]> git.ipfire.org Git - thirdparty/openssh-portable.git/log
thirdparty/openssh-portable.git
13 years ago - djm@cvs.openbsd.org 2011/12/04 23:16:12
Damien Miller [Sun, 18 Dec 2011 23:52:21 +0000 (10:52 +1100)] 
   - djm@cvs.openbsd.org 2011/12/04 23:16:12
     [mux.c]
     revert:
     > revision 1.32
     > date: 2011/12/02 00:41:56;  author: djm;  state: Exp;  lines: +4 -1
     > fix bz#1948: ssh -f doesn't fork for multiplexed connection.
     > ok dtucker@
     it interacts badly with ControlPersist

13 years ago - djm@cvs.openbsd.org 2011/12/02 00:43:57
Damien Miller [Sun, 18 Dec 2011 23:51:39 +0000 (10:51 +1100)] 
   - djm@cvs.openbsd.org 2011/12/02 00:43:57
     [mac.c]
     fix bz#1934: newer OpenSSL versions will require HMAC_CTX_Init before
     HMAC_init (this change in policy seems insane to me)
     ok dtucker@

13 years ago - djm@cvs.openbsd.org 2011/12/02 00:41:56
Damien Miller [Sun, 18 Dec 2011 23:51:11 +0000 (10:51 +1100)] 
   - djm@cvs.openbsd.org 2011/12/02 00:41:56
     [mux.c]
     fix bz#1948: ssh -f doesn't fork for multiplexed connection.
     ok dtucker@

13 years ago - oga@cvs.openbsd.org 2011/11/16 12:24:28
Damien Miller [Fri, 25 Nov 2011 02:53:48 +0000 (13:53 +1100)] 
   - oga@cvs.openbsd.org 2011/11/16 12:24:28
     [sftp.c]
     Don't leak list in complete_cmd_parse if there are no commands found.
     Discovered when I was ``borrowing'' this code for something else.
     ok djm@

13 years ago - (dtucker) [configure.ac] Set _FORTIFY_SOURCE. ok djm@
Darren Tucker [Mon, 21 Nov 2011 05:38:48 +0000 (16:38 +1100)] 
 - (dtucker) [configure.ac] Set _FORTIFY_SOURCE.  ok djm@

13 years ago - (dtucker) [INSTALL LICENCE configure.ac openbsd-compat/Makefile.in
Darren Tucker [Fri, 4 Nov 2011 00:25:24 +0000 (11:25 +1100)] 
 - (dtucker) [INSTALL LICENCE configure.ac openbsd-compat/Makefile.in
   openbsd-compat/getrrsetbyname-ldns.c openbsd-compat/getrrsetbyname.c]
   bz 1320: Add optional support for LDNS, a BSD licensed DNS resolver library
   which supports DNSSEC.  Patch from Simon Vallet (svallet at genoscope cns fr)
   with some rework from myself and djm.  ok djm.

13 years ago - dtucker@cvs.openbsd.org 011/11/04 00:09:39
Darren Tucker [Fri, 4 Nov 2011 00:16:06 +0000 (11:16 +1100)] 
   - dtucker@cvs.openbsd.org 011/11/04 00:09:39
     [moduli]
     regenerated moduli file; ok deraadt

13 years ago - djm@cvs.openbsd.org 2011/10/24 02:13:13
Darren Tucker [Thu, 3 Nov 2011 23:55:24 +0000 (10:55 +1100)] 
   - djm@cvs.openbsd.org 2011/10/24 02:13:13
     [session.c]
     bz#1859: send tty break to pty master instead of (probably already
     closed) slave side; "looks good" markus@

13 years ago - djm@cvs.openbsd.org 2011/10/24 02:10:46
Darren Tucker [Thu, 3 Nov 2011 23:54:22 +0000 (10:54 +1100)] 
   - djm@cvs.openbsd.org 2011/10/24 02:10:46
     [ssh.c]
     bz#1943: unbreak stdio forwarding when ControlPersist is in user - ssh
     was incorrectly requesting the forward in both the control master and
     slave. skip requesting it in the master to fix. ok markus@

13 years ago - djm@cvs.openbsd.org 2011/10/19 10:39:48
Darren Tucker [Thu, 3 Nov 2011 23:53:31 +0000 (10:53 +1100)] 
   - djm@cvs.openbsd.org 2011/10/19 10:39:48
     [umac.c]
     typo in comment; patch from Michael W. Bombardieri

13 years ago - djm@cvs.openbsd.org 2011/10/19 00:06:10
Darren Tucker [Thu, 3 Nov 2011 23:52:43 +0000 (10:52 +1100)] 
   - djm@cvs.openbsd.org 2011/10/19 00:06:10
     [moduli.c]
     s/tmpfile/tmp/ to make this -Wshadow clean

13 years ago - djm@cvs.openbsd.org 2011/10/18 23:37:42
Darren Tucker [Thu, 3 Nov 2011 23:51:51 +0000 (10:51 +1100)] 
   - djm@cvs.openbsd.org 2011/10/18 23:37:42
     [ssh-add.c]
     add -k to usage(); reminded by jmc@

