+20030923
+ - (dtucker) [Makefile.in] Bug #644: Fix "make clean" for out-of-tree
+ builds. Portability corrections from tim@.
+ - (dtucker) [configure.ac] Bug #665: uid swapping issues on Mac OS X.
+ Patch from max at quendi.de.
+ - (dtucker) [configure.ac] Bug #657: uid swapping issues on BSDi.
+ - (dtucker) [configure.ac] Bug #653: uid swapping issues on Tru64.
+ - (dtucker) [configure.ac] Bug #693: uid swapping issues on NCR MP-RAS.
+ Patch from david.haughton at ncr.com
+ - (dtucker) [configure.ac] Bug #659: uid swapping issues on IRIX 6.
+ Part of patch supplied by bugzilla-openssh at thewrittenword.com
+ - (dtucker) [configure.ac openbsd-compat/fake-rfc2553.c
+ openbsd-compat/fake-rfc2553.h] Bug #659: Test for and handle systems with
+ where gai_strerror is defined as "const char *". Part of patch supplied
+ by bugzilla-openssh at thewrittenword.com
+ - (dtucker) [contrib/cygwin/README contrib/cygwin/ssh-host-config] Update
+ ssh-host-config to match current defaults, bump README version. Patch from
+ vinschen at redhat.com.
+ - (dtucker) [uidswap.c] Don't test restoration of uid on Cygwin since the
+ OS does not support permanently dropping privileges. Patch from
+ vinschen at redhat.com.
+ - (dtucker) [openbsd-compat/port-aix.c] Use correct include for xmalloc.h,
+ add canohost.h to stop warning. Based on patch from openssh-unix-dev at
+ thewrittenword.com
+ - (dtucker) [INSTALL] Bug #686: Document requirement for zlib 1.1.4 or
+ higher.
+ - (tim) Fix typo. s/SETEIUD_BREAKS_SETUID/SETEUID_BREAKS_SETUID/
+ - (tim) [configure.ac] Bug 665: move 3 new AC_DEFINES outside of AC_TRY_RUN.
+ Report by distler AT golem ph utexas edu.
+ - (dtucker) [contrib/aix/pam.conf] Include example pam.conf for AIX from
+ article by genty at austin.ibm.com, included with the author's permission.
+ - (dtucker) OpenBSD CVS Sync
+ - markus@cvs.openbsd.org 2003/09/18 07:52:54
+ [sshconnect.c]
+ missing {}; bug #656; jclonguet at free.fr
+ - markus@cvs.openbsd.org 2003/09/18 07:54:48
+ [buffer.c]
+ protect against double free; #660; zardoz at users.sf.net
+ - markus@cvs.openbsd.org 2003/09/18 07:56:05
+ [authfile.c]
+ missing buffer_free(&encrypted); #662; zardoz at users.sf.net
+ - markus@cvs.openbsd.org 2003/09/18 08:49:45
+ [deattack.c misc.c session.c ssh-agent.c]
+ more buffer allocation fixes; from Solar Designer; CAN-2003-0682;
+ ok millert@
+ - miod@cvs.openbsd.org 2003/09/18 13:02:21
+ [authfd.c bufaux.c dh.c mac.c ssh-keygen.c]
+ A few signedness fixes for harmless situations; markus@ ok
+ - markus@cvs.openbsd.org 2003/09/19 09:02:02
+ [packet.c]
+ buffer_dump only if PACKET_DEBUG is defined; Jedi/Sector One; pr 3471
+ - markus@cvs.openbsd.org 2003/09/19 09:03:00
+ [buffer.c]
+ sign fix in buffer_dump; Jedi/Sector One; pr 3473
+ - markus@cvs.openbsd.org 2003/09/19 11:29:40
+ [ssh-agent.c]
+ provide a ssh-agent specific fatal() function; ok deraadt
+
+20030919
+ - (djm) Bug #683: Remove reference to --with-ipv4-default from INSTALL;
+ djast AT cs.toronto.edu
+ - (djm) Bug #661: Remove duplicate check for basename; from
+ bugzilla-openssh AT thewrittenword.com
+ - (djm) Bug #641: Allow RedHat RPM building without GTK-2; Patch from
+ jason AT devrandom.org
+ - (djm) Bug #646: Fix location of x11-ssh-askpass; Jim
+ - (dtucker) [openbsd-compat/port-aix.h] Bug #640: Don't include audit.h
+ unless required. Reorder to reduce warnings.
