) [regress/cert-hostkey.sh regress/cert-userkey.sh] fix shell test
   for no-ECC case. Patch from cristian.ionescu-idbohrn AT axis.com

14 years ago - otto@cvs.openbsd.org 2011/01/04 20:44:13
Damien Miller [Thu, 6 Jan 2011 11:44:44 +0000 (22:44 +1100)] 
   - otto@cvs.openbsd.org 2011/01/04 20:44:13
     [ssh-keyscan.c]
     handle ecdsa-sha2 with various key lengths; hint and ok djm@

14 years ago - djm@cvs.openbsd.org 2010/12/24 21:41:48
Damien Miller [Thu, 6 Jan 2011 11:44:18 +0000 (22:44 +1100)] 
   - djm@cvs.openbsd.org 2010/12/24 21:41:48
     [auth-options.c]
     don't send the actual forced command in a debug message; ok markus deraadt

14 years ago - djm@cvs.openbsd.org 2010/12/15 00:49:27
Damien Miller [Thu, 6 Jan 2011 11:43:44 +0000 (22:43 +1100)] 
   - djm@cvs.openbsd.org 2010/12/15 00:49:27
     [readpass.c]
     fix ControlMaster=ask regression
     reset SIGCHLD handler before fork (and restore it after) so we don't miss
     the the askpass child's exit status. Correct test for exit status/signal to
     account for waitpid() failure; with claudio@ ok claudio@ markus@

14 years ago - markus@cvs.openbsd.org 2010/12/14 11:59:06
Damien Miller [Thu, 6 Jan 2011 11:42:04 +0000 (22:42 +1100)] 
   - markus@cvs.openbsd.org 2010/12/14 11:59:06
     [sshconnect.c]
     don't mention key type in key-changed-warning, since we also print
     this warning if a new key type appears. ok djm@

14 years ago - jmc@cvs.openbsd.org 2010/12/09 14:13:33
Damien Miller [Thu, 6 Jan 2011 11:41:21 +0000 (22:41 +1100)] 
   - jmc@cvs.openbsd.org 2010/12/09 14:13:33
     [scp.1 scp.c]
     scp.1: grammer fix
     scp.c: add -3 to usage()

14 years ago - markus@cvs.openbsd.org 2010/12/08 22:46:03
Damien Miller [Thu, 6 Jan 2011 11:40:30 +0000 (22:40 +1100)] 
   - markus@cvs.openbsd.org 2010/12/08 22:46:03
     [scp.1 scp.c]
     add a new -3 option to scp: Copies between two remote hosts are
     transferred through the local host.  Without this option the data
     is copied directly between the two remote hosts. ok djm@ (bugzilla #1837)

14 years ago - (djm) [configure.ac Makefile.in] Use mandoc as preferred manpage
Damien Miller [Mon, 3 Jan 2011 21:16:27 +0000 (08:16 +1100)] 
 - (djm) [configure.ac Makefile.in] Use mandoc as preferred manpage
   formatter if it is present, followed by nroff and groff respectively.
   Fixes distprep target on OpenBSD (which has bumped groff/nroff to ports
   in favour of mandoc). feedback and ok tim

14 years ago - (djm) [Makefile.in] revert local hack I didn't intend to commit
Damien Miller [Mon, 3 Jan 2011 03:48:14 +0000 (14:48 +1100)] 
 - (djm) [Makefile.in] revert local hack I didn't intend to commit

14 years ago - (djm) [configure.ac] Check whether libdes is needed when building
Damien Miller [Sun, 2 Jan 2011 10:53:07 +0000 (21:53 +1100)] 
 - (djm) [configure.ac] Check whether libdes is needed when building
   with Heimdal krb5 support. On OpenBSD this library no longer exists,
   so linking it unconditionally causes a build failure; ok dtucker

14 years ago - (djm) [loginrec.c] Fix some fd leaks on error paths. ok dtucker
Damien Miller [Sun, 2 Jan 2011 10:43:59 +0000 (21:43 +1100)] 
 - (djm) [loginrec.c] Fix some fd leaks on error paths. ok dtucker

14 years ago - djm@cvs.openbsd.org 2010/12/08 04:02:47
Damien Miller [Sun, 26 Dec 2010 03:26:45 +0000 (14:26 +1100)] 
   - djm@cvs.openbsd.org 2010/12/08 04:02:47
     [ssh_config.5 sshd_config.5]
     explain that IPQoS arguments are separated by whitespace; iirc requested
     by jmc@ a while back

14 years agoId sync
Darren Tucker [Sat, 4 Dec 2010 23:34:08 +0000 (10:34 +1100)] 
Id sync

14 years ago - djm@cvs.openbsd.org 2010/12/04 00:21:19
Darren Tucker [Sat, 4 Dec 2010 22:45:50 +0000 (09:45 +1100)] 
   - djm@cvs.openbsd.org 2010/12/04 00:21:19
     [regress/sftp-cmds.sh]
     adjust for hard-link support

14 years ago - (dtucker) [regress/Makefile] Id sync.
Darren Tucker [Sat, 4 Dec 2010 22:29:31 +0000 (09:29 +1100)] 
 - (dtucker) [regress/Makefile] Id sync.

