]> git.ipfire.org Git - thirdparty/openssh-portable.git/log
thirdparty/openssh-portable.git
14 years ago - (djm) [regress/Makefile] use $TEST_SSH_KEYGEN instead of the one in
Damien Miller [Sun, 16 Jan 2011 23:51:40 +0000 (10:51 +1100)] 
 - (djm) [regress/Makefile] use $TEST_SSH_KEYGEN instead of the one in
   $PATH, fix cleanup of droppings; reported by openssh AT
   roumenpetrov.info; ok dtucker@

14 years ago - djm@cvs.openbsd.org 2011/01/16 12:05:59
Damien Miller [Sun, 16 Jan 2011 12:18:33 +0000 (23:18 +1100)] 
   - djm@cvs.openbsd.org 2011/01/16 12:05:59
     [clientloop.c]
     a couple more tweaks to the post-close protocol 1 stderr/stdout flush:
     now that we use atomicio(), convert them from while loops to if statements
     add test and cast to compile cleanly with -Wsigned

14 years ago - djm@cvs.openbsd.org 2011/01/16 11:50:36
Damien Miller [Sun, 16 Jan 2011 12:17:45 +0000 (23:17 +1100)] 
   - djm@cvs.openbsd.org 2011/01/16 11:50:36
     [sshconnect.c]
     reset the SIGPIPE handler when forking to execute child processes;
     ok dtucker@

14 years ago - djm@cvs.openbsd.org 2011/01/16 11:50:05
Damien Miller [Sun, 16 Jan 2011 12:16:53 +0000 (23:16 +1100)] 
   - djm@cvs.openbsd.org 2011/01/16 11:50:05
     [clientloop.c]
     Use atomicio when flushing protocol 1 std{out,err} buffers at
     session close. This was a latent bug exposed by setting a SIGCHLD
     handler and spotted by kevin.brott AT gmail.com; ok dtucker@

14 years ago - (dtucker) [Makefile.in configure.ac regress/kextype.sh] Skip sha256-based
Darren Tucker [Sun, 16 Jan 2011 07:28:09 +0000 (18:28 +1100)] 
 - (dtucker) [Makefile.in configure.ac regress/kextype.sh] Skip sha256-based
   on configurations that don't have it.

14 years agonot February yet...
Darren Tucker [Sun, 16 Jan 2011 07:24:04 +0000 (18:24 +1100)] 
not February yet...

14 years ago - (tim) [regress/cert-hostkey.sh] Add missing TEST_SSH_ECC guard around some
Tim Rice [Fri, 14 Jan 2011 06:36:14 +0000 (22:36 -0800)] 
 - (tim) [regress/cert-hostkey.sh] Add missing TEST_SSH_ECC guard around some
   ecdsa bits.

14 years ago - (tim) [regress/cert-hostkey.sh] Typo. Missing $ on variable name.
Tim Rice [Fri, 14 Jan 2011 06:20:27 +0000 (22:20 -0800)] 
 - (tim) [regress/cert-hostkey.sh] Typo. Missing $ on variable name.

14 years ago - (djm) [Makefile.in] Use shell test to disable ecdsa key generating in
Damien Miller [Fri, 14 Jan 2011 03:47:37 +0000 (14:47 +1100)] 
 - (djm) [Makefile.in] Use shell test to disable ecdsa key generating in
   host-key-force target rather than a substitution that is replaced with a
   comment so that the Makefile.in is still a syntactically valid Makefile
   (useful to run the distprep target)

14 years ago - djm@cvs.openbsd.org 2011/01/13 21:55:25
Damien Miller [Fri, 14 Jan 2011 01:01:50 +0000 (12:01 +1100)] 
   - djm@cvs.openbsd.org 2011/01/13 21:55:25
     [PROTOCOL.mux]
     correct protocol names and add a couple of missing protocol number
     defines; patch from bert.wesarg AT googlemail.com

14 years ago - djm@cvs.openbsd.org 2011/01/13 21:54:53
Damien Miller [Fri, 14 Jan 2011 01:01:29 +0000 (12:01 +1100)] 
   - djm@cvs.openbsd.org 2011/01/13 21:54:53
     [mux.c]
     correct error messages; patch from bert.wesarg AT googlemail.com

14 years ago - (djm) [regress/kextype.sh] Testing diffie-hellman-group-exchange-sha256
Damien Miller [Thu, 13 Jan 2011 11:05:14 +0000 (22:05 +1100)] 
 - (djm) [regress/kextype.sh] Testing diffie-hellman-group-exchange-sha256
   should not depend on ECC support

