Commit Graph

  • b00331402f
    propagate PAM crashes to PerSourcePenalties Damien Miller 2024-06-17 17:02:18 +10:00
  • 1c207f456a
    minix doesn't have loopback, so skip penalty tests Damien Miller 2024-06-17 15:06:01 +10:00
  • 48443d202e
    upstream: same treatment for this test djm@openbsd.org 2024-06-16 11:54:49 +00:00
  • 45562a95ea
    upstream: penalty test is still a bit racy djm@openbsd.org 2024-06-16 08:18:06 +00:00
  • 8d0f7eb147
    upstream: crank up penalty timeouts so this should work on even the djm@openbsd.org 2024-06-15 03:59:10 +00:00
  • 93c75471a1
    upstream: sort -q in the options list; jmc@openbsd.org 2024-06-14 05:20:34 +00:00
  • dd7807bbe8
    upstream: clarify KEXAlgorithms supported vs available. Inspired by djm@openbsd.org 2024-06-14 05:01:22 +00:00
  • d172ad56df
    upstream: ssh-keyscan -q man bits djm@openbsd.org 2024-06-14 05:00:42 +00:00
  • 092e4ff9cc
    skip penalty-expire test in valgrind test env Damien Miller 2024-06-14 14:46:35 +10:00
  • 2866ad08a9
    upstream: split the PerSourcePenalties test in two: one tests penalty djm@openbsd.org 2024-06-14 04:43:11 +00:00
  • b2c64bc170
    add a sshd_config PamServiceName option Damien Miller 2024-06-14 14:19:23 +10:00
  • 9f032a4dd1
    upstream: don't redirect stderr for ssh-keyscan we expect to succeed djm@openbsd.org 2024-06-14 00:26:12 +00:00
  • 1e84d0cf40
    upstream: make host/banner comments go to stderr instead of stdout, djm@openbsd.org 2024-06-14 00:25:25 +00:00
  • 3e806d0118
    upstream: separate keywords with comma naddy@openbsd.org 2024-06-13 15:06:33 +00:00
  • abfd1f7a3c
    upstream: specify an algorithm for ssh-keyscan, otherwise it will make djm@openbsd.org 2024-06-14 00:23:55 +00:00
  • a8fbe2f7d0
    sshd: don't use argv[0] as PAM service name Damien Miller 2024-06-13 16:41:29 +10:00
  • bf204bd05c
    prepare for checking in autogenerated files Damien Miller 2024-06-13 15:00:28 +10:00
  • 425f79a837
    typo in comment Damien Miller 2024-06-13 14:41:33 +10:00
  • afe10313c1
    fix PTY allocation on Cygwin, broken by sshd split Damien Miller 2024-06-13 14:35:25 +10:00
  • f66d4df574
    delay lookup of privsep user until config loaded Damien Miller 2024-06-13 11:33:09 +10:00
  • f1c42858b9
    missing file for PerSourcePenalties regress test Damien Miller 2024-06-13 11:16:57 +10:00
  • 4de80ff4e6
    upstream: split PerSourcePenalties address tracking. Previously it djm@openbsd.org 2024-06-12 22:36:00 +00:00
  • 06ab4c6931
    upstream: do not mark up "(default: 20ms)"; jmc@openbsd.org 2024-06-11 05:24:39 +00:00
  • cfe243cd9f
    upstream: reap preauth net child if it hangs up during privsep message djm@openbsd.org 2024-06-11 02:54:51 +00:00
  • b0a711c00b
    upstream: fix PIDFILE handling, broken for SUDO=doas in last commit djm@openbsd.org 2024-06-11 01:58:27 +00:00
  • 90fb801e2d
    upstream: reap the pre-auth [net] child if it hangs up during privsep djm@openbsd.org 2024-06-11 02:00:30 +00:00
  • ef878d5879
    upstream: a little more RB_TREE paranoia djm@openbsd.org 2024-06-11 01:23:25 +00:00
  • fc4e96b217
    upstream: fix off-by-one comparison for PerSourcePenalty djm@openbsd.org 2024-06-11 01:22:25 +00:00
  • 82c836df4f
    upstream: move tree init before possible early return djm@openbsd.org 2024-06-11 01:21:41 +00:00
  • a2300f015c
    upstream: update to mention that PerSourcePenalties default to djm@openbsd.org 2024-06-11 01:07:35 +00:00
  • 41987efd35
    upstream: reap the [net] child if it hangs up while writing privsep djm@openbsd.org 2024-06-11 00:44:52 +00:00
  • 6211aa085f
    upstream: log waitpid() status for abnormal exits djm@openbsd.org 2024-06-11 00:40:21 +00:00
  • a59634c7ad
    upstream: correct error message djm@openbsd.org 2024-06-11 00:36:20 +00:00
  • fa7d7a667f
