]> git.ipfire.org Git - thirdparty/openssh-portable.git/log
thirdparty/openssh-portable.git
10 years agoupstream commit
djm@openbsd.org [Mon, 17 Nov 2014 00:21:40 +0000 (00:21 +0000)] 
upstream commit

fix KRL generation when multiple CAs are in use

We would generate an invalid KRL when revoking certs by serial
number for multiple CA keys due to a section being written out
twice.

Also extend the regress test to catch this case by having it
produce a multi-CA KRL.

Reported by peter AT pean.org

10 years agoupstream commit
djm@openbsd.org [Tue, 18 Nov 2014 01:02:25 +0000 (01:02 +0000)] 
upstream commit

fix NULL pointer dereference crash in key loading

found by Michal Zalewski's AFL fuzzer

10 years agoupstream commit
djm@openbsd.org [Mon, 17 Nov 2014 00:21:40 +0000 (00:21 +0000)] 
upstream commit

fix KRL generation when multiple CAs are in use

We would generate an invalid KRL when revoking certs by serial
number for multiple CA keys due to a section being written out
twice.

Also extend the regress test to catch this case by having it
produce a multi-CA KRL.

Reported by peter AT pean.org

10 years agoupstream commit
bentley@openbsd.org [Sat, 15 Nov 2014 14:41:03 +0000 (14:41 +0000)] 
upstream commit

Reduce instances of `` '' in manuals.

troff displays these as typographic quotes, but nroff implementations
almost always print them literally, which rarely has the intended effect
with modern fonts, even in stock xterm.

These uses of `` '' can be replaced either with more semantic alternatives
or with Dq, which prints typographic quotes in a UTF-8 locale (but will
automatically fall back to `` '' in an ASCII locale).

improvements and ok schwarze@

10 years agoupstream commit
djm@openbsd.org [Mon, 10 Nov 2014 22:25:49 +0000 (22:25 +0000)] 
upstream commit

mux-related manual tweaks

mention ControlPersist=0 is the same as ControlPersist=yes

recommend that ControlPath sockets be placed in a og-w directory

10 years agoPrepare scripts for next Cygwin release
Damien Miller [Wed, 5 Nov 2014 00:01:31 +0000 (11:01 +1100)] 
Prepare scripts for next Cygwin release

Makes the Cygwin-specific ssh-user-config script independent of the
existence of /etc/passwd.  The next Cygwin release will allow to
generate passwd and group entries from the Windows account DBs, so the
scripts have to adapt.

from Corinna Vinschen

10 years agoinclude version number in OpenSSL-too-old error
Damien Miller [Wed, 29 Oct 2014 23:45:41 +0000 (10:45 +1100)] 
include version number in OpenSSL-too-old error

10 years agoupstream commit
lteo@openbsd.org [Fri, 24 Oct 2014 02:01:20 +0000 (02:01 +0000)] 
upstream commit

Remove unnecessary include: netinet/in_systm.h is not needed
 by these programs.

NB. skipped for portable

ok deraadt@ millert@

10 years agoupstream commit
djm@openbsd.org [Mon, 20 Oct 2014 03:43:01 +0000 (03:43 +0000)] 
upstream commit

whitespace

10 years agoupstream commit
daniel@openbsd.org [Tue, 14 Oct 2014 03:09:59 +0000 (03:09 +0000)] 
upstream commit

plug a memory leak; from Maxime Villard.

ok djm@

10 years agoupstream commit
jmc@openbsd.org [Thu, 9 Oct 2014 06:21:31 +0000 (06:21 +0000)] 
upstream commit

tweak previous;

10 years agoupstream commit
djm@openbsd.org [Mon, 13 Oct 2014 00:38:35 +0000 (00:38 +0000)] 
upstream commit

whitespace

10 years agoupstream commit
djm@openbsd.org [Wed, 8 Oct 2014 22:20:25 +0000 (22:20 +0000)] 
upstream commit

Tweak config reparsing with host canonicalisation

Make the second pass through the config files always run when
hostname canonicalisation is enabled.

Add a "Match canonical" criteria that allows ssh_config Match
blocks to trigger only in the second config pass.

