]> andersk Git - openssh.git/log
openssh.git
17 years ago - (dtucker) [INSTALL] Bug #1202: Note when autoconf is required and which
dtucker [Fri, 30 Jun 2006 06:20:58 +0000 (06:20 +0000)] 
 - (dtucker) [INSTALL] Bug #1202: Note when autoconf is required and which
   version.

17 years ago - (dtucker) [openbsd-compat/getrrsetbyname.c] Undef _res before defining it,
dtucker [Fri, 30 Jun 2006 01:47:49 +0000 (01:47 +0000)] 
 - (dtucker) [openbsd-compat/getrrsetbyname.c] Undef _res before defining it,
   prevents warnings on platforms where _res is in the system headers.

17 years ago - (dtucker) [openbsd-compat/openbsd-compat.h] SNPRINTF_CONST for snprintf
dtucker [Fri, 30 Jun 2006 00:51:32 +0000 (00:51 +0000)] 
 - (dtucker) [openbsd-compat/openbsd-compat.h] SNPRINTF_CONST for snprintf
   declaration too.  Patch from russ at sludge.net.

17 years ago - (dtucker) [configure.ac] Bug #1203: Add missing '[', which causes problems
dtucker [Tue, 27 Jun 2006 01:20:28 +0000 (01:20 +0000)] 
 - (dtucker) [configure.ac] Bug #1203: Add missing '[', which causes problems
   with autoconf 2.60.  Patch from vapier at gentoo.org.

17 years ago - (dtucker) [channels.c serverloop.c] Apply the bug #1102 workaround to ptys
dtucker [Sat, 24 Jun 2006 22:25:25 +0000 (22:25 +0000)] 
 - (dtucker) [channels.c serverloop.c] Apply the bug #1102 workaround to ptys
   only, otherwise sshd can hang exiting non-interactive sessions.

17 years ago - (dtucker) [serverloop.c] Get ifdef/ifndef the right way around for the bug
dtucker [Sat, 24 Jun 2006 06:58:45 +0000 (06:58 +0000)] 
 - (dtucker) [serverloop.c] Get ifdef/ifndef the right way around for the bug
   #1102 workaround.

17 years ago - (dtucker) [configure.ac] Bug #1193: Define PASSWD_NEEDS_USERNAME on Solaris.
dtucker [Sat, 24 Jun 2006 02:10:07 +0000 (02:10 +0000)] 
 - (dtucker) [configure.ac] Bug #1193: Define PASSWD_NEEDS_USERNAME on Solaris.
   Works around limitation in Solaris' passwd program for changing passwords
   where the username is longer than 8 characters.  ok djm@

17 years ago - (dtucker) [channels.c configure.ac serverloop.c] Bug #1102: Around AIX
dtucker [Fri, 23 Jun 2006 11:24:12 +0000 (11:24 +0000)] 
 - (dtucker) [channels.c configure.ac serverloop.c] Bug #1102: Around AIX
   4.3.3 ML3 or so, the AIX pty layer starting passing zero-length writes
   on the pty slave as zero-length reads on the pty master, which sshd
   interprets as the descriptor closing.  Since most things don't do zero
   length writes this rarely matters, but occasionally it happens, and when
   it does the SSH pty session appears to hang, so we add a special case for
   this condition.  ok djm@

17 years ago - (dtucker) [README.platform configure.ac openbsd-compat/port-tun.c] Add
dtucker [Fri, 23 Jun 2006 11:05:12 +0000 (11:05 +0000)] 
 - (dtucker) [README.platform configure.ac openbsd-compat/port-tun.c] Add
   tunnel support for Mac OS X/Darwin via a third-party tun driver.  Patch
   from reyk@, tested by anil@

17 years ago - (djm) [getput.h] This file has been replaced by functions in misc.c
djm [Tue, 13 Jun 2006 03:15:54 +0000 (03:15 +0000)] 
 - (djm) [getput.h] This file has been replaced by functions in misc.c

17 years ago - djm@cvs.openbsd.org 2006/06/13 01:18:36
djm [Tue, 13 Jun 2006 03:10:18 +0000 (03:10 +0000)] 
   - djm@cvs.openbsd.org 2006/06/13 01:18:36
     [ssh-agent.c]
     always use a format string, even when printing a constant
   - djm@cvs.openbsd.org 2006/06/13 02:17:07
     [ssh-agent.c]
     revert; i am on drugs. spotted by alexander AT beard.se

17 years ago - markus@cvs.openbsd.org 2006/06/08 14:45:49
djm [Tue, 13 Jun 2006 03:10:00 +0000 (03:10 +0000)] 
   - markus@cvs.openbsd.org 2006/06/08 14:45:49
     [readpass.c sshconnect.c sshconnect2.c uidswap.c uidswap.h]
     do not set the gid, noted by solar; ok djm