14 years ago - djm@cvs.openbsd.org 2010/12/04 13:31:37
Darren Tucker [Sat, 4 Dec 2010 22:03:31 +0000 (09:03 +1100)] 
   - djm@cvs.openbsd.org 2010/12/04 13:31:37
     [hostfile.c]
     fix fd leak; spotted and ok dtucker

14 years ago - djm@cvs.openbsd.org 2010/12/04 00:18:01
Darren Tucker [Sat, 4 Dec 2010 22:02:47 +0000 (09:02 +1100)] 
   - djm@cvs.openbsd.org 2010/12/04 00:18:01
     [sftp-server.c sftp.1 sftp-client.h sftp.c PROTOCOL sftp-client.c]
     add a protocol extension to support a hard link operation. It is
     available through the "ln" command in the client. The old "ln"
     behaviour of creating a symlink is available using its "-s" option
     or through the preexisting "symlink" command; based on a patch from
     miklos AT szeredi.hu in bz#1555; ok markus@

14 years ago - djm@cvs.openbsd.org 2010/12/03 23:55:27
Darren Tucker [Sat, 4 Dec 2010 22:01:47 +0000 (09:01 +1100)] 
   - djm@cvs.openbsd.org 2010/12/03 23:55:27
     [auth-rsa.c]
     move check for revoked keys to run earlier (in auth_rsa_key_allowed)
     bz#1829; patch from ldv AT altlinux.org; ok markus@

14 years ago - (dtucker) OpenBSD CVS Sync
Darren Tucker [Sat, 4 Dec 2010 22:00:30 +0000 (09:00 +1100)] 
 - (dtucker) OpenBSD CVS Sync
   - djm@cvs.openbsd.org 2010/12/03 23:49:26
     [schnorr.c]
     check that g^x^q === 1 mod p; recommended by JPAKE author Feng Hao
     (this code is still disabled, but apprently people are treating it as
     a reference implementation)

14 years ago - (dtucker) openbsd-compat/openssl-compat.c] remove sleep leftover from
Darren Tucker [Sat, 4 Dec 2010 21:46:05 +0000 (08:46 +1100)] 
 - (dtucker) openbsd-compat/openssl-compat.c] remove sleep leftover from
   debugging.  Spotted by djm.

14 years ago - (dtucker) [configure.ac moduli.c openbsd-compat/openssl-compat.{c,h}] Add
Darren Tucker [Sat, 4 Dec 2010 12:20:50 +0000 (23:20 +1100)] 
 - (dtucker) [configure.ac moduli.c openbsd-compat/openssl-compat.{c,h}]  Add
   shims for the new, non-deprecated OpenSSL key generation functions for
   platforms that don't have the new interfaces.

14 years ago - (djm) [openbsd-compat/bindresvport.c] Use arc4random_uniform(range)
Damien Miller [Thu, 2 Dec 2010 23:50:26 +0000 (10:50 +1100)] 
 - (djm) [openbsd-compat/bindresvport.c] Use arc4random_uniform(range)
   instead of (arc4random() % range)

14 years ago - djm@cvs.openbsd.org 2010/11/29 23:45:51
Damien Miller [Wed, 1 Dec 2010 01:21:51 +0000 (12:21 +1100)] 
   - djm@cvs.openbsd.org 2010/11/29 23:45:51
     [auth.c hostfile.c hostfile.h ssh.c ssh_config.5 sshconnect.c]
     [sshconnect.h sshconnect2.c]
     automatically order the hostkeys requested by the client based on
     which hostkeys are already recorded in known_hosts. This avoids
     hostkey warnings when connecting to servers with new ECDSA keys
     that are preferred by default; with markus@

14 years ago - markus@cvs.openbsd.org 2010/11/29 18:57:04
Damien Miller [Wed, 1 Dec 2010 01:03:39 +0000 (12:03 +1100)] 
   - markus@cvs.openbsd.org 2010/11/29 18:57:04
     [authfile.c]
     correctly load comment for encrypted rsa1 keys;
     report/fix Joachim Schipper; ok djm@