13 years ago - djm@cvs.openbsd.org 2011/10/18 05:15:28
Darren Tucker [Thu, 3 Nov 2011 23:50:40 +0000 (10:50 +1100)] 
   - djm@cvs.openbsd.org 2011/10/18 05:15:28
     [ssh.c]
     ssh(1): skip attempting to create ~/.ssh when -F is passed; ok markus@

13 years ago - (dtucker) [contrib/cygwin/Makefile] Continue if installing a doc file
Darren Tucker [Mon, 24 Oct 2011 22:37:57 +0000 (09:37 +1100)] 
 - (dtucker) [contrib/cygwin/Makefile] Continue if installing a doc file
   fails.  Patch from Corinna Vinschen.

13 years ago - djm@cvs.openbsd.org 2011/10/18 05:00:48
Damien Miller [Tue, 18 Oct 2011 05:06:33 +0000 (16:06 +1100)] 
   - djm@cvs.openbsd.org 2011/10/18 05:00:48
     [ssh-add.1 ssh-add.c]
     new "ssh-add -k" option to load plain keys (skipping certificates);
     "looks ok" markus@

13 years ago - djm@cvs.openbsd.org 2011/10/18 04:58:26
Damien Miller [Tue, 18 Oct 2011 05:06:14 +0000 (16:06 +1100)] 
   - djm@cvs.openbsd.org 2011/10/18 04:58:26
     [auth-options.c key.c]
     remove explict search for \0 in packet strings, this job is now done
     implicitly by buffer_get_cstring; ok markus

13 years ago - stsp@cvs.openbsd.org 2011/10/16 15:51:39
Damien Miller [Tue, 18 Oct 2011 05:05:55 +0000 (16:05 +1100)] 
   - stsp@cvs.openbsd.org 2011/10/16 15:51:39
     [moduli.c]
     add missing includes to unbreak tree; fix from rpointel

13 years ago - jmc@cvs.openbsd.org 2011/10/16 15:02:41
Damien Miller [Tue, 18 Oct 2011 05:05:38 +0000 (16:05 +1100)] 
   - jmc@cvs.openbsd.org 2011/10/16 15:02:41
     [ssh-keygen.c]
     put -K in the right place (usage());

13 years ago - dtucker@cvs.openbsd.org 2011/10/16 11:02:46
Damien Miller [Tue, 18 Oct 2011 05:05:19 +0000 (16:05 +1100)] 
   - dtucker@cvs.openbsd.org 2011/10/16 11:02:46
     [moduli.c ssh-keygen.1 ssh-keygen.c]
     Add optional checkpoints for moduli screening.  feedback & ok deraadt

13 years ago - djm@cvs.openbsd.org 2011/10/04 14:17:32
Damien Miller [Tue, 18 Oct 2011 05:04:57 +0000 (16:04 +1100)] 
   - djm@cvs.openbsd.org 2011/10/04 14:17:32
     [sftp-glob.c]
     silence error spam for "ls */foo" in directory with files; bz#1683

13 years ago - djm@cvs.openbsd.org 2011/09/30 21:22:49
Darren Tucker [Sun, 2 Oct 2011 08:10:13 +0000 (19:10 +1100)] 
   - djm@cvs.openbsd.org 2011/09/30 21:22:49
     [sshd.c]
     fix inverted test that caused logspam; spotted by henning@

13 years agoChangeLog entry for sshd.c rev 1.409
Darren Tucker [Sun, 2 Oct 2011 08:09:07 +0000 (19:09 +1100)] 
ChangeLog entry for sshd.c rev 1.409

13 years ago - djm@cvs.openbsd.org 2011/09/25 05:44:47
Darren Tucker [Sun, 2 Oct 2011 07:59:59 +0000 (18:59 +1100)] 
   - djm@cvs.openbsd.org 2011/09/25 05:44:47
     [auth2-pubkey.c]
     improve the AuthorizedPrincipalsFile debug log message to include
     file and line number

13 years ago - markus@cvs.openbsd.org 2011/09/23 07:45:05
Darren Tucker [Sun, 2 Oct 2011 07:59:03 +0000 (18:59 +1100)] 
   - markus@cvs.openbsd.org 2011/09/23 07:45:05
     [mux.c readconf.h channels.h compat.h compat.c ssh.c readconf.c channels.c     version.h]
     unbreak remote portforwarding with dynamic allocated listen ports:
     1) send the actual listen port in the open message (instead of 0).
        this allows multiple forwardings with a dynamic listen port
     2) update the matching permit-open entry, so we can identify where
        to connect to
     report: den at skbkontur.ru and P. Szczygielski
     feedback and ok djm@

13 years ago - dtucker@cvs.openbsd.org 2011/09/23 00:22:04
Darren Tucker [Sun, 2 Oct 2011 07:57:35 +0000 (18:57 +1100)] 
   - dtucker@cvs.openbsd.org 2011/09/23 00:22:04
     [channels.c auth-options.c servconf.c channels.h sshd.8]
     Add wildcard support to PermitOpen, allowing things like "PermitOpen
     localhost:*".  bz #1857, ok djm markus.