+ - (dtucker) [session.c] Bug #643: Fix size_t -> u_int and fix null deref
+ when /etc/default/login doesn't exist or isn't readable. Fixes from
+ jparsons-lists at saffron.net and georg.oppenberg at deu mci com.
+ - (dtucker) [acconfig.h] Updated basename test needs HAVE_BASENAME
+
+20030918
+ - (djm) Bug #652: Fix empty password auth
+
+20030917
+ - (djm) Sync with V_3_7 branch
+ - (djm) OpenBSD Sync
+ - markus@cvs.openbsd.org 2003/09/16 21:02:40
+ [buffer.c channels.c version.h]
+ more malloc/fatal fixes; ok millert/deraadt; ghudson at MIT.EDU
+ - (djm) Crank RPM spec file versions
+ - (tim) [openbsd-compat/inet_ntoa.c] 20030917 "Sync with V_3_7 branch" undid
+ 20030916 "Missed dead header in inet_ntoa.c"
+
+20030916
+ - (dtucker) [acconfig.h configure.ac defines.h session.c] Bug #252: Retrieve
+ PATH (or SUPATH) and UMASK from /etc/default/login on platforms that have it
+ (eg Solaris, Reliant Unix). Patch from Robert.Dahlem at siemens.com.
+ ok djm@
+ - (bal) OpenBSD Sync
+ - deraadt@cvs.openbsd.org 2003/09/16 03:03:47
+ [buffer.c]
+ do not expand buffer before attempting to reallocate it; markus ok
+ - (tim) [configure.ac] Fix portability issues.
+ - (bal) Missed dead header in inet_ntoa.c
+
+20030914
+ - (dtucker) [Makefile regress/Makefile] Fix portability issues preventing
+ the regression tests from running with Solaris' make. Patch from Brian
+ Poole (raj at cerias.purdue.edu).
+ - (dtucker) [regress/Makefile] AIX's make doesn't like " +=", so replace
+ with vanilla "=".
+
+20030913
+ - (dtucker) [regress/agent-timeout.sh] Timeout of 5 sec is borderline for
+ slower hosts, increase to 10 sec.
+ - (dtucker) [auth-passwd.c] On AIX, call setauthdb() before loginsuccess(),
+ required to correctly reset failed login count when using a password
+ registry other than "files" (eg LDAP, see bug #543).
+ - (tim) [configure.ac] define WITH_ABBREV_NO_TTY for SCO.
+ Report by Roger Cornelius.
+ - (dtucker) [auth-pam.c] Use SSHD_PAM_SERVICE for PAM service name, patch
+ from cjwatson at debian.org.
+
+20030912
+ - (tim) [regress/agent-ptrace.sh] sh doesn't like "if ! shell_function; then".
+ - (tim) [Makefile.in] only mkdir regress if it does not exist.
+ - (tim) [regress/yes-head.sh] shell portability fix.
+
+20030911
+ - (dtucker) [configure.ac] Bug #588, #615: Move other libgen tests to after
+ the dirname test, to allow a broken dirname to be detected correctly.
+ Based partially on patch supplied by alex.kiernan at thus.net. ok djm@
+ - (tim) [configure.ac] Move libgen tests to before libwrap to unbreak
+ UnixWare 2.03 using --with-tcp-wrappers.
+ - (tim) [configure.ac] Prefer setuid/setgid on UnixWare and Open Server.
+ - (tim) [regress/agent-ptrace.sh regress/dynamic-forward.sh
+ regress/sftp-cmds.sh regress/stderr-after-eof.sh regress/test-exec.sh]
+ no longer depends on which(1). patch by dtucker@
+
+20030910
+ - (dtucker) [configure.ac] Bug #636: Add support for Cray's new X1 machine.
+ Patch from wendyp at cray.com.
+ - (dtucker) [configure.ac] Part of bug #615: tcsendbreak might be a macro.
+ - (dtucker) [regressh/yes-head.sh] Some platforms (eg Solaris) don't have
+ "yes".
+
+20030909
+ - (tim) [regress/Makefile] Fixes for building outside of a read-only
+ source tree.
+ - (tim) [regress/agent-timeout.sh] s/TIMEOUT/SSHAGENT_TIMEOUT/ Fixes conflict
+ with shell read-only variable.
+ - (tim) [regress/sftp-badcmds.sh regress/sftp-cmds.sh] Fix errors like
+ UX:rm: ERROR: Cannot remove '.' or '..'