Add a -G option to ssh that causes it to parse its configuration
and dump the result to stdout, similar to "sshd -T"

Allow ssh_config Port options set in the second config parse
phase to be applied (they were being ignored).

bz#2267 bz#2286; ok markus

10 years agoupstream commit
djm@openbsd.org [Wed, 8 Oct 2014 22:15:27 +0000 (22:15 +0000)] 
upstream commit

another -Wpointer-sign from clang

10 years agoupstream commit
djm@openbsd.org [Wed, 8 Oct 2014 22:15:06 +0000 (22:15 +0000)] 
upstream commit

fix a few -Wpointer-sign warnings from clang

10 years agoupstream commit
djm@openbsd.org [Wed, 8 Oct 2014 21:45:48 +0000 (21:45 +0000)] 
upstream commit

parse cert sections using nested buffers to reduce
 copies; ok markus

10 years agoupstream commit
djm@openbsd.org [Mon, 6 Oct 2014 00:47:15 +0000 (00:47 +0000)] 
upstream commit

correct options in usage(); from mancha1 AT zoho.com

10 years agoupstream commit
djm@openbsd.org [Tue, 9 Sep 2014 09:45:36 +0000 (09:45 +0000)] 
upstream commit

mention permissions on tun(4) devices in PermitTunnel
 documentation; bz#2273

10 years agoupstream commit
djm@openbsd.org [Wed, 3 Sep 2014 18:55:07 +0000 (18:55 +0000)] 
upstream commit

tighten permissions on pty when the "tty" group does
 not exist; pointed out by Corinna Vinschen; ok markus

10 years agoupstream commit
sobrado@openbsd.org [Sat, 30 Aug 2014 16:32:25 +0000 (16:32 +0000)] 
upstream commit

typo.

10 years agoupstream commit
sobrado@openbsd.org [Sat, 30 Aug 2014 15:33:50 +0000 (15:33 +0000)] 
upstream commit

improve capitalization for the Ed25519 public-key
 signature system.

ok djm@

10 years agoupstream commit
doug@openbsd.org [Thu, 21 Aug 2014 01:08:52 +0000 (01:08 +0000)] 
upstream commit

Free resources on error in mkstemp and fdopen

ok djm@

10 years agoupstream commit
deraadt@openbsd.org [Wed, 20 Aug 2014 01:28:55 +0000 (01:28 +0000)] 
upstream commit

djm how did you make a typo like that...

10 years agoupstream commit
djm@openbsd.org [Tue, 19 Aug 2014 23:58:28 +0000 (23:58 +0000)] 
upstream commit

When dumping the server configuration (sshd -T), print
 correct KEX, MAC and cipher defaults. Spotted by Iain Morgan

10 years agoupstream commit
djm@openbsd.org [Tue, 19 Aug 2014 23:57:18 +0000 (23:57 +0000)] 
upstream commit

~-expand lcd paths

10 years agoremove duplicated KEX_DH1 entry
Damien Miller [Sun, 12 Oct 2014 01:35:48 +0000 (12:35 +1100)] 
remove duplicated KEX_DH1 entry

10 years agoremove ChangeLog file
Damien Miller [Wed, 8 Oct 2014 23:34:06 +0000 (10:34 +1100)] 
remove ChangeLog file

Commit logs will be generated from git at release time.

10 years agodelete contrib/caldera directory
Damien Miller [Tue, 7 Oct 2014 10:24:25 +0000 (21:24 +1100)] 
delete contrib/caldera directory

10 years agotest commit
Damien Miller [Tue, 7 Oct 2014 08:57:27 +0000 (19:57 +1100)] 
test commit

10 years ago - (djm) Release OpenSSH-6.7
Damien Miller [Mon, 6 Oct 2014 22:21:49 +0000 (09:21 +1100)] 
 - (djm) Release OpenSSH-6.7

10 years ago - (djm) [sshd_config.5] typo; from Iain Morgan
Damien Miller [Thu, 2 Oct 2014 23:24:56 +0000 (09:24 +1000)] 
 - (djm) [sshd_config.5] typo; from Iain Morgan

10 years ago - (djm) [openbsd-compat/Makefile.in openbsd-compat/kludge-fd_set.c]
Damien Miller [Tue, 30 Sep 2014 23:43:07 +0000 (09:43 +1000)] 
 - (djm) [openbsd-compat/Makefile.in openbsd-compat/kludge-fd_set.c]
   [openbsd-compat/openbsd-compat.h] Kludge around bad glibc
   _FORTIFY_SOURCE check that doesn't grok heap-allocated fd_sets;
   ok dtucker@