17 years ago - markus@cvs.openbsd.org 2006/06/06 10:20:20
djm [Tue, 13 Jun 2006 03:05:15 +0000 (03:05 +0000)] 
   - markus@cvs.openbsd.org 2006/06/06 10:20:20
     [readpass.c sshconnect.c sshconnect.h sshconnect2.c uidswap.c]
     replace remaining setuid() calls with permanently_set_uid() and
     check seteuid() return values; report Marcus Meissner; ok dtucker djm

17 years ago - markus@cvs.openbsd.org 2006/06/01 09:21:48
djm [Tue, 13 Jun 2006 03:03:53 +0000 (03:03 +0000)] 
   - markus@cvs.openbsd.org 2006/06/01 09:21:48
     [sshd.c]
     call get_remote_ipaddr() early; fixes logging after client disconnects;
     report mpf@; ok dtucker@

17 years ago - mk@cvs.openbsd.org 2006/05/30 11:46:38
djm [Tue, 13 Jun 2006 03:03:34 +0000 (03:03 +0000)] 
   - mk@cvs.openbsd.org 2006/05/30 11:46:38
     [ssh-add.c]
     Sync usage() with man page and reality.
     ok deraadt dtucker

17 years ago - jmc@cvs.openbsd.org 2006/05/29 16:13:23
djm [Tue, 13 Jun 2006 03:03:16 +0000 (03:03 +0000)] 
   - jmc@cvs.openbsd.org 2006/05/29 16:13:23
     [ssh.1]
     add GSSAPI to the list of authentication methods supported;

17 years ago - jmc@cvs.openbsd.org 2006/05/29 16:10:03
djm [Tue, 13 Jun 2006 03:01:41 +0000 (03:01 +0000)] 
   - jmc@cvs.openbsd.org 2006/05/29 16:10:03
     [ssh_config.5]
     oops - previous was too long; split the list of auths up

17 years ago - dtucker@cvs.openbsd.org 2006/05/29 12:56:33
djm [Tue, 13 Jun 2006 03:01:09 +0000 (03:01 +0000)] 
   - dtucker@cvs.openbsd.org 2006/05/29 12:56:33
     [ssh_config]
     Add GSSAPIAuthentication and GSSAPIDelegateCredentials to examples in sample
     ssh_config.  ok markus@

17 years ago - dtucker@cvs.openbsd.org 2006/05/29 12:54:08
djm [Tue, 13 Jun 2006 03:00:55 +0000 (03:00 +0000)] 
   - dtucker@cvs.openbsd.org 2006/05/29 12:54:08
     [ssh_config.5]
     Add gssapi-with-mic to PreferredAuthentications default list; ok jmc

17 years ago - miod@cvs.openbsd.org 2006/05/18 21:27:25
djm [Tue, 13 Jun 2006 03:00:41 +0000 (03:00 +0000)] 
   - miod@cvs.openbsd.org 2006/05/18 21:27:25
     [kexdhc.c kexgexc.c]
     paramter -> parameter

17 years ago - markus@cvs.openbsd.org 2006/05/17 12:43:34
djm [Tue, 13 Jun 2006 03:00:25 +0000 (03:00 +0000)] 
   - markus@cvs.openbsd.org 2006/05/17 12:43:34
     [scp.c sftp.c ssh-agent.c ssh-keygen.c sshconnect.c]
     fix leak; coverity via Kylene Jo Hall

17 years ago - markus@cvs.openbsd.org 2006/05/16 09:00:00
djm [Tue, 13 Jun 2006 03:00:09 +0000 (03:00 +0000)] 
   - markus@cvs.openbsd.org 2006/05/16 09:00:00
     [clientloop.c]
     missing free; from Kylene Hall

17 years ago - djm@cvs.openbsd.org 2006/05/08 10:49:48
djm [Tue, 13 Jun 2006 02:59:53 +0000 (02:59 +0000)] 
   - djm@cvs.openbsd.org 2006/05/08 10:49:48
     [sshconnect2.c]
     uint32_t -> u_int32_t (which we use everywhere else)
     (Id sync only - portable already had this)

18 years ago - (dtucker) [auth.c monitor.c] Now that we don't log from both the monitor
dtucker [Sun, 21 May 2006 08:26:40 +0000 (08:26 +0000)] 
 - (dtucker) [auth.c monitor.c] Now that we don't log from both the monitor
   and slave, we can remove the special-case handling in the audit hook in
   auth_log.

18 years ago - (dtucker) [ssh-rand-helper.c] Check return code of mkdir and fix file
dtucker [Wed, 17 May 2006 12:24:56 +0000 (12:24 +0000)] 
 - (dtucker) [ssh-rand-helper.c] Check return code of mkdir and fix file
   pointer leak.  From kjhall at us.ibm.com, found by coverity.