13 years agoremove SELECT_REQUIRED_FDS added erroneously with strnlen. spotted by tim
Darren Tucker [Sun, 2 Oct 2011 07:49:24 +0000 (18:49 +1100)] 
remove SELECT_REQUIRED_FDS added erroneously with strnlen. spotted by tim

13 years ago - (dtucker) [openbsd-compat/mktemp.c] Fix compiler warning. ok djm
Darren Tucker [Sat, 1 Oct 2011 08:46:12 +0000 (18:46 +1000)] 
 - (dtucker) [openbsd-compat/mktemp.c] Fix compiler warning.  ok djm

13 years ago - (dtucker) [configure.ac openbsd-compat/Makefile.in
Darren Tucker [Thu, 29 Sep 2011 13:17:18 +0000 (23:17 +1000)] 
 - (dtucker) [configure.ac openbsd-compat/Makefile.in
   openbsd-compat/strnlen.c] Add strnlen to the compat library.

13 years ago - (djm) [configure.ac defines.h] No need to detect sizeof(char); patch
Damien Miller [Thu, 29 Sep 2011 01:11:51 +0000 (11:11 +1000)] 
 - (djm) [configure.ac defines.h] No need to detect sizeof(char); patch
   from des AT des.no

13 years ago - (djm) [openbsd-compat/setenv.c] Forklift upgrade, including inclusion
Damien Miller [Fri, 23 Sep 2011 01:26:34 +0000 (11:26 +1000)] 
 - (djm) [openbsd-compat/setenv.c] Forklift upgrade, including inclusion
   of static __findenv() function from upstream setenv.c

13 years ago - otto@cvs.openbsd.org 2008/12/09 19:38:38
Damien Miller [Fri, 23 Sep 2011 01:16:09 +0000 (11:16 +1000)] 
   - otto@cvs.openbsd.org 2008/12/09 19:38:38
     [openbsd-compat/inet_ntop.c]
     fix inet_ntop(3) prototype; ok millert@ libc to be bumbed very soon

13 years ago - (djm) [openbsd-compat/sha2.c openbsd-compat/sha2.h] Remove OpenBSD rcsid
Damien Miller [Fri, 23 Sep 2011 01:13:00 +0000 (11:13 +1000)] 
 - (djm) [openbsd-compat/sha2.c openbsd-compat/sha2.h] Remove OpenBSD rcsid
   marker. The upstream API has changed (function and structure names)
   enough to put it out of sync with other providers of this interface.

13 years ago - (djm) [openbsd-compat/mktemp.c] forklift upgrade to -current version.
Damien Miller [Fri, 23 Sep 2011 00:56:29 +0000 (10:56 +1000)] 
 - (djm) [openbsd-compat/mktemp.c] forklift upgrade to -current version.
   The file was totally rewritten between what we had in tree and -current.

13 years ago - millert@cvs.openbsd.org 2008/08/21 16:54:44
Damien Miller [Fri, 23 Sep 2011 00:47:29 +0000 (10:47 +1000)] 
   - millert@cvs.openbsd.org 2008/08/21 16:54:44
     [mktemp.c]
     Remove useless code, the kernel will set errno appropriately if an
     element in the path does not exist.  OK deraadt@ pvalchev@

13 years ago - deraadt@cvs.openbsd.org 2008/07/22 21:47:45
Damien Miller [Fri, 23 Sep 2011 00:46:48 +0000 (10:46 +1000)] 
   - deraadt@cvs.openbsd.org 2008/07/22 21:47:45
     [mktemp.c]
     use arc4random_uniform(); ok djm millert

13 years ago - (djm) [openbsd-compat/getgrouplist.c] Remove OpenBSD rcsid marker: the
Damien Miller [Fri, 23 Sep 2011 00:44:03 +0000 (10:44 +1000)] 
 - (djm) [openbsd-compat/getgrouplist.c] Remove OpenBSD rcsid marker: the
   upstream version is YPified and we don't want this

13 years ago - tobias@cvs.openbsd.org 2007/10/21 11:09:30
Damien Miller [Fri, 23 Sep 2011 00:42:02 +0000 (10:42 +1000)] 
   - tobias@cvs.openbsd.org 2007/10/21 11:09:30
     [mktemp.c]
     Comment fix about time consumption of _gettemp.
     FreeBSD did this in revision 1.20.
     OK deraadt@, krw@

13 years ago - (djm) [openbsd-compat/getcwd.c] Remove OpenBSD rcsid marker since we no
Damien Miller [Fri, 23 Sep 2011 00:40:50 +0000 (10:40 +1000)] 
 - (djm) [openbsd-compat/getcwd.c] Remove OpenBSD rcsid marker since we no
   longer want to sync this file (OpenBSD uses a __getcwd syscall now, we
   want this longhand version)