14 years ago - (djm) [myproposal.h] Fix reversed OPENSSL_VERSION_NUMBER test and bad
Damien Miller [Thu, 13 Jan 2011 11:00:20 +0000 (22:00 +1100)] 
 - (djm) [myproposal.h] Fix reversed OPENSSL_VERSION_NUMBER test and bad
   #define that was causing diffie-hellman-group-exchange-sha256 to be
   incorrectly disabled

14 years ago - (djm) [regress/Makefile] add a few more generated files to the clean
Damien Miller [Thu, 13 Jan 2011 10:08:27 +0000 (21:08 +1100)] 
 - (djm) [regress/Makefile] add a few more generated files to the clean
   target

14 years ago - (djm) [entropy.c] cast OPENSSL_VERSION_NUMBER to u_long to avoid
Damien Miller [Thu, 13 Jan 2011 10:05:27 +0000 (21:05 +1100)] 
 - (djm) [entropy.c] cast OPENSSL_VERSION_NUMBER to u_long to avoid
   gcc warning on platforms where it defaults to int

14 years ago - (tim) [Makefile.in configure.ac opensshd.init.in] Add support for generating
Tim Rice [Thu, 13 Jan 2011 06:35:43 +0000 (22:35 -0800)] 
 - (tim) [Makefile.in configure.ac opensshd.init.in] Add support for generating
   ecdsa keys. ok djm.

14 years ago - (tim) [Makefile.in] test the ECC bits if we have the capability. ok djm
Tim Rice [Thu, 13 Jan 2011 03:06:31 +0000 (19:06 -0800)] 
 - (tim) [Makefile.in] test the ECC bits if we have the capability. ok djm

14 years ago - (djm) [misc.c] include time.h for nanosleep() prototype
Damien Miller [Thu, 13 Jan 2011 01:21:34 +0000 (12:21 +1100)] 
 - (djm) [misc.c] include time.h for nanosleep() prototype

14 years ago - (djm) [configure.ac] Fix broken test for gcc >= 4.4 with per-compiler
Damien Miller [Wed, 12 Jan 2011 05:00:37 +0000 (16:00 +1100)] 
 - (djm) [configure.ac] Fix broken test for gcc >= 4.4 with per-compiler
   flag tests that don't depend on gcc version at all; suggested by and
   ok dtucker@

14 years ago - (djm) [configure.ac] Turn on -Wno-unused-result for gcc >= 4.4 to avoid
Damien Miller [Wed, 12 Jan 2011 02:34:02 +0000 (13:34 +1100)] 
 - (djm) [configure.ac] Turn on -Wno-unused-result for gcc >= 4.4 to avoid
   silly warnings on write() calls we don't care succeed or not.

14 years ago - djm@cvs.openbsd.org 2011/01/12 01:53:14
Damien Miller [Wed, 12 Jan 2011 02:32:03 +0000 (13:32 +1100)] 
   - djm@cvs.openbsd.org 2011/01/12 01:53:14
     avoid some integer overflows mostly with GLOB_APPEND and GLOB_DOOFFS
     and sanity check arguments (these will be unnecessary when we switch
     struct glob members from being type into to size_t in the future);
     "looks ok" tedu@ feedback guenther@

14 years ago - nicm@cvs.openbsd.org 2010/10/08 21:48:42
Damien Miller [Wed, 12 Jan 2011 02:30:18 +0000 (13:30 +1100)] 
   - nicm@cvs.openbsd.org 2010/10/08 21:48:42
     [openbsd-compat/glob.c]
     Extend GLOB_LIMIT to cover readdir and stat and bump the malloc limit
     from ARG_MAX to 64K.
     Fixes glob-using programs (notably ftp) able to be triggered to hit
     resource limits.
     Idea from a similar NetBSD change, original problem reported by jasper@.
     ok millert tedu jasper

14 years ago - djm@cvs.openbsd.org 2011/01/11 06:13:10
Damien Miller [Tue, 11 Jan 2011 06:20:29 +0000 (17:20 +1100)] 
   - djm@cvs.openbsd.org 2011/01/11 06:13:10
     [clientloop.c ssh-keygen.c sshd.c]
     some unsigned long long casts that make things a bit easier for
     portable without resorting to dropping PRIu64 formats everywhere

14 years ago - djm@cvs.openbsd.org 2011/01/11 06:06:09
Damien Miller [Tue, 11 Jan 2011 06:20:05 +0000 (17:20 +1100)] 
   - djm@cvs.openbsd.org 2011/01/11 06:06:09
     [sshlogin.c]
     fd leak on error paths; from zinovik@
     NB. Id sync only; we use loginrec.c that was also audited and fixed
     recently