11 years ago - (djm) [sandbox-seccomp-filter.c] Allow mremap and exit for DietLibc;
Damien Miller [Tue, 9 Sep 2014 22:15:34 +0000 (08:15 +1000)] 
 - (djm) [sandbox-seccomp-filter.c] Allow mremap and exit for DietLibc;
   patch from Felix von Leitner; ok dtucker

11 years ago20140908
Darren Tucker [Tue, 9 Sep 2014 02:23:10 +0000 (12:23 +1000)] 
20140908
 - (dtucker) [INSTALL] Update info about egd.  ok djm@

11 years ago - (djm) [openbsd-compat/arc4random.c] Zero seed after keying PRNG
Damien Miller [Wed, 3 Sep 2014 17:46:05 +0000 (03:46 +1000)] 
 - (djm) [openbsd-compat/arc4random.c] Zero seed after keying PRNG

11 years ago - (djm) [contrib/cygwin/ssh-host-config] Fix old code leading to
Damien Miller [Tue, 2 Sep 2014 19:35:32 +0000 (05:35 +1000)] 
 - (djm) [contrib/cygwin/ssh-host-config] Fix old code leading to
   permissions/ACLs; from Corinna Vinschen

11 years ago - (djm) [defines.h sshbuf.c] Move __predict_true|false to defines.h and
Damien Miller [Tue, 2 Sep 2014 19:33:25 +0000 (05:33 +1000)] 
 - (djm) [defines.h sshbuf.c] Move __predict_true|false to defines.h and
   conditionalise to avoid duplicate definition.

11 years ago - (djm) [Makefile.in] Make TEST_SHELL a variable; "good idea" tim@
Damien Miller [Sat, 30 Aug 2014 06:23:06 +0000 (16:23 +1000)] 
 - (djm) [Makefile.in] Make TEST_SHELL a variable; "good idea" tim@

11 years ago - (djm) [openbsd-compat/openssl-compat.h] add include guard
Damien Miller [Fri, 29 Aug 2014 18:18:28 +0000 (04:18 +1000)] 
 - (djm) [openbsd-compat/openssl-compat.h] add include guard

11 years ago - (djm) [misc.c] Missing newline between functions
Damien Miller [Fri, 29 Aug 2014 17:29:19 +0000 (03:29 +1000)] 
 - (djm) [misc.c] Missing newline between functions

11 years ago - (djm) [openbsd-compat/openssl-compat.h] add
Damien Miller [Fri, 29 Aug 2014 16:30:30 +0000 (02:30 +1000)] 
 - (djm) [openbsd-compat/openssl-compat.h] add
   OPENSSL_[RD]SA_MAX_MODULUS_BITS defines for OpenSSL that lacks them

11 years ago - (djm) [openbsd-compat/explicit_bzero.c] implement explicit_bzero()
Damien Miller [Tue, 26 Aug 2014 20:32:01 +0000 (06:32 +1000)] 
 - (djm) [openbsd-compat/explicit_bzero.c] implement explicit_bzero()
   using memset_s() where possible; improve fallback to indirect bzero
   via a volatile pointer to give it more of a chance to avoid being
   optimised away.

11 years ago - (djm) [monitor.c sshd.c] SIGXFSZ needs to be ignored in postauth
Damien Miller [Tue, 26 Aug 2014 18:11:55 +0000 (04:11 +1000)] 
 - (djm) [monitor.c sshd.c] SIGXFSZ needs to be ignored in postauth
   monitor, not preauth; bz#2263

11 years ago - (djm) [regress/unittests/sshbuf/test_sshbuf_getput_crypto.c]
Damien Miller [Tue, 26 Aug 2014 18:04:40 +0000 (04:04 +1000)] 
 - (djm) [regress/unittests/sshbuf/test_sshbuf_getput_crypto.c]
   [regress/unittests/sshbuf/test_sshbuf_getput_fuzz.c]
   [regress/unittests/sshkey/common.c]
   [regress/unittests/sshkey/test_file.c]
   [regress/unittests/sshkey/test_fuzz.c]
   [regress/unittests/sshkey/test_sshkey.c] Don't include openssl/ec.h
   on !ECC OpenSSL systems

11 years ago - (djm) [INSTALL] Recommend libcrypto be built -fPIC, mention LibreSSL,
Damien Miller [Mon, 25 Aug 2014 23:27:28 +0000 (09:27 +1000)] 
 - (djm) [INSTALL] Recommend libcrypto be built -fPIC, mention LibreSSL,
   update OpenSSL version requirement.