18 years agotypo
dtucker [Mon, 15 May 2006 07:24:25 +0000 (07:24 +0000)] 
typo

18 years ago - (dtucker) [auth-pam.c] Bug #1188: pass result of do_pam_account back and
dtucker [Mon, 15 May 2006 07:22:33 +0000 (07:22 +0000)] 
 - (dtucker) [auth-pam.c] Bug #1188: pass result of do_pam_account back and
   do not allow kbdint again after the PAM account check fails.  ok djm@

18 years ago - (dtucker) [defines.h] Find a value for IOV_MAX or use a conservative
dtucker [Mon, 15 May 2006 07:17:29 +0000 (07:17 +0000)] 
 - (dtucker) [defines.h] Find a value for IOV_MAX or use a conservative
   default.  Patch originally from tim@, ok djm

18 years ago - (dtucker) [openbsd-compat/getrrsetbyname.c] Use _compat_res instead of
dtucker [Mon, 15 May 2006 07:15:56 +0000 (07:15 +0000)] 
 - (dtucker) [openbsd-compat/getrrsetbyname.c] Use _compat_res instead of
   _res, prevents problems on some platforms that have _res as a global but
   don't have getrrsetbyname(), eg IRIX 5.3.  Found and tested by
   georg.schwarz at freenet.de, ok djm@.

18 years ago - dtucker@cvs.openbsd.org 2006/05/06 08:35:40
dtucker [Sat, 6 May 2006 08:40:53 +0000 (08:40 +0000)] 
   - dtucker@cvs.openbsd.org 2006/05/06 08:35:40
     [auth-krb5.c]
     Add $OpenBSD$ in comment here too

18 years ago - djm@cvs.openbsd.org 2006/04/01 05:37:46
dtucker [Sat, 6 May 2006 07:48:48 +0000 (07:48 +0000)] 
   - djm@cvs.openbsd.org 2006/04/01 05:37:46
     [OVERVIEW]
     $OpenBSD$ in here too

18 years ago - djm@cvs.openbsd.org 2006/05/04 14:55:23
dtucker [Sat, 6 May 2006 07:43:33 +0000 (07:43 +0000)] 
   - djm@cvs.openbsd.org 2006/05/04 14:55:23
     [dh.c]
     tighter DH exponent checks here too; feedback and ok markus@

18 years ago - dtucker@cvs.openbsd.org 2006/04/25 08:02:27
dtucker [Sat, 6 May 2006 07:41:51 +0000 (07:41 +0000)] 
   - dtucker@cvs.openbsd.org 2006/04/25 08:02:27
     [authfile.c authfile.h sshconnect2.c ssh.c sshconnect1.c]
     Prevent ssh from trying to open private keys with bad permissions more than
     once or prompting for their passphrases (which it subsequently ignores
     anyway), similar to a previous change in ssh-add.  bz #1186, ok djm@

18 years ago - (dtucker) [auth-pam.c groupaccess.c monitor.c monitor_wrap.c scard-opensc.c
dtucker [Thu, 4 May 2006 06:24:34 +0000 (06:24 +0000)] 
 - (dtucker) [auth-pam.c groupaccess.c monitor.c monitor_wrap.c scard-opensc.c
   session.c ssh-rand-helper.c sshd.c openbsd-compat/bsd-cygwin_util.c
   openbsd-compat/setproctitle.c] Convert malloc(foo*bar) -> calloc(foo,bar)
   in Portable-only code; since calloc zeros, remove now-redundant memsets.
   Also add a couple of sanity checks.  With & ok djm@

18 years ago - (dtucker) [packet.c] Remove in_systm.h since it's also in includes.h
dtucker [Wed, 3 May 2006 09:01:09 +0000 (09:01 +0000)] 
 - (dtucker) [packet.c] Remove in_systm.h since it's also in includes.h
   and double including it on IRIX 5.3 causes problems.  From Georg Schwarz,
   "no objections" tim@

18 years agomissing file
djm [Sun, 23 Apr 2006 02:31:27 +0000 (02:31 +0000)] 
missing file

18 years ago - (djm) [auth.h dispatch.h kex.h] sprinkle in signal.h to get
djm [Sun, 23 Apr 2006 02:28:53 +0000 (02:28 +0000)] 
 - (djm) [auth.h dispatch.h kex.h] sprinkle in signal.h to get
   sig_atomic_t

18 years ago - dtucker@cvs.openbsd.org 2006/04/18 10:44:28
djm [Sun, 23 Apr 2006 02:15:08 +0000 (02:15 +0000)] 
   - dtucker@cvs.openbsd.org 2006/04/18 10:44:28
     [bufaux.c bufbn.c Makefile.in]
     Move Buffer bignum functions into their own file, bufbn.c. This means
     that sftp and sftp-server (which use the Buffer functions in bufaux.c
     but not the bignum ones) no longer need to be linked with libcrypto.
     ok markus@

18 years ago - stevesk@cvs.openbsd.org 2006/04/22 18:29:33
djm [Sun, 23 Apr 2006 02:12:24 +0000 (02:12 +0000)] 
   - stevesk@cvs.openbsd.org 2006/04/22 18:29:33
     [crc32.c]
     remove extra spaces