13 years ago - millert@cvs.openbsd.org 2006/05/05 15:27:38
Damien Miller [Fri, 23 Sep 2011 00:38:11 +0000 (10:38 +1000)] 
   - millert@cvs.openbsd.org 2006/05/05 15:27:38
     [openbsd-compat/strlcpy.c]
     Convert do {} while loop -> while {} for clarity.  No binary change
     on most architectures.  From Oliver Smith.  OK deraadt@ and henning@

13 years ago - millert@cvs.openbsd.org 2006/05/05 15:27:38
Damien Miller [Fri, 23 Sep 2011 00:38:01 +0000 (10:38 +1000)] 
   - millert@cvs.openbsd.org 2006/05/05 15:27:38
     [strlcpy.c]
     Convert do {} while loop -> while {} for clarity.  No binary change
     on most architectures.  From Oliver Smith.  OK deraadt@ and henning@

13 years ago - djm@cvs.openbsd.org 2011/09/22 06:29:03
Damien Miller [Thu, 22 Sep 2011 11:43:06 +0000 (21:43 +1000)] 
   - djm@cvs.openbsd.org 2011/09/22 06:29:03
     [sftp.c]
     don't let remote_glob() implicitly sort its results in do_globbed_ls() -
     in all likelihood, they will be resorted anyway

13 years ago - markus@cvs.openbsd.org 2011/09/12 08:46:15
Damien Miller [Thu, 22 Sep 2011 11:42:45 +0000 (21:42 +1000)] 
   - markus@cvs.openbsd.org 2011/09/12 08:46:15
     [sftp-client.c]
     fix leak in do_lsreaddir(); ok djm

13 years ago - markus@cvs.openbsd.org 2011/09/11 16:07:26
Damien Miller [Thu, 22 Sep 2011 11:41:05 +0000 (21:41 +1000)] 
   - markus@cvs.openbsd.org 2011/09/11 16:07:26
     [sftp-client.c]
     fix leaks in do_hardlink() and do_readlink(); bz#1921
     from Loganaden Velvindron

13 years ago - okan@cvs.openbsd.org 2011/09/11 06:59:05
Damien Miller [Thu, 22 Sep 2011 11:40:45 +0000 (21:40 +1000)] 
   - okan@cvs.openbsd.org 2011/09/11 06:59:05
     [ssh.1]
     document new -O cancel command; ok djm@

13 years ago - markus@cvs.openbsd.org 2011/09/10 22:26:34
Damien Miller [Thu, 22 Sep 2011 11:39:48 +0000 (21:39 +1000)] 
   - markus@cvs.openbsd.org 2011/09/10 22:26:34
     [channels.c channels.h clientloop.c ssh.1]
     support cancellation of local/dynamic forwardings from ~C commandline;
     ok & feedback djm@

13 years ago - djm@cvs.openbsd.org 2011/09/09 22:46:44
Damien Miller [Thu, 22 Sep 2011 11:38:52 +0000 (21:38 +1000)] 
   - djm@cvs.openbsd.org 2011/09/09 22:46:44
     [channels.c channels.h clientloop.h mux.c ssh.c]
     support for cancelling local and remote port forwards via the multiplex
     socket. Use ssh -O cancel -L xx:xx:xx -R yy:yy:yy user@host" to request
     the cancellation of the specified forwardings; ok markus@

13 years ago - djm@cvs.openbsd.org 2011/09/09 22:38:21
Damien Miller [Thu, 22 Sep 2011 11:38:30 +0000 (21:38 +1000)] 
   - djm@cvs.openbsd.org 2011/09/09 22:38:21
     [sshd.c]
     kill the preauth privsep child on fatal errors in the monitor;
     ok markus@

13 years ago - djm@cvs.openbsd.org 2011/09/09 22:37:01
Damien Miller [Thu, 22 Sep 2011 11:38:00 +0000 (21:38 +1000)] 
   - djm@cvs.openbsd.org 2011/09/09 22:37:01
     [scp.c]
     suppress adding '--' to remote commandlines when the first argument
     does not start with '-'. saves breakage on some difficult-to-upgrade
     embedded/router platforms; feedback & ok dtucker ok markus

13 years ago - djm@cvs.openbsd.org 2011/09/09 00:44:07
Damien Miller [Thu, 22 Sep 2011 11:37:38 +0000 (21:37 +1000)] 
   - djm@cvs.openbsd.org 2011/09/09 00:44:07
     [PROTOCOL.mux]
     MUX_C_CLOSE_FWD includes forward type in message (though it isn't
     implemented anyway)

13 years ago - djm@cvs.openbsd.org 2011/09/09 00:43:00
Damien Miller [Thu, 22 Sep 2011 11:37:13 +0000 (21:37 +1000)] 
   - djm@cvs.openbsd.org 2011/09/09 00:43:00
     [ssh_config.5 sshd_config.5]
     fix typo in IPQoS parsing: there is no "AF14" class, but there is
     an "AF21" class. Spotted by giesen AT snickers.org; ok markus stevesk