11 years ago - (djm) [bufec.c] Skip this file on !ECC OpenSSL
Damien Miller [Mon, 25 Aug 2014 22:37:47 +0000 (08:37 +1000)] 
 - (djm) [bufec.c] Skip this file on !ECC OpenSSL

11 years ago - (djm) [sftp-server.c] Some systems (e.g. Irix) have prctl() but not
Damien Miller [Sat, 23 Aug 2014 17:01:06 +0000 (03:01 +1000)] 
 - (djm) [sftp-server.c] Some systems (e.g. Irix) have prctl() but not
   PR_SET_DUMPABLE, so adjust ifdef; reported by Tom Christensen

11 years ago - (djm) [configure.ac] We now require a working vsnprintf everywhere (not
Damien Miller [Sat, 23 Aug 2014 07:06:49 +0000 (17:06 +1000)] 
 - (djm) [configure.ac] We now require a working vsnprintf everywhere (not
   just for systems that lack asprintf); check for it always and extend
   test to catch more brokenness. Fixes builds on Solaris <= 9

11 years ago - (djm) [sshd.c] Ignore SIGXFSZ in preauth monitor child; can explode on
Damien Miller [Fri, 22 Aug 2014 17:11:09 +0000 (03:11 +1000)] 
 - (djm) [sshd.c] Ignore SIGXFSZ in preauth monitor child; can explode on
   lastlog writing on platforms with high UIDs; bz#2263

11 years ago - (djm) [configure.ac] double braces to appease autoconf
Damien Miller [Fri, 22 Aug 2014 08:06:20 +0000 (18:06 +1000)] 
 - (djm) [configure.ac] double braces to appease autoconf

11 years ago - (djm) [openbsd-compat/bsd-snprintf.c] Fix compilation failure (prototype/
Damien Miller [Fri, 22 Aug 2014 07:48:27 +0000 (17:48 +1000)] 
 - (djm) [openbsd-compat/bsd-snprintf.c] Fix compilation failure (prototype/
   definition mismatch) and warning for broken/missing snprintf case.

11 years ago - (djm) [sshbuf-getput-crypto.c] Fix compilation when OpenSSL lacks ECC
Damien Miller [Fri, 22 Aug 2014 07:36:56 +0000 (17:36 +1000)] 
 - (djm) [sshbuf-getput-crypto.c] Fix compilation when OpenSSL lacks ECC

11 years ago - (djm) [configure.ac] include leading zero characters in OpenSSL version
Damien Miller [Fri, 22 Aug 2014 07:36:19 +0000 (17:36 +1000)] 
 - (djm) [configure.ac] include leading zero characters in OpenSSL version
   number; fixes test for unsupported versions

11 years ago - (djm) [regress/unittests/test_helper/test_helper.c] Fix for systems that
Damien Miller [Thu, 21 Aug 2014 05:54:50 +0000 (15:54 +1000)] 
 - (djm) [regress/unittests/test_helper/test_helper.c] Fix for systems that
   don't set __progname. Diagnosed by Tom Christensen.

11 years ago - (djm) [key.h] Fix ifdefs for no-ECC OpenSSL
Damien Miller [Thu, 21 Aug 2014 00:48:41 +0000 (10:48 +1000)] 
 - (djm) [key.h] Fix ifdefs for no-ECC OpenSSL

11 years ago - (djm) [Makefile.in] fix reference to libtest_helper.a in sshkey test too.
Damien Miller [Thu, 21 Aug 2014 00:47:54 +0000 (10:47 +1000)] 
 - (djm) [Makefile.in] fix reference to libtest_helper.a in sshkey test too.