18 years ago - djm@cvs.openbsd.org 2006/04/22 04:06:51
djm [Sun, 23 Apr 2006 02:11:57 +0000 (02:11 +0000)] 
   - djm@cvs.openbsd.org 2006/04/22 04:06:51
     [uidswap.c]
     use setres[ug]id() to permanently revoke privileges; ok deraadt@
     (ID Sync only - portable already uses setres[ug]id() whenever possible)

18 years ago - djm@cvs.openbsd.org 2006/04/20 21:53:44
djm [Sun, 23 Apr 2006 02:10:49 +0000 (02:10 +0000)] 
   - djm@cvs.openbsd.org 2006/04/20 21:53:44
     [includes.h session.c sftp.c]
     Switch from using pipes to socketpairs for communication between
     sftp/scp and ssh, and between sshd and its subprocesses. This saves
     a file descriptor per session and apparently makes userland ppp over
     ssh work; ok markus@ deraadt@ (ID Sync only - portable makes this
     decision on a per-platform basis)

18 years ago - markus@cvs.openbsd.org 2006/04/20 09:47:59
djm [Sun, 23 Apr 2006 02:08:59 +0000 (02:08 +0000)] 
   - markus@cvs.openbsd.org 2006/04/20 09:47:59
     [sshconnect.c]
     simplify; ok djm@

18 years ago - djm@cvs.openbsd.org 2006/04/20 09:27:09
djm [Sun, 23 Apr 2006 02:08:37 +0000 (02:08 +0000)] 
   - djm@cvs.openbsd.org 2006/04/20 09:27:09
     [auth.h clientloop.c dispatch.c dispatch.h kex.h]
     replace the last non-sig_atomic_t flag used in a signal handler with a
     sig_atomic_t, unfortunately with some knock-on effects in other (non-
     signal) contexts in which it is used; ok markus@

18 years ago - dtucker@cvs.openbsd.org 2006/04/18 10:44:28
djm [Sun, 23 Apr 2006 02:08:19 +0000 (02:08 +0000)] 
   - dtucker@cvs.openbsd.org 2006/04/18 10:44:28
     [bufaux.c bufbn.c]
     Move Buffer bignum functions into their own file, bufbn.c. This means
     that sftp and sftp-server (which use the Buffer functions in bufaux.c
     but not the bignum ones) no longer need to be linked with libcrypto.
     ok markus@

18 years ago - djm@cvs.openbsd.org 2006/04/16 07:59:00
djm [Sun, 23 Apr 2006 02:06:49 +0000 (02:06 +0000)] 
   - djm@cvs.openbsd.org 2006/04/16 07:59:00
     [atomicio.c]
     reorder sanity test so that it cannot dereference past the end of the
     iov array; well spotted canacar@!

18 years ago - djm@cvs.openbsd.org 2006/04/16 00:54:10
djm [Sun, 23 Apr 2006 02:06:35 +0000 (02:06 +0000)] 
   - djm@cvs.openbsd.org 2006/04/16 00:54:10
     [sftp-client.c]
     avoid making a tiny 4-byte write to send the packet length of sftp
     commands, which would result in a separate tiny packet on the wire by
     using atomiciov(writev, ...) to write the length and the command in one
     pass; ok deraadt@

18 years ago - djm@cvs.openbsd.org 2006/04/16 00:52:55
djm [Sun, 23 Apr 2006 02:06:20 +0000 (02:06 +0000)] 
   - djm@cvs.openbsd.org 2006/04/16 00:52:55
     [atomicio.c atomicio.h]
     introduce atomiciov() function that wraps readv/writev to retry
     interrupted transfers like atomicio() does for read/write;
     feedback deraadt@ dtucker@ stevesk@ ok deraadt@

18 years ago - djm@cvs.openbsd.org 2006/04/16 00:48:52
djm [Sun, 23 Apr 2006 02:06:03 +0000 (02:06 +0000)] 
   - djm@cvs.openbsd.org 2006/04/16 00:48:52
     [buffer.c buffer.h channels.c]
     Fix condition where we could exit with a fatal error when an input
     buffer became too large and the remote end had advertised a big window.
     The problem was a mismatch in the backoff math between the channels code
     and the buffer code, so make a buffer_check_alloc() function that the
     channels code can use to propsectivly check whether an incremental
     allocation will succeed.  bz #1131, debugged with the assistance of
     cove AT wildpackets.com; ok dtucker@ deraadt@

18 years ago - djm@cvs.openbsd.org 2006/04/03 07:10:38
djm [Sun, 23 Apr 2006 02:05:46 +0000 (02:05 +0000)] 
   - djm@cvs.openbsd.org 2006/04/03 07:10:38
     [gss-genr.c]
     GSSAPI buffers shouldn't be nul-terminated, spotted in bugzilla #1066
     by dleonard AT vintela.com. use xasprintf() to simplify code while in
     there; "looks right" deraadt@

18 years ago - dtucker@cvs.openbsd.org 2006/04/02 08:34:52
djm [Sun, 23 Apr 2006 02:05:32 +0000 (02:05 +0000)] 
   - dtucker@cvs.openbsd.org 2006/04/02 08:34:52
     [ssh-keysign.c]
     sessionid can be 32 bytes now too when sha256 kex is used; ok djm@