14 years ago - djm@cvs.openbsd.org 2011/01/08 10:51:51
Damien Miller [Tue, 11 Jan 2011 06:18:56 +0000 (17:18 +1100)] 
   - djm@cvs.openbsd.org 2011/01/08 10:51:51
     [clientloop.c]
     use host and not options.hostname, as the latter may have unescaped
     substitution characters

14 years ago - (djm) [platform.c] Some missing includes that show up under -Werror
Damien Miller [Tue, 11 Jan 2011 06:02:23 +0000 (17:02 +1100)] 
 - (djm) [platform.c] Some missing includes that show up under -Werror

14 years ago - (tim) [regress/host-expand.sh] Fix for building outside of read only
Tim Rice [Mon, 10 Jan 2011 20:56:26 +0000 (12:56 -0800)] 
 - (tim) [regress/host-expand.sh] Fix for building outside of read only
   source tree.

14 years ago - (djm) [Makefile.in] list ssh_host_ecdsa key in PATHSUBS; spotted by
Damien Miller [Sat, 8 Jan 2011 22:19:50 +0000 (09:19 +1100)] 
 - (djm) [Makefile.in] list ssh_host_ecdsa key in PATHSUBS; spotted by
   openssh AT roumenpetrov.info

14 years ago - (djm) [regress/keytype.sh] s/echo -n/echon/ to repair failing regress
Damien Miller [Sat, 8 Jan 2011 10:58:20 +0000 (21:58 +1100)] 
 - (djm) [regress/keytype.sh] s/echo -n/echon/ to repair failing regress
   test on OSX and others. Reported by imorgan AT nas.nasa.gov

14 years ago - djm@cvs.openbsd.org 2011/01/06 23:01:35
Damien Miller [Thu, 6 Jan 2011 23:02:52 +0000 (10:02 +1100)] 
   - djm@cvs.openbsd.org 2011/01/06 23:01:35
     [sshconnect.c]
     reset SIGCHLD handler to SIG_DFL when execuring LocalCommand;
     ok markus@

14 years ago - djm@cvs.openbsd.org 2011/01/06 22:46:21
Damien Miller [Thu, 6 Jan 2011 22:54:20 +0000 (09:54 +1100)] 
   - djm@cvs.openbsd.org 2011/01/06 22:46:21
     [regress/Makefile regress/host-expand.sh]
     regress test for LocalCommand %n expansion from bert.wesarg AT
     googlemail.com; ok markus@

14 years ago - djm@cvs.openbsd.org 2011/01/06 22:23:02
Damien Miller [Thu, 6 Jan 2011 22:51:52 +0000 (09:51 +1100)] 
   - djm@cvs.openbsd.org 2011/01/06 22:23:02
     [clientloop.c]
     when exiting due to ServerAliveTimeout, mention the hostname that caused
     it (useful with backgrounded controlmaster)

14 years ago - djm@cvs.openbsd.org 2011/01/06 22:23:53
Damien Miller [Thu, 6 Jan 2011 22:51:17 +0000 (09:51 +1100)] 
   - djm@cvs.openbsd.org 2011/01/06 22:23:53
     [ssh.c]
     unbreak %n expansion in LocalCommand; patch from bert.wesarg AT
     googlemail.com; ok markus@

14 years ago - (djm) [regress/cert-hostkey.sh regress/cert-userkey.sh] fix shell test
Damien Miller [Thu, 6 Jan 2011 22:50:08 +0000 (09:50 +1100)] 
 - (djm) [regress/cert-hostkey.sh regress/cert-userkey.sh] fix shell test
   for no-ECC case. Patch from cristian.ionescu-idbohrn AT axis.com

14 years ago - otto@cvs.openbsd.org 2011/01/04 20:44:13
Damien Miller [Thu, 6 Jan 2011 11:44:44 +0000 (22:44 +1100)] 
   - otto@cvs.openbsd.org 2011/01/04 20:44:13
     [ssh-keyscan.c]
     handle ecdsa-sha2 with various key lengths; hint and ok djm@

14 years ago - djm@cvs.openbsd.org 2010/12/24 21:41:48
Damien Miller [Thu, 6 Jan 2011 11:44:18 +0000 (22:44 +1100)] 
   - djm@cvs.openbsd.org 2010/12/24 21:41:48
     [auth-options.c]
     don't send the actual forced command in a debug message; ok markus deraadt

14 years ago - djm@cvs.openbsd.org 2010/12/15 00:49:27
Damien Miller [Thu, 6 Jan 2011 11:43:44 +0000 (22:43 +1100)] 
   - djm@cvs.openbsd.org 2010/12/15 00:49:27
     [readpass.c]
     fix ControlMaster=ask regression
     reset SIGCHLD handler before fork (and restore it after) so we don't miss
     the the askpass child's exit status. Correct test for exit status/signal to
     account for waitpid() failure; with claudio@ ok claudio@ markus@