+
+20030908
+ - (tim) [configure.ac openbsd-compat/getrrsetbyname.c] wrap _getshort and
+ _getlong in #ifndef
+ - (tim) [configure.ac acconfig.h openbsd-compat/getrrsetbyname.c] test for
+ HEADER.ad in arpa/nameser.h
+ - (tim) [ssh-keygen.c] s/PATH_MAX/MAXPATHLEN/ ok mouring@
+
+20030907
+ - (dtucker) [agent-ptrace.sh dynamic-forward.sh (all regress/)]
+ Put "which" inside quotes.
+ - (dtucker) [dynamic-forward.sh forwarding.sh sftp-batch.sh (all regress/)]
+ Add ${EXEEXT}: required to work on Cygwin.
+ - (dtucker) [regress/sftp-batch.sh] Make temporary batch file name more
+ distinctive, so "rm ${BATCH}.*" doesn't match the script itself.
+ - (dtucker) [regress/sftp-cmds.sh] Skip quoted file test on Cygwin.
+ - (dtucker) [openbsd-compat/xcrypt.c] #elsif -> #elif
+ - (dtucker) [acconfig.h] Typo.
+ - (dtucker) [CREDITS Makefile.in configure.ac mdoc2man.awk mdoc2man.pl]
+ Replace mdoc2man.pl with mdoc2man.awk, provided by Peter Stuge.
+
+20030906
+ - (dtucker) [acconfig.h configure.ac uidswap.c] Prefer setuid/setgid on AIX.
+
+20030905
+ - (dtucker) [Makefile.in] Add distclean target for regress/, fix clean target.
+
+20030904
+ - (dtucker) Portablize regression tests. Parts contributed by Roumen
+ Petrov, David M. Williams and Corinna Vinschen.
+ - [Makefile.in] Add "make tests" target and "make clean" hooks.
+ - [regress/agent-getpeereid.sh] Skip test on platforms that don't support
+ getpeereid.
+ - [regress/agent-ptrace.sh] Skip tests if platform doesn't support it or
+ gdb cannot be found.
+ - [regress/reconfigure/sh] Make path to sshd fully qualified if required.
+ - [regress/rekey.sh] Remove dependence on /dev/zero (not all platforms have
+ it). The sparse file will take less disk space too.
+ - [regress/sftp-cmds.sh] Ensure files used for test are readable.
+ - [regress/stderr-after-eof.sh] Search for a usable checksum program.
+ - [regress/sftp-badcmds.sh regress/sftp-cmds.sh regress/sftp.sh
+ regress/ssh-com-client.sh regress/ssh-com-sftp.sh regress/stderr-data.sh
+ regress/transfer.sh] Use ${EXEEXT} where appropriate.
+ - [regress/sftp.sh regress/ssh-com-sftp.sh] Remove dependency on /dev/stdin.
+ - [regress/agent-ptrace.sh regress/agent-timeout.sh]
+ "grep -q" -> "grep >/dev/null"
+ - [regress/agent.sh regress/proto-version.sh regress/ssh-com.sh
+ regress/test-exec.sh] Handle different ways of echoing without newlines.
+ - [regress/dynamic-forward.sh] Some "which" programs output on stderr.
+ - [regress/sftp-cmds.sh] Use portable "test" option.
+ - [regress/test-exec.sh] Use sudo, search for "whoami" equivalent, always
+ use Strictmodes no, wait longer for sshd startup.
+ - [regress/Makefile] Remove BSDisms.
+ - [regress/README.regress] Add a basic readme.
+ - [Makefile.in regress/agent-getpeereid.sh] config.h is now in $BUILDDIR
+ not $OBJ.
+ - [Makefile.in regress/agent-ptrace] Fix minor regress issues on Cygwin.
+
+20030903
+ - (djm) OpenBSD CVS Sync
+ - markus@cvs.openbsd.org 2003/08/26 09:58:43
+ [auth-passwd.c auth.c auth.h auth1.c auth2-none.c auth2-passwd.c]
+ [auth2.c monitor.c]
+ fix passwd auth for 'username leaks via timing'; with djm@, original
+ patches from solar
+ - markus@cvs.openbsd.org 2003/08/28 12:54:34
+ [auth.h]
+ remove kerberos support from ssh1, since it has been replaced with GSSAPI;
+ but keep kerberos passwd auth for ssh1 and 2; ok djm, hin, henning, ...