18 years ago - djm@cvs.openbsd.org 2006/04/01 05:51:34
djm [Sun, 23 Apr 2006 02:05:16 +0000 (02:05 +0000)] 
   - djm@cvs.openbsd.org 2006/04/01 05:51:34
     [atomicio.c]
     ANSIfy; requested deraadt@

18 years ago - djm@cvs.openbsd.org 2006/04/01 05:50:29
djm [Sun, 23 Apr 2006 02:04:46 +0000 (02:04 +0000)] 
   - djm@cvs.openbsd.org 2006/04/01 05:50:29
     [scp.c]
     xasprintification; ok deraadt@

18 years ago - (djm) OpenBSD CVS Sync
djm [Sun, 23 Apr 2006 02:04:27 +0000 (02:04 +0000)] 
 - (djm) OpenBSD CVS Sync
   - deraadt@cvs.openbsd.org 2006/04/01 05:42:20
     [scp.c]
     minimal lint cleanup (unused crud, and some size_t); ok djm

18 years ago - (djm) [Makefile.in configure.ac session.c sshpty.c]
djm [Sat, 22 Apr 2006 11:26:08 +0000 (11:26 +0000)] 
 - (djm) [Makefile.in configure.ac session.c sshpty.c]
   [contrib/redhat/sshd.init openbsd-compat/Makefile.in]
   [openbsd-compat/openbsd-compat.h openbsd-compat/port-linux.c]
   [openbsd-compat/port-linux.h] Add support for SELinux, setting
   the execution and TTY contexts. based on patch from Daniel Walsh,
   bz #880; ok dtucker@

18 years ago - (djm) Reorder IP options check so that it isn't broken by
djm [Tue, 18 Apr 2006 05:13:16 +0000 (05:13 +0000)] 
 - (djm) Reorder IP options check so that it isn't broken by
   mapped addresses; bz #1179 reported by markw wtech-llc.com;
   ok dtucker@

18 years ago - djm@cvs.openbsd.org 2006/03/31 09:13:56
djm [Fri, 31 Mar 2006 12:14:57 +0000 (12:14 +0000)] 
   - djm@cvs.openbsd.org 2006/03/31 09:13:56
     [ssh_config.5]
     remote user escape is %r not %h; spotted by jmc@

18 years ago - jmc@cvs.openbsd.org 2006/03/31 09:09:30
djm [Fri, 31 Mar 2006 12:14:41 +0000 (12:14 +0000)] 
   - jmc@cvs.openbsd.org 2006/03/31 09:09:30
     [ssh_config.5]
     kill trailing whitespace;

18 years ago - dtucker@cvs.openbsd.org 2006/03/30 11:40:21
djm [Fri, 31 Mar 2006 12:14:23 +0000 (12:14 +0000)] 
   - dtucker@cvs.openbsd.org 2006/03/30 11:40:21
     [auth.c monitor.c]
     Prevent duplicate log messages when privsep=yes; ok djm@

18 years ago - dtucker@cvs.openbsd.org 2006/03/30 11:05:17
djm [Fri, 31 Mar 2006 12:13:35 +0000 (12:13 +0000)] 
   - dtucker@cvs.openbsd.org 2006/03/30 11:05:17
     [ssh-keygen.c]
     Correctly handle truncated files while converting keys; ok djm@

18 years ago - djm@cvs.openbsd.org 2006/03/30 10:41:25
djm [Fri, 31 Mar 2006 12:13:21 +0000 (12:13 +0000)] 
   - djm@cvs.openbsd.org 2006/03/30 10:41:25
     [ssh.c ssh_config.5]
     add percent escape chars to the IdentityFile option, bz #1159 based
     on a patch by imaging AT math.ualberta.ca; feedback and ok dtucker@

18 years ago - djm@cvs.openbsd.org 2006/03/30 09:58:16
djm [Fri, 31 Mar 2006 12:13:02 +0000 (12:13 +0000)] 
   - djm@cvs.openbsd.org 2006/03/30 09:58:16
     [authfd.c bufaux.c deattack.c gss-serv.c mac.c misc.c misc.h]
     [monitor_wrap.c msg.c packet.c sftp-client.c sftp-server.c ssh-agent.c]
     replace {GET,PUT}_XXBIT macros with functionally similar functions,
     silencing a heap of lint warnings. also allows them to use
     __bounded__ checking which can't be applied to macros; requested
     by and feedback from deraadt@

18 years ago - djm@cvs.openbsd.org 2006/03/30 09:41:25
djm [Fri, 31 Mar 2006 12:11:44 +0000 (12:11 +0000)] 
   - djm@cvs.openbsd.org 2006/03/30 09:41:25
     [channels.c]
     ARGSUSED for dispatch table-driven functions