14 years ago - markus@cvs.openbsd.org 2010/12/14 11:59:06
Damien Miller [Thu, 6 Jan 2011 11:42:04 +0000 (22:42 +1100)] 
   - markus@cvs.openbsd.org 2010/12/14 11:59:06
     [sshconnect.c]
     don't mention key type in key-changed-warning, since we also print
     this warning if a new key type appears. ok djm@

14 years ago - jmc@cvs.openbsd.org 2010/12/09 14:13:33
Damien Miller [Thu, 6 Jan 2011 11:41:21 +0000 (22:41 +1100)] 
   - jmc@cvs.openbsd.org 2010/12/09 14:13:33
     [scp.1 scp.c]
     scp.1: grammer fix
     scp.c: add -3 to usage()

14 years ago - markus@cvs.openbsd.org 2010/12/08 22:46:03
Damien Miller [Thu, 6 Jan 2011 11:40:30 +0000 (22:40 +1100)] 
   - markus@cvs.openbsd.org 2010/12/08 22:46:03
     [scp.1 scp.c]
     add a new -3 option to scp: Copies between two remote hosts are
     transferred through the local host.  Without this option the data
     is copied directly between the two remote hosts. ok djm@ (bugzilla #1837)

14 years ago - (djm) [configure.ac Makefile.in] Use mandoc as preferred manpage
Damien Miller [Mon, 3 Jan 2011 21:16:27 +0000 (08:16 +1100)] 
 - (djm) [configure.ac Makefile.in] Use mandoc as preferred manpage
   formatter if it is present, followed by nroff and groff respectively.
   Fixes distprep target on OpenBSD (which has bumped groff/nroff to ports
   in favour of mandoc). feedback and ok tim

14 years ago - (djm) [Makefile.in] revert local hack I didn't intend to commit
Damien Miller [Mon, 3 Jan 2011 03:48:14 +0000 (14:48 +1100)] 
 - (djm) [Makefile.in] revert local hack I didn't intend to commit

14 years ago - (djm) [configure.ac] Check whether libdes is needed when building
Damien Miller [Sun, 2 Jan 2011 10:53:07 +0000 (21:53 +1100)] 
 - (djm) [configure.ac] Check whether libdes is needed when building
   with Heimdal krb5 support. On OpenBSD this library no longer exists,
   so linking it unconditionally causes a build failure; ok dtucker

14 years ago - (djm) [loginrec.c] Fix some fd leaks on error paths. ok dtucker
Damien Miller [Sun, 2 Jan 2011 10:43:59 +0000 (21:43 +1100)] 
 - (djm) [loginrec.c] Fix some fd leaks on error paths. ok dtucker

14 years ago - djm@cvs.openbsd.org 2010/12/08 04:02:47
Damien Miller [Sun, 26 Dec 2010 03:26:45 +0000 (14:26 +1100)] 
   - djm@cvs.openbsd.org 2010/12/08 04:02:47
     [ssh_config.5 sshd_config.5]
     explain that IPQoS arguments are separated by whitespace; iirc requested
     by jmc@ a while back

14 years agoId sync
Darren Tucker [Sat, 4 Dec 2010 23:34:08 +0000 (10:34 +1100)] 
Id sync

14 years ago - djm@cvs.openbsd.org 2010/12/04 00:21:19
Darren Tucker [Sat, 4 Dec 2010 22:45:50 +0000 (09:45 +1100)] 
   - djm@cvs.openbsd.org 2010/12/04 00:21:19
     [regress/sftp-cmds.sh]
     adjust for hard-link support

14 years ago - (dtucker) [regress/Makefile] Id sync.
Darren Tucker [Sat, 4 Dec 2010 22:29:31 +0000 (09:29 +1100)] 
 - (dtucker) [regress/Makefile] Id sync.

14 years ago - djm@cvs.openbsd.org 2010/12/04 13:31:37
Darren Tucker [Sat, 4 Dec 2010 22:03:31 +0000 (09:03 +1100)] 
   - djm@cvs.openbsd.org 2010/12/04 13:31:37
     [hostfile.c]
     fix fd leak; spotted and ok dtucker

14 years ago - djm@cvs.openbsd.org 2010/12/04 00:18:01
Darren Tucker [Sat, 4 Dec 2010 22:02:47 +0000 (09:02 +1100)] 
   - djm@cvs.openbsd.org 2010/12/04 00:18:01
     [sftp-server.c sftp.1 sftp-client.h sftp.c PROTOCOL sftp-client.c]
     add a protocol extension to support a hard link operation. It is
     available through the "ln" command in the client. The old "ln"
     behaviour of creating a symlink is available using its "-s" option
     or through the preexisting "symlink" command; based on a patch from
     miklos AT szeredi.hu in bz#1555; ok markus@