13 years ago - deraadt@cvs.openbsd.org 2011/09/07 02:18:31
Damien Miller [Thu, 22 Sep 2011 11:36:00 +0000 (21:36 +1000)] 
   - deraadt@cvs.openbsd.org 2011/09/07 02:18:31
     [ssh-keygen.1]
     typo (they vs the) found by Lawrence Teo

13 years ago - jmc@cvs.openbsd.org 2011/09/05 07:01:44
Damien Miller [Thu, 22 Sep 2011 11:34:56 +0000 (21:34 +1000)] 
   - jmc@cvs.openbsd.org 2011/09/05 07:01:44
     [scp.1]
     knock out a useless Ns;

13 years ago - djm@cvs.openbsd.org 2011/09/05 05:59:08
Damien Miller [Thu, 22 Sep 2011 11:34:35 +0000 (21:34 +1000)] 
   - djm@cvs.openbsd.org 2011/09/05 05:59:08
     [misc.c]
     fix typo in IPQoS parsing: there is no "AF14" class, but there is
     an "AF21" class. Spotted by giesen AT snickers.org; ok markus stevesk

13 years ago - djm@cvs.openbsd.org 2011/09/05 05:56:13
Damien Miller [Thu, 22 Sep 2011 11:34:15 +0000 (21:34 +1000)] 
   - djm@cvs.openbsd.org 2011/09/05 05:56:13
     [scp.1 sftp.1]
     mention ControlPersist and KbdInteractiveAuthentication in the -o
     verbiage in these pages too (prompted by jmc@)

13 years ago - djm@cvs.openbsd.org 2011/08/26 01:45:15
Damien Miller [Thu, 22 Sep 2011 11:33:53 +0000 (21:33 +1000)] 
   - djm@cvs.openbsd.org 2011/08/26 01:45:15
     [ssh.1]
     Add some missing ssh_config(5) options that can be used in ssh(1)'s
     -o argument. Patch from duclare AT guu.fi

13 years ago - djm@cvs.openbsd.org 2011/09/22 06:27:29
Damien Miller [Thu, 22 Sep 2011 11:22:21 +0000 (21:22 +1000)] 
   - djm@cvs.openbsd.org 2011/09/22 06:27:29
     [glob.c]
     fix GLOB_KEEPSTAT without GLOB_NOSORT; the implicit sort was being
     applied only to the gl_pathv vector and not the corresponding gl_statv
     array. reported in OpenSSH bz#1935; feedback and okay matthew@

13 years ago - stsp@cvs.openbsd.org 2011/09/20 10:18:46
Damien Miller [Thu, 22 Sep 2011 11:21:48 +0000 (21:21 +1000)] 
   - stsp@cvs.openbsd.org 2011/09/20 10:18:46
     [glob.c]
     In glob(3), limit recursion during matching attempts. Similar to
     fnmatch fix. Also collapse consecutive '*' (from NetBSD).
     ok miod deraadt

13 years ago - pyr@cvs.openbsd.org 2011/05/12 07:15:10
Damien Miller [Thu, 22 Sep 2011 11:20:21 +0000 (21:20 +1000)] 
   - pyr@cvs.openbsd.org 2011/05/12 07:15:10
     [openbsd-compat/glob.c]
     When the max number of items for a directory has reached GLOB_LIMIT_READDIR
     an error is returned but closedir() is not called.
     spotted and fix provided by Frank Denis obsd-tech@pureftpd.org
     ok otto@, millert@

14 years ago - (dtucker) [entropy.h] Bug #1932: remove old definition of init_rng. From
Darren Tucker [Fri, 9 Sep 2011 01:29:40 +0000 (11:29 +1000)] 
 - (dtucker) [entropy.h] Bug #1932: remove old definition of init_rng.  From
   Colin Watson.

14 years ago - (djm) [contrib/redhat/openssh.spec] Correct restorcon => restorecon
Damien Miller [Tue, 6 Sep 2011 23:15:02 +0000 (09:15 +1000)] 
 - (djm) [contrib/redhat/openssh.spec] Correct restorcon => restorecon

14 years ago - (djm) [README version.h] Correct version
Damien Miller [Tue, 6 Sep 2011 23:11:53 +0000 (09:11 +1000)] 
 - (djm) [README version.h] Correct version

14 years ago - (djm) Release OpenSSH-5.9
Damien Miller [Mon, 5 Sep 2011 05:39:20 +0000 (15:39 +1000)] 
 - (djm) Release OpenSSH-5.9

14 years ago - (djm) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec]
Damien Miller [Mon, 5 Sep 2011 00:29:04 +0000 (10:29 +1000)] 
 - (djm) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec]
   [contrib/suse/openssh.spec] Update version numbers.