14 years ago - djm@cvs.openbsd.org 2010/11/26 05:52:49
Damien Miller [Wed, 1 Dec 2010 01:03:19 +0000 (12:03 +1100)] 
   - djm@cvs.openbsd.org 2010/11/26 05:52:49
     [scp.c]
     Pass through ssh command-line flags and options when doing remote-remote
     transfers, e.g. to enable agent forwarding which is particularly useful
     in this case; bz#1837 ok dtucker@

14 years ago - djm@cvs.openbsd.org 2010/11/25 04:10:09
Damien Miller [Wed, 1 Dec 2010 01:02:59 +0000 (12:02 +1100)] 
   - djm@cvs.openbsd.org 2010/11/25 04:10:09
     [session.c]
     replace close() loop for fds 3->64 with closefrom();
     ok markus deraadt dtucker

14 years ago - djm@cvs.openbsd.org 2010/11/24 01:24:14
Damien Miller [Wed, 1 Dec 2010 01:02:35 +0000 (12:02 +1100)] 
   - djm@cvs.openbsd.org 2010/11/24 01:24:14
     [channels.c]
     remove a debug() that pollutes stderr on client connecting to a server
     in debug mode (channel_close_fds is called transitively from the session
     code post-fork); bz#1719, ok dtucker

14 years ago - djm@cvs.openbsd.org 2010/11/23 23:57:24
Damien Miller [Wed, 1 Dec 2010 01:02:14 +0000 (12:02 +1100)] 
   - djm@cvs.openbsd.org 2010/11/23 23:57:24
     [clientloop.c]
     avoid NULL deref on receiving a channel request on an unknown or invalid
     channel; report bz#1842 from jchadima AT redhat.com; ok dtucker@

14 years ago - djm@cvs.openbsd.org 2010/11/23 02:35:50
Damien Miller [Wed, 1 Dec 2010 01:01:51 +0000 (12:01 +1100)] 
   - djm@cvs.openbsd.org 2010/11/23 02:35:50
     [auth.c]
     use strict_modes already passed as function argument over referencing
     global options.strict_modes

14 years ago - djm@cvs.openbsd.org 2010/11/21 10:57:07
Damien Miller [Wed, 1 Dec 2010 01:01:21 +0000 (12:01 +1100)] 
   - djm@cvs.openbsd.org 2010/11/21 10:57:07
     [authfile.c]
     Refactor internals of private key loading and saving to work on memory
     buffers rather than directly on files. This will make a few things
     easier to do in the future; ok markus@

14 years ago - djm@cvs.openbsd.org 2010/11/21 01:01:13
Damien Miller [Wed, 1 Dec 2010 00:50:35 +0000 (11:50 +1100)] 
   - djm@cvs.openbsd.org 2010/11/21 01:01:13
     [clientloop.c misc.c misc.h ssh-agent.1 ssh-agent.c]
     honour $TMPDIR for client xauth and ssh-agent temporary directories;
     feedback and ok markus@

14 years ago - OpenBSD CVS Sync
Damien Miller [Wed, 1 Dec 2010 00:50:14 +0000 (11:50 +1100)] 
 - OpenBSD CVS Sync
   - deraadt@cvs.openbsd.org 2010/11/20 05:12:38
     [auth2-pubkey.c]
     clean up cases of ;;

14 years ago - (djm) [defines.h] Add IP DSCP defines
Damien Miller [Tue, 23 Nov 2010 23:50:04 +0000 (10:50 +1100)] 
 - (djm) [defines.h] Add IP DSCP defines

14 years ago - (dtucker) [packet.c] Remove redundant local declaration of "int tos".
Darren Tucker [Tue, 23 Nov 2010 23:46:37 +0000 (10:46 +1100)] 
 - (dtucker) [packet.c] Remove redundant local declaration of "int tos".

14 years ago - (djm) [loginrec.c] Relax permission requirement on btmp logs to allow
Damien Miller [Tue, 23 Nov 2010 23:36:15 +0000 (10:36 +1100)] 
 - (djm) [loginrec.c] Relax permission requirement on btmp logs to allow
   group read/write. ok dtucker@

14 years ago - (dtucker) [platform.c session.c] Move the getluid call out of session.c and
Darren Tucker [Tue, 23 Nov 2010 23:09:13 +0000 (10:09 +1100)] 
 - (dtucker) [platform.c session.c] Move the getluid call out of session.c and
   into the platform-specific code  Only affects SCO, tested by and ok tim@.