14 years ago - djm@cvs.openbsd.org 2010/12/03 23:55:27
Darren Tucker [Sat, 4 Dec 2010 22:01:47 +0000 (09:01 +1100)] 
   - djm@cvs.openbsd.org 2010/12/03 23:55:27
     [auth-rsa.c]
     move check for revoked keys to run earlier (in auth_rsa_key_allowed)
     bz#1829; patch from ldv AT altlinux.org; ok markus@

14 years ago - (dtucker) OpenBSD CVS Sync
Darren Tucker [Sat, 4 Dec 2010 22:00:30 +0000 (09:00 +1100)] 
 - (dtucker) OpenBSD CVS Sync
   - djm@cvs.openbsd.org 2010/12/03 23:49:26
     [schnorr.c]
     check that g^x^q === 1 mod p; recommended by JPAKE author Feng Hao
     (this code is still disabled, but apprently people are treating it as
     a reference implementation)

14 years ago - (dtucker) openbsd-compat/openssl-compat.c] remove sleep leftover from
Darren Tucker [Sat, 4 Dec 2010 21:46:05 +0000 (08:46 +1100)] 
 - (dtucker) openbsd-compat/openssl-compat.c] remove sleep leftover from
   debugging.  Spotted by djm.

14 years ago - (dtucker) [configure.ac moduli.c openbsd-compat/openssl-compat.{c,h}] Add
Darren Tucker [Sat, 4 Dec 2010 12:20:50 +0000 (23:20 +1100)] 
 - (dtucker) [configure.ac moduli.c openbsd-compat/openssl-compat.{c,h}]  Add
   shims for the new, non-deprecated OpenSSL key generation functions for
   platforms that don't have the new interfaces.

14 years ago - (djm) [openbsd-compat/bindresvport.c] Use arc4random_uniform(range)
Damien Miller [Thu, 2 Dec 2010 23:50:26 +0000 (10:50 +1100)] 
 - (djm) [openbsd-compat/bindresvport.c] Use arc4random_uniform(range)
   instead of (arc4random() % range)

14 years ago - djm@cvs.openbsd.org 2010/11/29 23:45:51
Damien Miller [Wed, 1 Dec 2010 01:21:51 +0000 (12:21 +1100)] 
   - djm@cvs.openbsd.org 2010/11/29 23:45:51
     [auth.c hostfile.c hostfile.h ssh.c ssh_config.5 sshconnect.c]
     [sshconnect.h sshconnect2.c]
     automatically order the hostkeys requested by the client based on
     which hostkeys are already recorded in known_hosts. This avoids
     hostkey warnings when connecting to servers with new ECDSA keys
     that are preferred by default; with markus@

14 years ago - markus@cvs.openbsd.org 2010/11/29 18:57:04
Damien Miller [Wed, 1 Dec 2010 01:03:39 +0000 (12:03 +1100)] 
   - markus@cvs.openbsd.org 2010/11/29 18:57:04
     [authfile.c]
     correctly load comment for encrypted rsa1 keys;
     report/fix Joachim Schipper; ok djm@

14 years ago - djm@cvs.openbsd.org 2010/11/26 05:52:49
Damien Miller [Wed, 1 Dec 2010 01:03:19 +0000 (12:03 +1100)] 
   - djm@cvs.openbsd.org 2010/11/26 05:52:49
     [scp.c]
     Pass through ssh command-line flags and options when doing remote-remote
     transfers, e.g. to enable agent forwarding which is particularly useful
     in this case; bz#1837 ok dtucker@

14 years ago - djm@cvs.openbsd.org 2010/11/25 04:10:09
Damien Miller [Wed, 1 Dec 2010 01:02:59 +0000 (12:02 +1100)] 
   - djm@cvs.openbsd.org 2010/11/25 04:10:09
     [session.c]
     replace close() loop for fds 3->64 with closefrom();
     ok markus deraadt dtucker

14 years ago - djm@cvs.openbsd.org 2010/11/24 01:24:14
Damien Miller [Wed, 1 Dec 2010 01:02:35 +0000 (12:02 +1100)] 
   - djm@cvs.openbsd.org 2010/11/24 01:24:14
     [channels.c]
     remove a debug() that pollutes stderr on client connecting to a server
     in debug mode (channel_close_fds is called transitively from the session
     code post-fork); bz#1719, ok dtucker