18 years ago - deraadt@cvs.openbsd.org 2006/03/28 01:53:43
djm [Fri, 31 Mar 2006 12:11:28 +0000 (12:11 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/28 01:53:43
     [ssh-agent.c]
     use strtonum() to parse the pid from the file, and range check it
     better; ok djm

18 years ago - deraadt@cvs.openbsd.org 2006/03/28 01:52:28
djm [Fri, 31 Mar 2006 12:11:07 +0000 (12:11 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/28 01:52:28
     [channels.c]
     do not accept unreasonable X ports numbers; ok djm

18 years ago - deraadt@cvs.openbsd.org 2006/03/28 00:12:31
djm [Fri, 31 Mar 2006 12:10:51 +0000 (12:10 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/28 00:12:31
     [README.tun ssh.c]
     spacing

18 years ago - djm@cvs.openbsd.org 2006/03/27 23:15:46
djm [Fri, 31 Mar 2006 12:10:31 +0000 (12:10 +0000)] 
   - djm@cvs.openbsd.org 2006/03/27 23:15:46
     [sftp.c]
     always use a format string for addargs; spotted by mouring@

18 years ago - deraadt@cvs.openbsd.org 2006/03/27 13:03:54
djm [Fri, 31 Mar 2006 12:09:41 +0000 (12:09 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/27 13:03:54
     [dh.c]
     use strtonum() instead of atoi(), limit dhg size to 64k; ok djm

18 years ago - OpenBSD CVS Sync
djm [Fri, 31 Mar 2006 12:09:17 +0000 (12:09 +0000)] 
 - OpenBSD CVS Sync
   - deraadt@cvs.openbsd.org 2006/03/27 01:21:18
     [xmalloc.c]
     we can do the size & nmemb check before the integer overflow check;
     evol

18 years ago - deraadt@cvs.openbsd.org 2006/03/26 01:31:48
djm [Sun, 26 Mar 2006 03:30:33 +0000 (03:30 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/26 01:31:48
     [uuencode.c]
     typo

18 years ago - djm@cvs.openbsd.org 2006/03/25 22:22:43
djm [Sun, 26 Mar 2006 03:30:00 +0000 (03:30 +0000)] 
   - djm@cvs.openbsd.org 2006/03/25 22:22:43
     [atomicio.h auth-options.h auth.h auth2-gss.c authfd.h authfile.h]
     [bufaux.h buffer.h canohost.h channels.h cipher.h clientloop.h]
     [compat.h compress.h crc32.c crc32.h deattack.h dh.h dispatch.h]
     [dns.c dns.h getput.h groupaccess.h gss-genr.c gss-serv-krb5.c]
     [gss-serv.c hostfile.h includes.h kex.h key.h log.h mac.h match.h]
     [misc.h monitor.h monitor_fdpass.h monitor_mm.h monitor_wrap.h msg.h]
     [myproposal.h packet.h pathnames.h progressmeter.h readconf.h rsa.h]
     [scard.h servconf.h serverloop.h session.h sftp-common.h sftp.h]
     [ssh-gss.h ssh.h ssh1.h ssh2.h sshconnect.h sshlogin.h sshpty.h]
     [ttymodes.h uidswap.h uuencode.h xmalloc.h]
     standardise spacing in $OpenBSD$ tags; requested by deraadt@

18 years ago - deraadt@cvs.openbsd.org 2006/03/25 18:58:10
djm [Sun, 26 Mar 2006 03:29:06 +0000 (03:29 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/25 18:58:10
     [channels.c]
     delete cast not required

18 years ago - deraadt@cvs.openbsd.org 2006/03/25 18:56:55
djm [Sun, 26 Mar 2006 03:28:50 +0000 (03:28 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/25 18:56:55
     [bufaux.c channels.c packet.c]
     remove (char *) casts to a function that accepts void * for the arg

18 years ago - deraadt@cvs.openbsd.org 2006/03/25 18:43:30
djm [Sun, 26 Mar 2006 03:28:32 +0000 (03:28 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/25 18:43:30
     [channels.c]
     use strtonum() instead of atoi() [limit X screens to 400, sorry]

18 years ago - deraadt@cvs.openbsd.org 2006/03/25 18:41:45
djm [Sun, 26 Mar 2006 03:28:14 +0000 (03:28 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/25 18:41:45
     [ssh-agent.c]
     mark two more signal handlers ARGSUSED

18 years ago - deraadt@cvs.openbsd.org 2006/03/25 18:40:14
djm [Sun, 26 Mar 2006 03:27:57 +0000 (03:27 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/25 18:40:14
     [ssh-keygen.c]
     cast strtonum() result to right type

18 years ago - deraadt@cvs.openbsd.org 2006/03/25 18:36:15
djm [Sun, 26 Mar 2006 03:27:35 +0000 (03:27 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/25 18:36:15
     [sshlogin.c sshlogin.h]
     nicer size_t and time_t types

18 years ago - deraadt@cvs.openbsd.org 2006/03/25 18:30:55
djm [Sun, 26 Mar 2006 03:25:37 +0000 (03:25 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/25 18:30:55
     [clientloop.c serverloop.c]
     spacing