    upstream: avoid shadowing issues which some compilers won't accept deraadt@openbsd.org 2024-06-07 13:23:30 +00:00
  • 3ad4cd9eec
    upstream: escape the final dot at eol in "e.g." to avoid double jmc@openbsd.org 2024-06-06 21:14:49 +00:00
  • 0e0c69761a
    upstream: enable PerSourcePenalties by default. djm@openbsd.org 2024-06-06 20:25:48 +00:00
  • bd1f74741d
    upstream: mention that PerSourcePenalties don't affect concurrent djm@openbsd.org 2024-06-06 20:20:42 +00:00
  • 9774b93857
    upstream: regress test for PerSourcePenalties djm@openbsd.org 2024-06-06 19:49:25 +00:00
  • b8ebd86cef
    upstream: make sure logs are saved from sshd run via start_sshd djm@openbsd.org 2024-06-06 19:48:40 +00:00
  • d7b2070bda
    upstream: simplify djm@openbsd.org 2024-06-06 19:47:48 +00:00
  • e6ea3d2245
    upstream: prepare for PerSourcePenalties being enabled by default djm@openbsd.org 2024-06-06 18:48:13 +00:00
  • c0cb3b8c83
    upstream: disable stderr redirection before closing fds djm@openbsd.org 2024-06-06 19:50:01 +00:00
  • 81c1099d22
    upstream: Add a facility to sshd(8) to penalise particular djm@openbsd.org 2024-06-06 17:15:25 +00:00
  • 916b0b6174
    whitespace Damien Miller 2024-06-07 03:31:02 +10:00
  • 49b55e4418
    upstream: enable -fret-clean on amd64, for libc libcrypto ld.so deraadt@openbsd.org 2024-06-04 15:14:45 +00:00
  • cc80d51d03
    remove PRIVSEP macros for osx Damien Miller 2024-06-05 02:21:30 +10:00
  • 8785491123
    upstream: be really strict with fds reserved for communication with the djm@openbsd.org 2024-06-01 07:03:37 +00:00
  • f1c8918cb9
    depend Damien Miller 2024-05-31 19:12:26 +10:00
  • 94b4866cb1
    rename need_privsep to need_chroot Damien Miller 2024-05-31 19:11:14 +10:00
  • e68a95142e
    remove remaining use_privsep mention Damien Miller 2024-05-31 19:05:34 +10:00
  • b21d271f65
    upstream: warn when -r (deprecated option to disable re-exec) is djm@openbsd.org 2024-05-31 09:01:08 +00:00
  • a4b5bc246c
    upstream: typos djm@openbsd.org 2024-05-31 08:49:35 +00:00
  • 8054b90698
    upstream: don't need sys/queue.h here djm@openbsd.org 2024-05-27 01:52:26 +00:00
  • 210d423973
    upstream: remove references to SSH1 and DSA server keys naddy@openbsd.org 2024-05-26 20:35:12 +00:00
  • f0b9261d7f
    upstream: remove unused struct fwd_perm_list, no decl with complete jsg@openbsd.org 2024-05-23 23:47:16 +00:00
  • 2477a98c3e
    upstream: Do not pass -Werror twice when building with clang. naddy@openbsd.org 2024-05-22 15:24:55 +00:00
  • 435844f567
    upstream: Do not pass -Werror if building with gcc 3, for asn1.h miod@openbsd.org 2024-05-22 11:49:36 +00:00
  • fc5dc09283
    upstream: this test has been broken since 2014, and has been djm@openbsd.org 2024-05-22 04:20:00 +00:00
  • fd4816791b
    upstream: Add missing kex-names.c source file required since the anton@openbsd.org 2024-05-19 19:10:01 +00:00
  • beccb7319c
    upstream: remove duplicate copy of relink kit for sshd-session naddy@openbsd.org 2024-05-17 14:42:00 +00:00
  • dcd79fa141
    upstream: remove prototypes with no matching function; ok djm@ jsg@openbsd.org 2024-05-17 06:42:04 +00:00
  • 6454a05e7c
    upstream: remove externs for removed vars; ok djm@ jsg@openbsd.org 2024-05-17 06:38:00 +00:00
  • f3e4db4601
    upstream: -Werror was turned on (probably just for development), deraadt@openbsd.org 2024-05-17 06:11:17 +00:00
  • 24a1f3e5ad
    attempt at updating RPM specs for sshd-session Damien Miller 2024-05-17 14:50:43 +10:00
  • 17b566eeb7
    upstream: g/c unused variable djm@openbsd.org 2024-05-17 04:42:13 +00:00
  • 01fb82eb2a
    upstream: spelling; ok djm@ jsg@openbsd.org 2024-05-17 02:39:11 +00:00
  • b88b690e99
    upstream: allow overriding the sshd-session binary path djm@openbsd.org 2024-05-17 01:45:22 +00:00
  • a68f80f251