14 years ago - djm@cvs.openbsd.org 2010/11/23 23:57:24
Damien Miller [Wed, 1 Dec 2010 01:02:14 +0000 (12:02 +1100)] 
   - djm@cvs.openbsd.org 2010/11/23 23:57:24
     [clientloop.c]
     avoid NULL deref on receiving a channel request on an unknown or invalid
     channel; report bz#1842 from jchadima AT redhat.com; ok dtucker@

14 years ago - djm@cvs.openbsd.org 2010/11/23 02:35:50
Damien Miller [Wed, 1 Dec 2010 01:01:51 +0000 (12:01 +1100)] 
   - djm@cvs.openbsd.org 2010/11/23 02:35:50
     [auth.c]
     use strict_modes already passed as function argument over referencing
     global options.strict_modes

14 years ago - djm@cvs.openbsd.org 2010/11/21 10:57:07
Damien Miller [Wed, 1 Dec 2010 01:01:21 +0000 (12:01 +1100)] 
   - djm@cvs.openbsd.org 2010/11/21 10:57:07
     [authfile.c]
     Refactor internals of private key loading and saving to work on memory
     buffers rather than directly on files. This will make a few things
     easier to do in the future; ok markus@

14 years ago - djm@cvs.openbsd.org 2010/11/21 01:01:13
Damien Miller [Wed, 1 Dec 2010 00:50:35 +0000 (11:50 +1100)] 
   - djm@cvs.openbsd.org 2010/11/21 01:01:13
     [clientloop.c misc.c misc.h ssh-agent.1 ssh-agent.c]
     honour $TMPDIR for client xauth and ssh-agent temporary directories;
     feedback and ok markus@

14 years ago - OpenBSD CVS Sync
Damien Miller [Wed, 1 Dec 2010 00:50:14 +0000 (11:50 +1100)] 
 - OpenBSD CVS Sync
   - deraadt@cvs.openbsd.org 2010/11/20 05:12:38
     [auth2-pubkey.c]
     clean up cases of ;;

14 years ago - (djm) [defines.h] Add IP DSCP defines
Damien Miller [Tue, 23 Nov 2010 23:50:04 +0000 (10:50 +1100)] 
 - (djm) [defines.h] Add IP DSCP defines

14 years ago - (dtucker) [packet.c] Remove redundant local declaration of "int tos".
Darren Tucker [Tue, 23 Nov 2010 23:46:37 +0000 (10:46 +1100)] 
 - (dtucker) [packet.c] Remove redundant local declaration of "int tos".

14 years ago - (djm) [loginrec.c] Relax permission requirement on btmp logs to allow
Damien Miller [Tue, 23 Nov 2010 23:36:15 +0000 (10:36 +1100)] 
 - (djm) [loginrec.c] Relax permission requirement on btmp logs to allow
   group read/write. ok dtucker@

14 years ago - (dtucker) [platform.c session.c] Move the getluid call out of session.c and
Darren Tucker [Tue, 23 Nov 2010 23:09:13 +0000 (10:09 +1100)] 
 - (dtucker) [platform.c session.c] Move the getluid call out of session.c and
   into the platform-specific code  Only affects SCO, tested by and ok tim@.

14 years ago - (dtucker) Bug #1840: fix warning when configuring --with-ssl-engine, patch
Darren Tucker [Mon, 22 Nov 2010 06:59:00 +0000 (17:59 +1100)] 
 - (dtucker) Bug #1840: fix warning when configuring --with-ssl-engine, patch
   from vapier at gentoo org.

14 years ago - jmc@cvs.openbsd.org 2010/11/18 15:01:00
Damien Miller [Sat, 20 Nov 2010 04:21:03 +0000 (15:21 +1100)] 
   - jmc@cvs.openbsd.org 2010/11/18 15:01:00
     [scp.1 sftp.1 ssh.1 sshd_config.5]
     add IPQoS to the various -o lists, and zap some trailing whitespace;

14 years ago - jmc@cvs.openbsd.org 2010/11/15 07:40:14
Damien Miller [Sat, 20 Nov 2010 04:20:10 +0000 (15:20 +1100)] 
   - jmc@cvs.openbsd.org 2010/11/15 07:40:14
     [ssh_config.5]
     libary -> library;

14 years ago - djm@cvs.openbsd.org 2010/11/13 23:27:51
Damien Miller [Sat, 20 Nov 2010 04:19:38 +0000 (15:19 +1100)] 
   - djm@cvs.openbsd.org 2010/11/13 23:27:51
     [clientloop.c misc.c misc.h packet.c packet.h readconf.c readconf.h]
     [servconf.c servconf.h session.c ssh.c ssh_config.5 sshd_config.5]
     allow ssh and sshd to set arbitrary TOS/DSCP/QoS values instead of
     hardcoding lowdelay/throughput.