18 years ago - deraadt@cvs.openbsd.org 2006/03/25 18:29:35
djm [Sun, 26 Mar 2006 03:25:19 +0000 (03:25 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/25 18:29:35
     [auth-rsa.c authfd.c packet.c]
     needed casts (always will be needed)

18 years agooops, rewrap
djm [Sun, 26 Mar 2006 03:25:05 +0000 (03:25 +0000)] 
oops, rewrap

18 years ago - djm@cvs.openbsd.org 2006/03/25 13:17:03
djm [Sun, 26 Mar 2006 03:24:48 +0000 (03:24 +0000)] 
   - djm@cvs.openbsd.org 2006/03/25 13:17:03
     [atomicio.c auth-bsdauth.c auth-chall.c auth-options.c auth-passwd.c]
     [auth-rh-rsa.c auth-rhosts.c auth-rsa.c auth-skey.c auth.c auth1.c]
     [auth2-chall.c auth2-hostbased.c auth2-kbdint.c auth2-none.c]
     [auth2-passwd.c auth2-pubkey.c auth2.c authfd.c authfile.c bufaux.c]
     [buffer.c canohost.c channels.c cipher-3des1.c cipher-bf1.c]
     [cipher-ctr.c cipher.c cleanup.c clientloop.c compat.c compress.c]
     [deattack.c dh.c dispatch.c fatal.c groupaccess.c hostfile.c kex.c]
     [kexdh.c kexdhc.c kexdhs.c kexgex.c kexgexc.c kexgexs.c key.c log.c]
     [mac.c match.c md-sha256.c misc.c monitor.c monitor_fdpass.c]
     [monitor_mm.c monitor_wrap.c msg.c nchan.c packet.c progressmeter.c]
     [readconf.c readpass.c rsa.c scard.c scp.c servconf.c serverloop.c]
     [session.c sftp-client.c sftp-common.c sftp-glob.c sftp-server.c]
     [sftp.c ssh-add.c ssh-agent.c ssh-dss.c ssh-keygen.c ssh-keyscan.c]
     [ssh-keysign.c ssh-rsa.c ssh.c sshconnect.c sshconnect1.c]
     [sshconnect2.c sshd.c sshlogin.c sshpty.c sshtty.c ttymodes.c]
     [uidswap.c uuencode.c xmalloc.c]
     Put $OpenBSD$ tags back (as comments) to replace the RCSID()s that
     Theo nuked - our scripts to sync -portable need them in the files

18 years ago - djm@cvs.openbsd.org 2006/03/25 01:30:23
djm [Sun, 26 Mar 2006 03:23:17 +0000 (03:23 +0000)] 
   - djm@cvs.openbsd.org 2006/03/25 01:30:23
     [sftp.c]
     "abormally" is a perfectly cromulent word, but "abnormally" is better

18 years ago - djm@cvs.openbsd.org 2006/03/25 01:13:23
djm [Sun, 26 Mar 2006 03:22:47 +0000 (03:22 +0000)] 
   - djm@cvs.openbsd.org 2006/03/25 01:13:23
     [buffer.c channels.c deattack.c misc.c scp.c session.c sftp-client.c]
     [sftp-server.c ssh-agent.c ssh-rsa.c xmalloc.c xmalloc.h auth-pam.c]
     [uidswap.c]
     change OpenSSH's xrealloc() function from being xrealloc(p, new_size)
     to xrealloc(p, new_nmemb, new_itemsize).

     realloc is particularly prone to integer overflows because it is
     almost always allocating "n * size" bytes, so this is a far safer
     API; ok deraadt@

18 years ago - djm@cvs.openbsd.org 2006/03/25 00:05:41
djm [Sun, 26 Mar 2006 03:19:21 +0000 (03:19 +0000)] 
   - djm@cvs.openbsd.org 2006/03/25 00:05:41
     [auth-bsdauth.c auth-skey.c auth.c auth2-chall.c channels.c]
     [clientloop.c deattack.c gss-genr.c kex.c key.c misc.c moduli.c]
     [monitor.c monitor_wrap.c packet.c scard.c sftp-server.c ssh-agent.c]
     [ssh-keyscan.c ssh.c sshconnect.c sshconnect2.c sshd.c uuencode.c]
     [xmalloc.c xmalloc.h]
     introduce xcalloc() and xasprintf() failure-checked allocations
     functions and use them throughout openssh

     xcalloc is particularly important because malloc(nmemb * size) is a
     dangerous idiom (subject to integer overflow) and it is time for it
     to die

     feedback and ok deraadt@

18 years ago - djm@cvs.openbsd.org 2006/03/22 21:27:15
djm [Sun, 26 Mar 2006 03:11:39 +0000 (03:11 +0000)] 
   - djm@cvs.openbsd.org 2006/03/22 21:27:15
     [deattack.c deattack.h packet.c]
     remove IV support from the CRC attack detector, OpenSSH has never used
     it - it only applied to IDEA-CFB, which we don't support.
     prompted by NetBSD Coverity report via elad AT netbsd.org;
     feedback markus@ "nuke it" deraadt@