    upstream: Since ssh-agent(1) is only readable by root by now, use anton@openbsd.org 2024-04-03 06:01:11 +00:00
  • 92e5589031
    upstream: fix incorrect debug option name introduce in previous djm@openbsd.org 2024-05-17 01:17:40 +00:00
  • 4ad72878af
    upstream: construct and install a relink-kit for sshd-session ok deraadt@openbsd.org 2024-05-17 00:33:25 +00:00
  • 02e679a2cb
    Makefile support for sshd-session Damien Miller 2024-05-17 12:21:27 +10:00
  • c0416035c5
    upstream: missing files from previous djm@openbsd.org 2024-05-17 00:32:32 +00:00
  • 03e3de416e
    upstream: Start the process of splitting sshd into separate djm@openbsd.org 2024-05-17 00:30:23 +00:00
  • 1c0d813579
    upstream: simplify exit message handling, which was more complicated djm@openbsd.org 2024-05-09 09:46:47 +00:00
  • cbbbf76aa6
    upstream: remove SSH1 leftovers tobias@openbsd.org 2024-05-06 19:26:17 +00:00
  • bc5dcb8ab9
    upstream: never close stdin tobias@openbsd.org 2024-04-30 15:40:43 +00:00
  • 6a42b70e56
    sync getrrsetbyname.c with recent upstream changes Damien Miller 2024-05-08 09:43:59 +10:00
  • 661803c9ec
    Allow SID strings in sshd_config (#724) Andrew 2024-05-07 13:15:28 -07:00
  • afe9007141
    remove HAVE_FREEZERO from preprocessor definitions (#730) Tess Gauthier 2024-05-07 11:52:20 -04:00
  • 385ecb31e1
    upstream: fix home-directory extension implementation, it always djm@openbsd.org 2024-04-30 06:23:51 +00:00
  • 14e2b16bc6
    upstream: flush stdout after writing "sftp>" prompt when not using djm@openbsd.org 2024-04-30 06:16:55 +00:00
  • 2e69a72405
    upstream: stricter validation of messaging socket fd number; disallow djm@openbsd.org 2024-04-30 05:53:03 +00:00
  • da757b022b
    upstream: add missing reserved fields to key constraint protocol djm@openbsd.org 2024-04-30 05:45:56 +00:00
  • 16d0b82fa0
    depend Damien Miller 2024-04-30 12:39:34 +10:00
  • 66aaa678db
    upstream: correctly restore sigprocmask around ppoll() reported djm@openbsd.org 2024-04-30 02:14:10 +00:00
  • 80fb0eb215
    upstream: add explict check for server hostkey type against djm@openbsd.org 2024-04-30 02:10:49 +00:00
  • 5b28096d31
    upstream: correct indentation; no functional change ok tb@ jsg@openbsd.org 2024-04-23 13:34:50 +00:00
  • fd3cb8a827
    upstream: set right mode on ssh-agent at boot-time semarie@openbsd.org 2024-04-04 16:00:51 +00:00
  • 54343a260e
    upstream: Oops, incorrect hex conversion spotted by claudio. deraadt@openbsd.org 2024-04-02 12:22:38 +00:00
  • ec78c31409
    upstream: for parse_ipqos(), use strtonum() instead of mostly deraadt@openbsd.org 2024-04-02 10:02:08 +00:00
  • 8176e1a6c2
    upstream: can shortcut by returning strtonum() value directly; ok deraadt@openbsd.org 2024-04-02 09:56:58 +00:00
  • 9f543d7022
    upstream: rewrite convtime() to use a isdigit-scanner and deraadt@openbsd.org 2024-04-02 09:52:14 +00:00
  • 8673137f78
    upstream: Remove unused ptr[3] char array in pkcs11_decode_hex. claudio@openbsd.org 2024-04-02 09:48:24 +00:00
  • c7fec708f3
    upstream: Replace non-idiomatic strtoul(, 16) to parse a region deraadt@openbsd.org 2024-04-02 09:32:28 +00:00
  • 019a5f483b
    upstream: Use strtonum() instead of severely non-idomatic deraadt@openbsd.org 2024-04-02 09:29:31 +00:00
  • 8231ca046f
    upstream: also create a relink kit for ssh-agent, since it is a deraadt@openbsd.org 2024-04-01 15:50:17 +00:00
  • bf7bf50bd6
    upstream: new-style relink kit for sshd. The old scheme created deraadt@openbsd.org 2024-04-01 15:48:16 +00:00
  • b89ee6aa37
    fix how build script finds repo root (#729) Steve Lee 2024-04-29 08:43:53 -07:00
  • 00e6368892
    Shell syntax fix (leftover from a sync). renmingshuai 2024-04-12 10:20:49 +08:00
  • 2eded551ba
    Merge flags for OpenSSL 3.x versions. Darren Tucker 2024-04-25 13:20:19 +10:00