     bz#1733 patch from philipp AT redfish-solutions.com; ok markus@ deraadt@

14 years ago - djm@cvs.openbsd.org 2010/11/10 01:33:07
Damien Miller [Sat, 20 Nov 2010 04:15:49 +0000 (15:15 +1100)] 
   - djm@cvs.openbsd.org 2010/11/10 01:33:07
     [kexdhc.c kexdhs.c kexgexc.c kexgexs.c key.c moduli.c]
     use only libcrypto APIs that are retained with OPENSSL_NO_DEPRECATED.
     these have been around for years by this time. ok markus

14 years ago - djm@cvs.openbsd.org 2010/11/05 02:46:47
Damien Miller [Sat, 20 Nov 2010 04:14:29 +0000 (15:14 +1100)] 
   - djm@cvs.openbsd.org 2010/11/05 02:46:47
     [packet.c]
     whitespace KNF

14 years ago - (djm) [servconf.c ssh-add.c ssh-keygen.c] don't look for ECDSA keys on
Damien Miller [Thu, 11 Nov 2010 03:17:02 +0000 (14:17 +1100)] 
 - (djm) [servconf.c ssh-add.c ssh-keygen.c] don't look for ECDSA keys on
   platforms that don't support ECC. Fixes some spurious warnings reported
   by tim@

14 years ago - (tim) [configure.ac openbsd-compat/bsd-misc.h openbsd-compat/bsd-misc.c] Add
Tim Rice [Mon, 8 Nov 2010 22:26:23 +0000 (14:26 -0800)] 
 - (tim) [configure.ac openbsd-compat/bsd-misc.h openbsd-compat/bsd-misc.c] Add
   support for platforms missing isblank(). ok djm@

14 years ago - (tim) [regress/kextype.sh] Not all platforms have time in /usr/bin.
Tim Rice [Mon, 8 Nov 2010 17:15:14 +0000 (09:15 -0800)] 
 - (tim) [regress/kextype.sh] Not all platforms have time in /usr/bin.
   Feedback from dtucker@

14 years ago - (tim) [regress/kextype.sh] Shell portability fix.
Tim Rice [Sun, 7 Nov 2010 21:03:11 +0000 (13:03 -0800)] 
 - (tim) [regress/kextype.sh] Shell portability fix.

14 years ago - (tim) [regress/Makefile] Fixes to allow building/testing outside source
Tim Rice [Sun, 7 Nov 2010 21:00:27 +0000 (13:00 -0800)] 
 - (tim) [regress/Makefile] Fixes to allow building/testing outside source
   tree.

14 years ago - (dtucker) [platform.c] includes.h instead of defines.h so that we get
Darren Tucker [Sun, 7 Nov 2010 07:05:54 +0000 (18:05 +1100)] 
 - (dtucker) [platform.c] includes.h instead of defines.h so that we get
   the correct typedefs.

14 years ago - (dtucker) [platform.c] Need servconf.h and extern options.
Darren Tucker [Fri, 5 Nov 2010 07:56:08 +0000 (18:56 +1100)] 
 - (dtucker) [platform.c] Need servconf.h and extern options.

14 years ago - (dtucker) [regress/kextype.sh] Make sha256 test depend on ECC. This is not
Darren Tucker [Fri, 5 Nov 2010 07:41:50 +0000 (18:41 +1100)] 
 - (dtucker) [regress/kextype.sh] Make sha256 test depend on ECC.  This is not
   strictly correct since while ECC requires sha256 the reverse is not true
   however it does prevent spurious test failures.

14 years ago - (dtucker) [regress/kextype.sh] Add missing "test".
Darren Tucker [Fri, 5 Nov 2010 07:35:52 +0000 (18:35 +1100)] 
 - (dtucker) [regress/kextype.sh] Add missing "test".

14 years ago - (dtucker) [Makefile configure.ac regress/Makefile regress/keytype.sh]
Darren Tucker [Fri, 5 Nov 2010 07:23:38 +0000 (18:23 +1100)] 
 - (dtucker) [Makefile configure.ac regress/Makefile regress/keytype.sh]
   Import recent changes to regress/Makefile, pass a flag to enable ECC tests
   from configure through to regress/Makefile and use it in the tests.

14 years ago - (dtucker) [regress/keytype.sh] Import new test.
Darren Tucker [Fri, 5 Nov 2010 07:19:15 +0000 (18:19 +1100)] 
 - (dtucker) [regress/keytype.sh] Import new test.