11 years ago - (djm) [contrib/cygwin/README] Correct build instructions; from Corinna
Damien Miller [Wed, 20 Aug 2014 01:10:51 +0000 (11:10 +1000)] 
 - (djm) [contrib/cygwin/README] Correct build instructions; from Corinna

11 years ago - (djm) [sshkey.h] Fix compilation when OpenSSL lacks ECC
Damien Miller [Wed, 20 Aug 2014 01:06:50 +0000 (11:06 +1000)] 
 - (djm) [sshkey.h] Fix compilation when OpenSSL lacks ECC

11 years ago - (djm) [Makefile.in] refer to libtest_helper.a by explicit path rather than
Damien Miller [Wed, 20 Aug 2014 01:06:20 +0000 (11:06 +1000)] 
 - (djm) [Makefile.in] refer to libtest_helper.a by explicit path rather than
   -L/-l; fixes linking problems on some platforms

11 years ago - (djm) [configure.ac] Check OpenSSL version is supported at configure time;
Damien Miller [Wed, 20 Aug 2014 01:05:03 +0000 (11:05 +1000)] 
 - (djm) [configure.ac] Check OpenSSL version is supported at configure time;
   suggested by Kevin Brott

11 years ago - (djm) [INSTALL contrib/caldera/openssh.spec contrib/cygwin/README]
Damien Miller [Tue, 19 Aug 2014 01:36:07 +0000 (11:36 +1000)] 
 - (djm) [INSTALL contrib/caldera/openssh.spec contrib/cygwin/README]
   [contrib/redhat/openssh.spec contrib/suse/openssh.spec] Remove mentions
   of TCP wrappers.

11 years ago - (djm) [ssh-dss.c] Include openssl/dsa.h for DSA_SIG
Damien Miller [Tue, 19 Aug 2014 01:32:34 +0000 (11:32 +1000)] 
 - (djm) [ssh-dss.c] Include openssl/dsa.h for DSA_SIG

11 years ago - (djm) [sshbuf.h] Fix compilation on systems without OPENSSL_HAS_ECC.
Damien Miller [Tue, 19 Aug 2014 01:28:11 +0000 (11:28 +1000)] 
 - (djm) [sshbuf.h] Fix compilation on systems without OPENSSL_HAS_ECC.

11 years ago - (djm) [myproposal.h] Make curve25519 KEX dependent on
Damien Miller [Tue, 19 Aug 2014 01:14:36 +0000 (11:14 +1000)] 
 - (djm) [myproposal.h] Make curve25519 KEX dependent on
   HAVE_EVP_SHA256 instead of OPENSSL_HAS_ECC.

11 years ago - (djm) [serverloop.c] Fix syntax error on Cygwin; from Corinna Vinschen
Damien Miller [Tue, 19 Aug 2014 01:14:17 +0000 (11:14 +1000)] 
 - (djm) [serverloop.c] Fix syntax error on Cygwin; from Corinna Vinschen

11 years ago - (djm) [README contrib/caldera/openssh.spec]
Damien Miller [Sun, 10 Aug 2014 01:35:05 +0000 (11:35 +1000)] 
 - (djm) [README contrib/caldera/openssh.spec]
   [contrib/redhat/openssh.spec contrib/suse/openssh.spec] Update versions

11 years ago - (djm) [regress/multiplex.sh] Use -d (detach stdin) flag to disassociate
Damien Miller [Fri, 1 Aug 2014 03:31:52 +0000 (13:31 +1000)] 
 - (djm) [regress/multiplex.sh] Use -d (detach stdin) flag to disassociate
   nc from stdin, it's more portable

11 years ago - (djm) [regress/multiplex.sh] Instruct nc not to quit as soon as stdin
Damien Miller [Fri, 1 Aug 2014 02:28:31 +0000 (12:28 +1000)] 
 - (djm) [regress/multiplex.sh] Instruct nc not to quit as soon as stdin
   is closed; avoid regress failures when stdin is /dev/null

11 years ago - (djm) [regress/multiplex.sh] Skip test for non-OpenBSD netcat. We need
Damien Miller [Fri, 1 Aug 2014 02:26:49 +0000 (12:26 +1000)] 
 - (djm) [regress/multiplex.sh] Skip test for non-OpenBSD netcat. We need
   a better solution, but this will have to do for now.