14 years ago - (dtucker) [ssh-keygen.c ssh-pkcs11.c] Bug #1929: add null implementations
Darren Tucker [Sun, 4 Sep 2011 09:59:26 +0000 (19:59 +1000)] 
 - (dtucker) [ssh-keygen.c ssh-pkcs11.c] Bug #1929: add null implementations
   ofsh-pkcs11.cpkcs_init and pkcs_terminate for building without dlopen support.

14 years ago - (djm) [regress/connect-privsep.sh regress/test-exec.sh] demote fatal
Damien Miller [Sun, 4 Sep 2011 09:04:16 +0000 (19:04 +1000)] 
 - (djm) [regress/connect-privsep.sh regress/test-exec.sh] demote fatal
   regress errors for the sandbox to warnings. ok tim dtucker

14 years ago - (djm) [openbsd-compat/port-linux.c] Suppress logging when attempting
Damien Miller [Mon, 29 Aug 2011 06:09:52 +0000 (16:09 +1000)] 
 - (djm) [openbsd-compat/port-linux.c] Suppress logging when attempting
   to switch SELinux context away from unconfined_t, based on patch from
   Jan Chadima; bz#1919 ok dtucker@

14 years ago - (dtucker) [auth-skey.c] Add log.h to fix build --with-skey.
Darren Tucker [Sat, 27 Aug 2011 18:50:16 +0000 (04:50 +1000)] 
 - (dtucker) [auth-skey.c] Add log.h to fix build --with-skey.

14 years ago - (tim) [configure.ac] Typo in error message spotted by Andy Tsouladze
Tim Rice [Thu, 18 Aug 2011 04:48:22 +0000 (21:48 -0700)] 
 - (tim) [configure.ac] Typo in error message spotted by Andy Tsouladze

14 years ago - (djm) [regress/cipher-speed.sh regress/try-ciphers.sh] disable HMAC-SHA2
Damien Miller [Wed, 17 Aug 2011 02:25:46 +0000 (12:25 +1000)] 
 - (djm) [regress/cipher-speed.sh regress/try-ciphers.sh] disable HMAC-SHA2
   MAC tests for platforms that hack EVP_SHA2 support

14 years ago - djm@cvs.openbsd.org 2011/08/02 01:23:41
Damien Miller [Wed, 17 Aug 2011 02:10:02 +0000 (12:10 +1000)] 
   - djm@cvs.openbsd.org 2011/08/02 01:23:41
     [regress/cipher-speed.sh regress/try-ciphers.sh]
     add SHA256/SHA512 based HMAC modes

14 years ago - markus@cvs.openbsd.org 2011/06/30 22:44:43
Damien Miller [Wed, 17 Aug 2011 02:09:19 +0000 (12:09 +1000)] 
   - markus@cvs.openbsd.org 2011/06/30 22:44:43
     [connect-privsep.sh]
     test with sandbox enabled; ok djm@

14 years ago - dtucker@cvs.openbsd.org 2011/06/03 05:35:10
Damien Miller [Wed, 17 Aug 2011 02:08:15 +0000 (12:08 +1000)] 
   - dtucker@cvs.openbsd.org 2011/06/03 05:35:10
     [regress/cfgmatch.sh]
     use OBJ to find test configs, patch from Tim Rice

14 years ago - (djm) [contrib/ssh-copy-id] Missing backlslash; spotted by
Damien Miller [Wed, 17 Aug 2011 02:01:44 +0000 (12:01 +1000)] 
 - (djm) [contrib/ssh-copy-id] Missing backlslash; spotted by
   bisson AT archlinux.org

14 years ago - (djm) [configure.ac] error out if the host lacks the necessary bits for
Damien Miller [Wed, 17 Aug 2011 01:59:25 +0000 (11:59 +1000)] 
 - (djm) [configure.ac] error out if the host lacks the necessary bits for
   an explicitly requested sandbox type

14 years ago - (djm) [ openbsd-compat/bsd-cygwin_util.c openbsd-compat/bsd-cygwin_util.h]
Damien Miller [Wed, 17 Aug 2011 01:31:07 +0000 (11:31 +1000)] 
 - (djm) [ openbsd-compat/bsd-cygwin_util.c openbsd-compat/bsd-cygwin_util.h]
   binary_pipe is no longer required on Cygwin; patch from Corinna Vinschen

14 years ago - (tim) [mac.c myproposal.h] Wrap SHA256 and SHA512 in ifdefs for
Tim Rice [Wed, 17 Aug 2011 00:29:01 +0000 (17:29 -0700)] 
 - (tim) [mac.c myproposal.h] Wrap SHA256 and SHA512 in ifdefs for
   OpenSSL 0.9.7. ok djm

14 years ago - (djm) [contrib/ssh-copy-id] Fix failure for cases where the path to the
Damien Miller [Fri, 12 Aug 2011 01:22:47 +0000 (11:22 +1000)] 
 - (djm) [contrib/ssh-copy-id] Fix failure for cases where the path to the
   identify file contained whitespace. bz#1828 patch from gwenael.lambrouin
   AT gmail.com; ok dtucker@