14 years ago - (dtucker) [platform.c platform.h session.c] Move the Cygwin special-case
Darren Tucker [Fri, 5 Nov 2010 03:47:01 +0000 (14:47 +1100)] 
 - (dtucker) [platform.c platform.h session.c] Move the Cygwin special-case
   check into platform.c

14 years ago - (dtucker) [platform.c session.c] Move PAM credential establishment for the
Darren Tucker [Fri, 5 Nov 2010 02:32:52 +0000 (13:32 +1100)] 
 - (dtucker) [platform.c session.c] Move PAM credential establishment for the
   non-LOGIN_CAP case into platform.c.

14 years ago - (dtucker) [platform.c session.c] Move irix setusercontext fragment into
Darren Tucker [Fri, 5 Nov 2010 02:29:25 +0000 (13:29 +1100)] 
 - (dtucker) [platform.c session.c] Move irix setusercontext fragment into
   platform.c.

14 years ago - (dtucker) platform.c session.c] Move aix_usrinfo frament into platform.c.
Darren Tucker [Fri, 5 Nov 2010 02:11:04 +0000 (13:11 +1100)] 
 - (dtucker) platform.c session.c] Move aix_usrinfo frament into platform.c.

14 years ago - (dtucker) platform.c session.c] Move the USE_LIBIAF fragment into
Darren Tucker [Fri, 5 Nov 2010 02:07:24 +0000 (13:07 +1100)] 
 - (dtucker) platform.c session.c] Move the USE_LIBIAF fragment into
   platform.c

14 years ago - (dtucker) [platform.c session.c] Move the PAM credential establishment for
Darren Tucker [Fri, 5 Nov 2010 02:00:05 +0000 (13:00 +1100)] 
 - (dtucker) [platform.c session.c] Move the PAM credential establishment for
   the LOGIN_CAP case into platform.c.

14 years ago - (dtucker) [platform.c] Only call setpgrp on BSDI if running as root to
Darren Tucker [Fri, 5 Nov 2010 01:50:41 +0000 (12:50 +1100)] 
 - (dtucker) [platform.c] Only call setpgrp on BSDI if running as root to
   retain previous behavior.

14 years ago - (dtucker) [platform.c session.c] Move the BSDI setpgrp into platform.c.
Darren Tucker [Fri, 5 Nov 2010 01:45:18 +0000 (12:45 +1100)] 
 - (dtucker) [platform.c session.c] Move the BSDI setpgrp into platform.c.

14 years ago - (dtucker) [platform.c session.c] Move the AIX setpcred+chroot hack into
Darren Tucker [Fri, 5 Nov 2010 01:41:13 +0000 (12:41 +1100)] 
 - (dtucker) [platform.c session.c] Move the AIX setpcred+chroot hack into
   platform.c

14 years ago - (dtucker) [platform.c platform.h session.c] Add a platform hook to run
Darren Tucker [Fri, 5 Nov 2010 01:36:15 +0000 (12:36 +1100)] 
 - (dtucker) [platform.c platform.h session.c] Add a platform hook to run
   after the user's groups are established and move the selinux calls into it.

14 years ago - (dtucker) [configure.ac platform.{c,h} session.c
Darren Tucker [Fri, 5 Nov 2010 01:03:05 +0000 (12:03 +1100)] 
 - (dtucker) [configure.ac platform.{c,h} session.c
   openbsd-compat/port-solaris.{c,h}] Bug #1824: Add Solaris Project support.
   Patch from cory.erickson at csu mnscu edu with a bit of rework from me.
   ok djm@

14 years ago - (djm) [loginrec.c loginrec.h] Use correct uid_t/pid_t types instead of
Damien Miller [Thu, 4 Nov 2010 23:52:37 +0000 (10:52 +1100)] 
 - (djm) [loginrec.c loginrec.h] Use correct uid_t/pid_t types instead of
   int. Should fix bz#1817 cleanly; ok dtucker@

14 years ago - djm@cvs.openbsd.org 2010/11/04 02:45:34
Damien Miller [Thu, 4 Nov 2010 23:20:31 +0000 (10:20 +1100)] 
   - djm@cvs.openbsd.org 2010/11/04 02:45:34
     [sftp-server.c]
     umask should be parsed as octal. reported by candland AT xmission.com;
     ok markus@

14 years ago - jmc@cvs.openbsd.org 2010/10/28 18:33:28
Damien Miller [Thu, 4 Nov 2010 23:20:14 +0000 (10:20 +1100)] 
   - jmc@cvs.openbsd.org 2010/10/28 18:33:28
     [scp.1 ssh-add.1 ssh-keygen.1 ssh.1 ssh_config.5 sshd.8 sshd_config.5]
     knock out some "-*- nroff -*-" lines;