11 years ago - schwarze@cvs.openbsd.org 2014/07/28 15:40:08
Damien Miller [Wed, 30 Jul 2014 02:33:20 +0000 (12:33 +1000)] 
   - schwarze@cvs.openbsd.org 2014/07/28 15:40:08
     [sftp-server.8 sshd_config.5]
     some systems no longer need /dev/log;
     issue noticed by jirib;
     ok deraadt

11 years ago - dtucker@cvs.openbsd.org 2014/07/25 21:22:03
Damien Miller [Wed, 30 Jul 2014 02:32:46 +0000 (12:32 +1000)] 
   - dtucker@cvs.openbsd.org 2014/07/25 21:22:03
     [ssh-agent.c]
     Clear buffer used for handling messages.  This prevents keys being
     left in memory after they have been expired or deleted in some cases
     (but note that ssh-agent is setgid so you would still need root to
     access them).  Pointed out by Kevin Burns, ok deraadt

11 years ago - OpenBSD CVS Sync
Damien Miller [Wed, 30 Jul 2014 02:32:28 +0000 (12:32 +1000)] 
 - OpenBSD CVS Sync
   - millert@cvs.openbsd.org 2014/07/24 22:57:10
     [ssh.1]
     Mention UNIX-domain socket forwarding too.  OK jmc@ deraadt@

11 years ago - (djm) [regress/multiplex.sh] restore incorrectly deleted line;
Damien Miller [Thu, 24 Jul 2014 22:11:30 +0000 (08:11 +1000)] 
 - (djm) [regress/multiplex.sh] restore incorrectly deleted line;
   pointed out by Christian Hesse

11 years ago - dtucker@cvs.openbsd.org 2014/07/22 23:35:38
Darren Tucker [Wed, 23 Jul 2014 00:41:21 +0000 (10:41 +1000)] 
   - dtucker@cvs.openbsd.org 2014/07/22 23:35:38
     [regress/unittests/sshkey/testdata/*]
     Regenerate test keys with certs signed with ed25519 instead of ecdsa.
     These can be used in -portable on platforms that don't support ECDSA.

11 years ago - dtucker@cvs.openbsd.org 2014/07/22 23:57:40
Darren Tucker [Wed, 23 Jul 2014 00:35:45 +0000 (10:35 +1000)] 
   - dtucker@cvs.openbsd.org 2014/07/22 23:57:40
     [regress/unittests/sshkey/mktestdata.sh]
     Add $OpenBSD tag to make syncs easier

11 years ago - dtucker@cvs.openbsd.org 2014/07/22 23:23:22
Darren Tucker [Wed, 23 Jul 2014 00:34:26 +0000 (10:34 +1000)] 
   - dtucker@cvs.openbsd.org 2014/07/22 23:23:22
     [regress/unittests/sshkey/mktestdata.sh]
     Sign test certs with ed25519 instead of ecdsa so that they'll work in
     -portable on platforms that don't have ECDSA in their OpenSSL.  ok djm

11 years ago - djm@cvs.openbsd.org 2014/07/22 01:32:12
Darren Tucker [Wed, 23 Jul 2014 00:04:02 +0000 (10:04 +1000)] 
   - djm@cvs.openbsd.org 2014/07/22 01:32:12
     [regress/multiplex.sh]
     change the test for still-open Unix domain sockets to be robust against
     nc implementations that produce error messages. from -portable
     (Id sync only)

11 years ago - guenther@cvs.openbsd.org 2014/07/22 07:13:42
Darren Tucker [Tue, 22 Jul 2014 23:43:42 +0000 (09:43 +1000)] 
   - guenther@cvs.openbsd.org 2014/07/22 07:13:42
     [umac.c]
     Convert from <sys/endian.h> to the shiney new <endian.h>
     ok dtucker@, who also confirmed that -portable handles this already
     (ID sync only, includes.h pulls in endian.h if available.)

11 years ago - dtucker@cvs.openbsd.org 2014/07/22 01:18:50
Darren Tucker [Tue, 22 Jul 2014 23:40:46 +0000 (09:40 +1000)] 
   - dtucker@cvs.openbsd.org 2014/07/22 01:18:50
     [key.c]
     Prevent spam from key_load_private_pem during hostbased auth.  ok djm@

11 years ago - (dtucker) [regress/unittests/sshkey/test_{file,fuzz,sshkey}.c] Wrap ecdsa-
Darren Tucker [Tue, 22 Jul 2014 18:27:50 +0000 (04:27 +1000)] 
 - (dtucker) [regress/unittests/sshkey/test_{file,fuzz,sshkey}.c] Wrap ecdsa-
   specific tests inside OPENSSL_HAS_ECC.