18 years ago - deraadt@cvs.openbsd.org 2006/03/20 21:11:53
djm [Sun, 26 Mar 2006 03:10:34 +0000 (03:10 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/20 21:11:53
     [ttymodes.c]
     spacing

18 years ago - deraadt@cvs.openbsd.org 2006/03/20 18:48:34
djm [Sun, 26 Mar 2006 03:10:14 +0000 (03:10 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/20 18:48:34
     [channels.c fatal.c kex.c packet.c serverloop.c]
     spacing

18 years ago - deraadt@cvs.openbsd.org 2006/03/20 18:42:27
djm [Sun, 26 Mar 2006 03:09:54 +0000 (03:09 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/20 18:42:27
     [canohost.c match.c ssh.c sshconnect.c]
     be strict with tolower() casting

18 years ago - deraadt@cvs.openbsd.org 2006/03/20 18:41:43
djm [Sun, 26 Mar 2006 03:09:09 +0000 (03:09 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/20 18:41:43
     [dns.c]
     cast xstrdup to propert u_char *

18 years ago - deraadt@cvs.openbsd.org 2006/03/20 18:35:12
djm [Sun, 26 Mar 2006 03:08:10 +0000 (03:08 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/20 18:35:12
     [channels.c]
     x11_fake_data is only ever used as u_char *

18 years ago - deraadt@cvs.openbsd.org 2006/03/20 18:27:50
djm [Sun, 26 Mar 2006 03:07:52 +0000 (03:07 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/20 18:27:50
     [monitor.c]
     spacing

18 years ago - deraadt@cvs.openbsd.org 2006/03/20 18:26:55
djm [Sun, 26 Mar 2006 03:07:26 +0000 (03:07 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/20 18:26:55
     [channels.c monitor.c session.c session.h ssh-agent.c ssh-keygen.c]
     [ssh-rsa.c ssh.c sshlogin.c]
     annoying spacing fixes getting in the way of real diffs

18 years ago - deraadt@cvs.openbsd.org 2006/03/20 18:17:20
djm [Sun, 26 Mar 2006 03:05:20 +0000 (03:05 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/20 18:17:20
     [auth1.c auth2.c sshd.c]
     sprinkle some ARGSUSED for table driven functions (which sometimes
     must ignore their args)

18 years agorewrap
djm [Sun, 26 Mar 2006 03:05:02 +0000 (03:05 +0000)] 
rewrap

18 years ago - deraadt@cvs.openbsd.org 2006/03/20 18:14:02
djm [Sun, 26 Mar 2006 03:04:36 +0000 (03:04 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/20 18:14:02
     [channels.c clientloop.c monitor_wrap.c monitor_wrap.h serverloop.c]
     [ssh.c sshpty.c sshpty.h]
     sprinkle u_int throughout pty subsystem, ok markus

18 years ago - deraadt@cvs.openbsd.org 2006/03/20 17:17:23
djm [Sun, 26 Mar 2006 03:03:21 +0000 (03:03 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/20 17:17:23
     [ssh-rsa.c]
     in a switch (), break after return or goto is stupid

18 years ago - deraadt@cvs.openbsd.org 2006/03/20 17:13:16
djm [Sun, 26 Mar 2006 03:03:03 +0000 (03:03 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/20 17:13:16
     [key.c]
     djm did a typo

18 years ago - deraadt@cvs.openbsd.org 2006/03/20 17:10:19
djm [Sun, 26 Mar 2006 03:02:35 +0000 (03:02 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/20 17:10:19
     [auth.c key.c misc.c packet.c ssh-add.c]
     in a switch (), break after return or goto is stupid

18 years ago - djm@cvs.openbsd.org 2006/03/20 11:38:46
djm [Sun, 26 Mar 2006 03:02:16 +0000 (03:02 +0000)] 
   - djm@cvs.openbsd.org 2006/03/20 11:38:46
     [key.c]
     (really) last of the Coverity diffs: avoid possible NULL deref in
     key_free. via elad AT netbsd.org; markus@ ok

18 years ago - djm@cvs.openbsd.org 2006/03/20 04:09:44
djm [Sun, 26 Mar 2006 03:01:54 +0000 (03:01 +0000)] 
   - djm@cvs.openbsd.org 2006/03/20 04:09:44
     [monitor.c]
     memory leaks detected by Coverity via elad AT netbsd.org;
     deraadt@ ok
     that should be all of them now

18 years ago - deraadt@cvs.openbsd.org 2006/03/19 18:59:09
djm [Sun, 26 Mar 2006 03:00:31 +0000 (03:00 +0000)] 
   - deraadt@cvs.openbsd.org 2006/03/19 18:59:09
     [authfile.c]
     whoever thought that break after return was a good idea needs to
     get their head examimed

This page took 0.087535 seconds and 4 git commands to generate.