+ - markus@cvs.openbsd.org 2003/09/02 16:40:29
+ [version.h]
+ enter 3.7
+ - jmc@cvs.openbsd.org 2003/09/02 18:50:06
+ [sftp.1 ssh_config.5]
+ escape punctuation;
+ ok deraadt@
+
+20030902
+ - (djm) OpenBSD CVS Sync
+ - deraadt@cvs.openbsd.org 2003/08/24 17:36:51
+ [auth2-gss.c]
+ 64 bit cleanups; markus ok
+ - markus@cvs.openbsd.org 2003/08/28 12:54:34
+ [auth-krb5.c auth.h auth1.c monitor.c monitor.h monitor_wrap.c]
+ [monitor_wrap.h readconf.c servconf.c session.c ssh_config.5]
+ [sshconnect1.c sshd.c sshd_config sshd_config.5]
+ remove kerberos support from ssh1, since it has been replaced with GSSAPI;
+ but keep kerberos passwd auth for ssh1 and 2; ok djm, hin, henning, ...
+ - markus@cvs.openbsd.org 2003/08/29 10:03:15
+ [compat.c compat.h]
+ SSH_BUG_K5USER is unused; ok henning@
+ - markus@cvs.openbsd.org 2003/08/29 10:04:36
+ [channels.c nchan.c]
+ be less chatty; debug -> debug2, cleanup; ok henning@
+ - markus@cvs.openbsd.org 2003/08/31 10:26:04
+ [progressmeter.c]
+ pass file_size + 1 to snprintf: fixes printing of truncated
+ file names; fix based on patch/report from sturm@;
+ - markus@cvs.openbsd.org 2003/08/31 12:14:22
+ [progressmeter.c]
+ do write to buf[-1]
+ - markus@cvs.openbsd.org 2003/08/31 13:29:05
+ [session.c]
+ call ssh_gssapi_storecreds conditionally from do_exec();
+ with sxw@inf.ed.ac.uk
+ - markus@cvs.openbsd.org 2003/08/31 13:30:18
+ [gss-serv.c]
+ correct string termination in parse_ename(); sxw@inf.ed.ac.uk
+ - markus@cvs.openbsd.org 2003/08/31 13:31:57
+ [gss-serv.c]
+ whitspace KNF
+ - markus@cvs.openbsd.org 2003/09/01 09:50:04
+ [sshd_config.5]
+ gss kex is not supported; sxw@inf.ed.ac.uk
+ - markus@cvs.openbsd.org 2003/09/01 12:50:46
+ [readconf.c]
+ rm gssapidelegatecreds alias; never supported before
+ - markus@cvs.openbsd.org 2003/09/01 13:52:18
+ [ssh.h]
+ rm whitespace
+ - markus@cvs.openbsd.org 2003/09/01 18:15:50
+ [readconf.c readconf.h servconf.c servconf.h ssh.c]
+ remove unused kerberos code; ok henning@
+ - markus@cvs.openbsd.org 2003/09/01 20:44:54
+ [auth2-gss.c]
+ fix leak
+ - (djm) Don't initialise pam_conv structures inline. Avoids HP/UX compiler
+ error. Part of Bug #423, patch from michael_steffens AT hp.com
+ - (djm) Bug #423: reorder setting of PAM_TTY and calling of PAM session
+ management (now done in do_setusercontext). Largely from
+ michael_steffens AT hp.com
+ - (djm) Fix openbsd-compat/ again - remove references to strl(cpy|cat).h
+
+20030829
+ - (bal) openbsd-compat/ clean up. Considate headers, add in Id on our
+ files, and added missing license to header.
+
+20030826
+ - (djm) Bug #629: Mark ssh_config option "pamauthenticationviakbdint"
+ as deprecated. Remove mention from README.privsep. Patch from
+ aet AT cc.hut.fi
+ - (dtucker) OpenBSD CVS Sync
+ - markus@cvs.openbsd.org 2003/08/22 10:56:09
+ [auth2.c auth2-gss.c auth.h compat.c compat.h gss-genr.c gss-serv-krb5.c
+ gss-serv.c monitor.c monitor.h monitor_wrap.c monitor_wrap.h readconf.c
+ readconf.h servconf.c servconf.h session.c session.h ssh-gss.h
+ ssh_config.5 sshconnect2.c sshd_config sshd_config.5]
+ support GSS API user authentication; patches from Simon Wilkinson,
+ stripped down and tested by Jakob and myself.