11 years ago - (djm) [regress/multiplex.sh] change the test for still-open Unix
Damien Miller [Tue, 22 Jul 2014 01:31:47 +0000 (11:31 +1000)] 
 - (djm) [regress/multiplex.sh] change the test for still-open Unix
    domain sockets to be robust against nc implementations that produce
    error messages.

11 years ago - (djm) [regress/multiplex.sh] ssh mux master lost -N somehow;
Damien Miller [Mon, 21 Jul 2014 23:39:19 +0000 (09:39 +1000)] 
 - (djm) [regress/multiplex.sh] ssh mux master lost -N somehow;
   put it back

11 years ago - (dtucker) [sshkey.c] ifdef out unused variable when compiling without
Darren Tucker [Mon, 21 Jul 2014 15:07:11 +0000 (01:07 +1000)] 
 - (dtucker) [sshkey.c] ifdef out unused variable when compiling without
   OPENSSL_HAS_ECC.

11 years ago - (djm) [regress/multiplex.sh] Not all netcat accept the -N option.
Damien Miller [Mon, 21 Jul 2014 00:23:27 +0000 (10:23 +1000)] 
 - (djm) [regress/multiplex.sh] Not all netcat accept the -N option.

11 years ago - millert@cvs.openbsd.org 2014/07/15 15:54:15
Damien Miller [Sun, 20 Jul 2014 23:52:54 +0000 (09:52 +1000)] 
   - millert@cvs.openbsd.org 2014/07/15 15:54:15
     [forwarding.sh multiplex.sh]
     Add support for Unix domain socket forwarding.  A remote TCP port
     may be forwarded to a local Unix domain socket and vice versa or
     both ends may be a Unix domain socket.  This is a reimplementation
     of the streamlocal patches by William Ahern from:
         http://www.25thandclement.com/~william/projects/streamlocal.html
     OK djm@ markus@

11 years ago - (dtucker) [regress/unittests/sshkey/
Darren Tucker [Sun, 20 Jul 2014 20:30:25 +0000 (06:30 +1000)] 
 - (dtucker) [regress/unittests/sshkey/
   {common,test_file,test_fuzz,test_sshkey}.c] Wrap stdint.h includes in
   ifdefs.

11 years ago- (dtucker) [cipher.c openbsd-compat/openssl-compat.h] Restore the bits
Darren Tucker [Sun, 20 Jul 2014 16:24:59 +0000 (02:24 +1000)] 
- (dtucker) [cipher.c openbsd-compat/openssl-compat.h] Restore the bits
   needed to build AES CTR mode against OpenSSL 0.9.8f and above.  ok djm

11 years ago - (tim) [openbsd-compat/port-uw.c] Include misc.h for fwd_opts, used
Tim Rice [Sat, 19 Jul 2014 03:00:11 +0000 (20:00 -0700)] 
 - (tim) [openbsd-compat/port-uw.c] Include misc.h for fwd_opts, used
   in servconf.h.

11 years ago - (dtucker) [key.c sshkey.c] Put new ecdsa bits inside ifdef OPENSSL_HAS_ECC.
Darren Tucker [Fri, 18 Jul 2014 21:23:55 +0000 (07:23 +1000)] 
 - (dtucker) [key.c sshkey.c] Put new ecdsa bits inside ifdef OPENSSL_HAS_ECC.

11 years ago - (dtucker) [Makefile.in] Add a t-exec target to run just the executable
Darren Tucker [Fri, 18 Jul 2014 20:33:12 +0000 (06:33 +1000)] 
 - (dtucker) [Makefile.in] Add a t-exec target to run just the executable
   tests.

11 years ago - (dtucker) [auth2-gss.c gss-serv-krb5.c] Include misc.h for fwd_opts, used
Darren Tucker [Fri, 18 Jul 2014 20:23:18 +0000 (06:23 +1000)] 
 - (dtucker) [auth2-gss.c gss-serv-krb5.c] Include misc.h for fwd_opts, used
   in servconf.h.