14 years ago - (djm) [contrib/redhat/openssh.spec contrib/redhat/sshd.init]
Damien Miller [Fri, 12 Aug 2011 01:02:35 +0000 (11:02 +1000)] 
 - (djm) [contrib/redhat/openssh.spec contrib/redhat/sshd.init]
   [contrib/suse/openssh.spec contrib/suse/rc.sshd] Updated RHEL and SLES
   init scrips from imorgan AT nas.nasa.gov

14 years ago - (dtucker) [openbsd-compat/port-linux.c] Bug 1924: Improve selinux context
Darren Tucker [Fri, 12 Aug 2011 00:12:53 +0000 (10:12 +1000)] 
 - (dtucker) [openbsd-compat/port-linux.c] Bug 1924: Improve selinux context
   change error by reporting old and new context names  Patch from
   jchadima at redhat.

14 years ago - dtucker@cvs.openbsd.org 2011/08/07 12:55:30
Darren Tucker [Sun, 7 Aug 2011 13:12:26 +0000 (23:12 +1000)] 
   - dtucker@cvs.openbsd.org 2011/08/07 12:55:30
     [sftp.1]
     typo, fix from Laurent Gautrot

14 years ago - jmc@cvs.openbsd.org 2010/10/14 20:41:28
Darren Tucker [Sun, 7 Aug 2011 13:10:56 +0000 (23:10 +1000)] 
   - jmc@cvs.openbsd.org 2010/10/14 20:41:28
     [moduli.5]
     probabalistic -> probabilistic; from naddy

14 years ago - sobrado@cvs.openbsd.org 2009/10/28 08:56:54
Darren Tucker [Sun, 7 Aug 2011 13:10:11 +0000 (23:10 +1000)] 
   - sobrado@cvs.openbsd.org 2009/10/28 08:56:54
     [moduli.5]
     "Diffie-Hellman" is the usual spelling for the cryptographic protocol
     first published by Whitfield Diffie and Martin Hellman in 1976.
     ok jmc@

14 years ago - (dtucker) OpenBSD CVS Sync
Darren Tucker [Sun, 7 Aug 2011 13:09:20 +0000 (23:09 +1000)] 
 - (dtucker) OpenBSD CVS Sync
   - jmc@cvs.openbsd.org 2008/06/26 06:59:39
     [moduli.5]
     tweak previous;

14 years ago - djm@cvs.openbsd.org 2011/08/02 23:15:03
Damien Miller [Fri, 5 Aug 2011 20:18:16 +0000 (06:18 +1000)] 
   - djm@cvs.openbsd.org 2011/08/02 23:15:03
     [ssh.c]
     typo in comment

14 years ago - djm@cvs.openbsd.org 2011/08/02 23:13:01
Damien Miller [Fri, 5 Aug 2011 20:17:48 +0000 (06:17 +1000)] 
   - djm@cvs.openbsd.org 2011/08/02 23:13:01
     [version.h]
     crank now, release later

14 years ago - djm@cvs.openbsd.org 2011/08/02 01:22:11
Damien Miller [Fri, 5 Aug 2011 20:17:30 +0000 (06:17 +1000)] 
   - djm@cvs.openbsd.org 2011/08/02 01:22:11
     [mac.c myproposal.h ssh.1 ssh_config.5 sshd.8 sshd_config.5]
     Add new SHA256 and SHA512 based HMAC modes from
     http://www.ietf.org/id/draft-dbider-sha2-mac-for-ssh-02.txt
     Patch from mdb AT juniper.net; feedback and ok markus@

14 years ago - markus@cvs.openbsd.org 2011/08/01 19:18:15
Damien Miller [Fri, 5 Aug 2011 20:16:46 +0000 (06:16 +1000)] 
   - markus@cvs.openbsd.org 2011/08/01 19:18:15
     [gss-serv.c]
     prevent post-auth resource exhaustion (int overflow leading to 4GB malloc);
     report Adam Zabrock; ok djm@, deraadt@

14 years ago - djm@cvs.openbsd.org 2011/07/29 14:42:45
Damien Miller [Fri, 5 Aug 2011 20:16:23 +0000 (06:16 +1000)] 
   - djm@cvs.openbsd.org 2011/07/29 14:42:45
     [sandbox-systrace.c]
     fail open(2) with EPERM rather than SIGKILLing the whole process. libc
     will call open() to do strerror() when NLS is enabled;
     feedback and ok markus@

14 years ago - tedu@cvs.openbsd.org 2011/07/06 18:09:21
Damien Miller [Fri, 5 Aug 2011 20:16:00 +0000 (06:16 +1000)] 
   - tedu@cvs.openbsd.org 2011/07/06 18:09:21
     [authfd.c]
     bzero the agent address.  the kernel was for a while very cranky about
     these things.  evne though that's fixed, always good to initialize
     memory.  ok deraadt djm

14 years ago - djm@cvs.openbsd.org 2011/06/23 23:35:42
Damien Miller [Fri, 5 Aug 2011 20:15:15 +0000 (06:15 +1000)] 
   - djm@cvs.openbsd.org 2011/06/23 23:35:42
     [monitor.c]
     ignore EINTR errors from poll()