+ - markus@cvs.openbsd.org 2003/08/22 13:20:03
+ [sshconnect2.c]
+ remove support for "kerberos-2@ssh.com"
+ - markus@cvs.openbsd.org 2003/08/22 13:22:27
+ [auth2.c] (auth2-krb5.c removed)
+ nuke "kerberos-2@ssh.com"
+ - markus@cvs.openbsd.org 2003/08/22 20:55:06
+ [LICENCE]
+ add Simon Wilkinson
+ - deraadt@cvs.openbsd.org 2003/08/24 17:36:52
+ [monitor.c monitor_wrap.c sshconnect2.c]
+ 64 bit cleanups; markus ok
+ - fgsch@cvs.openbsd.org 2003/08/25 08:13:09
+ [sftp-int.c]
+ fix div by zero when listing for filename lengths longer than width.
+ markus@ ok.
+ - djm@cvs.openbsd.org 2003/08/25 10:33:33
+ [sshconnect2.c]
+ fprintf->logit to silence login banner with "ssh -q"; ok markus@
+ - (dtucker) [Makefile.in acconfig.h auth-krb5.c auth-pam.c auth-pam.h
+ configure.ac defines.h gss-serv-krb5.c session.c ssh-gss.h sshconnect1.c
+ sshconnect2.c] Add Portable GSSAPI support, patch by Simon Wilkinson.
+ - (dtucker) [Makefile.in] Remove auth2-krb5.
+ - (dtucker) [contrib/aix/inventory.sh] Add public domain notice. ok mouring@
+ (the original author)
+ - (dtucker) [auth.c] Do not check for locked accounts when PAM is enabled.
+
+20030825
+ - (djm) Bug #621: Select OpenSC keys by usage attributes. Patch from
+ larsch@trustcenter.de
+ - (bal) openbsd-compat/ OpenBSD updates. Mostly licensing, ansifications
+ and minor fixes. OK djm@
+ - (bal) redo how we handle 'mysignal()'. Move it to
+ openbsd-compat/bsd-misc.c, s/mysignal/signal/ and #define signal to
+ be our 'mysignal' by default. OK djm@
+ - (dtucker) [acconfig.h auth.c configure.ac sshd.8] Bug #422 again: deny
+ any access to locked accounts. ok djm@
+ - (djm) Bug #564: Perform PAM account checks for all authentications when
+ UsePAM=yes; ok dtucker
+ - (dtucker) [configure.ac] Bug #533, #551: define BROKEN_GETADDRINFO on
+ Tru64, solves getnameinfo and "bad addr or host" errors. ok djm@
+ - (dtucker) [README buildbff.sh inventory.sh] (all in contrib/aix)
+ Update package builder: correctly handle config variables, use lsuser
+ rather than /etc/passwd, fix typos, add Id's.
+
+20030822
+ - (djm) s/get_progname/ssh_get_progname/g to avoid conflict with Heimdal
+ -lbroken; ok dtucker
+ - (dtucker) [contrib/cygwin/ssh-user-config] Put keys in authorized_keys
+ rather that authorized_keys2. Patch from vinschen@redhat.com.
+
+20030821
+ - (dtucker) OpenBSD CVS Sync
+ - markus@cvs.openbsd.org 2003/08/14 16:08:58
+ [ssh-keygen.c]
+ exit after primetest, ok djm@
+ - (dtucker) [defines.h] Put CMSG_DATA, CMSG_FIRSTHDR with other CMSG* macros,
+ change CMSG_DATA to use __CMSG_ALIGN (and thus work properly), reformat for
+ consistency.
+ - (dtucker) [configure.ac] Move openpty/ctty test outside of case statement
+ and after normal openpty test.
+
20030813
- (dtucker) [session.c] Remove #ifdef TIOCSBRK kludge.
+ - (dtucker) OpenBSD CVS Sync
+ - markus@cvs.openbsd.org 2003/08/13 08:33:02
+ [session.c]
+ use more portable tcsendbreak(3) and ignore break_length;
+ ok deraadt, millert
+ - markus@cvs.openbsd.org 2003/08/13 08:46:31
+ [auth1.c readconf.c readconf.h servconf.c servconf.h ssh.c ssh_config
+ ssh_config.5 sshconnect1.c sshd.8 sshd.c sshd_config sshd_config.5]
+ remove RhostsAuthentication; suggested by djm@ before; ok djm@, deraadt@,
+ fgsch@, miod@, henning@, jakob@ and others
+ - markus@cvs.openbsd.org 2003/08/13 09:07:10
+ [readconf.c ssh.c]
+ socks4->socks, since with support both 4 and 5; dtucker@zip.com.au
+ - (dtucker) [configure.ac openbsd-compat/bsd-misc.c openbsd-compat/bsd-misc.h]
+ Add a tcsendbreak function for platforms that don't have one, based on the
+ one from OpenBSD.
20030811
- (dtucker) OpenBSD CVS Sync