11 years ago - djm@cvs.openbsd.org 2014/07/18 02:46:01
Damien Miller [Fri, 18 Jul 2014 05:04:47 +0000 (15:04 +1000)] 
   - djm@cvs.openbsd.org 2014/07/18 02:46:01
     [ssh-agent.c]
     restore umask around listener socket creation (dropped in streamlocal patch
     merge)

11 years ago - djm@cvs.openbsd.org 2014/07/17 07:22:19
Damien Miller [Fri, 18 Jul 2014 05:04:10 +0000 (15:04 +1000)] 
   - djm@cvs.openbsd.org 2014/07/17 07:22:19
     [mux.c ssh.c]
     reflect stdio-forward ("ssh -W host:port ...") failures in exit status.
     previously we were always returning 0. bz#2255 reported by Brendan
     Germain; ok dtucker

11 years ago - djm@cvs.openbsd.org 2014/07/17 00:12:03
Damien Miller [Fri, 18 Jul 2014 05:03:49 +0000 (15:03 +1000)] 
   - djm@cvs.openbsd.org 2014/07/17 00:12:03
     [key.c]
     silence "incorrect passphrase" error spam; reported and ok dtucker@

11 years ago - djm@cvs.openbsd.org 2014/07/17 00:10:18
Damien Miller [Fri, 18 Jul 2014 05:03:27 +0000 (15:03 +1000)] 
   - djm@cvs.openbsd.org 2014/07/17 00:10:18
     [mux.c]
     preserve errno across syscall

11 years ago - djm@cvs.openbsd.org 2014/07/17 00:10:56
Damien Miller [Fri, 18 Jul 2014 05:03:02 +0000 (15:03 +1000)] 
   - djm@cvs.openbsd.org 2014/07/17 00:10:56
     [sandbox-systrace.c]
     ifdef SYS_sendsyslog so this will compile without patching on -stable

11 years ago - jmc@cvs.openbsd.org 2014/07/16 14:48:57
Damien Miller [Fri, 18 Jul 2014 05:02:06 +0000 (15:02 +1000)] 
   - jmc@cvs.openbsd.org 2014/07/16 14:48:57
     [ssh.1]
     add the streamlocal* options to ssh's -o list; millert says they're
     irrelevant for scp/sftp;

     ok markus millert

11 years ago - millert@cvs.openbsd.org 2014/07/15 15:54:14
Damien Miller [Fri, 18 Jul 2014 04:11:24 +0000 (14:11 +1000)] 
   - millert@cvs.openbsd.org 2014/07/15 15:54:14
     [PROTOCOL auth-options.c auth-passwd.c auth-rh-rsa.c auth-rhosts.c]
     [auth-rsa.c auth.c auth1.c auth2-hostbased.c auth2-kbdint.c auth2-none.c]
     [auth2-passwd.c auth2-pubkey.c auth2.c canohost.c channels.c channels.h]
     [clientloop.c misc.c misc.h monitor.c mux.c packet.c readconf.c]
     [readconf.h servconf.c servconf.h serverloop.c session.c ssh-agent.c]
     [ssh.c ssh_config.5 sshconnect.c sshconnect1.c sshconnect2.c sshd.c]
     [sshd_config.5 sshlogin.c]
     Add support for Unix domain socket forwarding.  A remote TCP port
     may be forwarded to a local Unix domain socket and vice versa or
     both ends may be a Unix domain socket.  This is a reimplementation
     of the streamlocal patches by William Ahern from:
         http://www.25thandclement.com/~william/projects/streamlocal.html
     OK djm@ markus@

11 years ago - tedu@cvs.openbsd.org 2014/07/11 13:54:34
Damien Miller [Wed, 16 Jul 2014 23:52:07 +0000 (09:52 +1000)] 
   - tedu@cvs.openbsd.org 2014/07/11 13:54:34
     [myproposal.h]
     by popular demand, add back hamc-sha1 to server proposal for better compat
     with many clients still in use. ok deraadt

11 years ago - deraadt@cvs.openbsd.org 2014/07/11 08:09:54
Damien Miller [Wed, 16 Jul 2014 23:49:37 +0000 (09:49 +1000)] 
   - deraadt@cvs.openbsd.org 2014/07/11 08:09:54
     [sandbox-systrace.c]
     Permit use of SYS_sendsyslog from inside the sandbox.  Clock is ticking,
     update your kernels and sshd soon.. libc will start using sendsyslog()
     in about 4 days.