14 years ago - (djm) [configure.ac Makefile.in sandbox-darwin.c] Add a sandbox for
Damien Miller [Sun, 26 Jun 2011 21:18:18 +0000 (07:18 +1000)] 
 - (djm) [configure.ac Makefile.in sandbox-darwin.c] Add a sandbox for
   Darwin/OS X using sandbox_init() + setrlimit(); feedback and testing
   markus@

14 years ago - djm@cvs.openbsd.org 2011/06/23 09:34:13
Damien Miller [Thu, 23 Jun 2011 09:45:51 +0000 (19:45 +1000)] 
   - djm@cvs.openbsd.org 2011/06/23 09:34:13
     [sshd.c ssh-sandbox.h sandbox.h sandbox-rlimit.c sandbox-systrace.c]
     [sandbox-null.c]
     rename sandbox.h => ssh-sandbox.h to make things easier for portable

14 years ago - (djm) [sandbox-null.c] Dummy sandbox for platforms that don't support
Damien Miller [Thu, 23 Jun 2011 09:03:18 +0000 (19:03 +1000)] 
 - (djm) [sandbox-null.c] Dummy sandbox for platforms that don't support
   setrlimit(2)

14 years ago - djm@cvs.openbsd.org 2011/06/22 22:08:42
Damien Miller [Wed, 22 Jun 2011 22:31:57 +0000 (08:31 +1000)] 
   - djm@cvs.openbsd.org 2011/06/22 22:08:42
     [channels.c channels.h clientloop.c clientloop.h mux.c ssh.c]
     hook up a channel confirm callback to warn the user then requested X11
     forwarding was refused by the server; ok markus@

14 years ago - djm@cvs.openbsd.org 2011/06/22 21:57:01
Damien Miller [Wed, 22 Jun 2011 22:30:03 +0000 (08:30 +1000)] 
   - djm@cvs.openbsd.org 2011/06/22 21:57:01
     [servconf.c servconf.h sshd.c sshd_config.5 sandbox-rlimit.c]
     [sandbox-systrace.c sandbox.h configure.ac Makefile.in]
     introduce sandboxing of the pre-auth privsep child using systrace(4).

     This introduces a new "UsePrivilegeSeparation=sandbox" option for
     sshd_config that applies mandatory restrictions on the syscalls the
     privsep child can perform. This prevents a compromised privsep child
     from being used to attack other hosts (by opening sockets and proxying)
     or probing local kernel attack surface.

     The sandbox is implemented using systrace(4) in unsupervised "fast-path"
     mode, where a list of permitted syscalls is supplied. Any syscall not
     on the list results in SIGKILL being sent to the privsep child. Note
     that this requires a kernel with the new SYSTR_POLICY_KILL option.

     UsePrivilegeSeparation=sandbox will become the default in the future
     so please start testing it now.

     feedback dtucker@; ok markus@

14 years ago - OpenBSD CVS Sync
Damien Miller [Wed, 22 Jun 2011 22:20:30 +0000 (08:20 +1000)] 
 - OpenBSD CVS Sync
   - djm@cvs.openbsd.org 2011/06/22 21:47:28
     [servconf.c]
     reuse the multistate option arrays to pretty-print options for "sshd -T"

14 years ago - djm@cvs.openbsd.org 2011/06/17 21:57:25
Damien Miller [Mon, 20 Jun 2011 04:43:31 +0000 (14:43 +1000)] 
   - djm@cvs.openbsd.org 2011/06/17 21:57:25
     [clientloop.c]
     setproctitle for a mux master that has been gracefully stopped;
     bz#1911 from Bert.Wesarg AT googlemail.com

14 years ago - djm@cvs.openbsd.org 2011/06/17 21:47:35
Damien Miller [Mon, 20 Jun 2011 04:43:11 +0000 (14:43 +1000)] 
   - djm@cvs.openbsd.org 2011/06/17 21:47:35
     [servconf.c]
     factor out multi-choice option parsing into a parse_multistate label
     and some support structures; ok dtucker@

14 years ago - djm@cvs.openbsd.org 2011/06/17 21:46:16
Damien Miller [Mon, 20 Jun 2011 04:42:51 +0000 (14:42 +1000)] 
   - djm@cvs.openbsd.org 2011/06/17 21:46:16
     [sftp-server.c]
     the protocol version should be unsigned; bz#1913 reported by mb AT
     smartftp.com

14 years ago - djm@cvs.openbsd.org 2011/06/17 21:44:31
Damien Miller [Mon, 20 Jun 2011 04:42:23 +0000 (14:42 +1000)] 
   - djm@cvs.openbsd.org 2011/06/17 21:44:31
     [log.c log.h monitor.c monitor.h monitor_wrap.c monitor_wrap.h sshd.c]
     make the pre-auth privsep slave log via a socketpair shared with the
     monitor rather than /var/empty/dev/log; ok dtucker@ deraadt@ markus@