]> andersk Git - openssh.git/log
openssh.git
14 years ago - djm@cvs.openbsd.org 2010/01/09 00:57:10
dtucker [Sat, 9 Jan 2010 11:25:14 +0000 (11:25 +0000)] 
   - djm@cvs.openbsd.org 2010/01/09 00:57:10
     [PROTOCOL]
     tweak language

14 years ago - djm@cvs.openbsd.org 2010/01/09 00:20:26
dtucker [Sat, 9 Jan 2010 11:24:33 +0000 (11:24 +0000)] 
   - djm@cvs.openbsd.org 2010/01/09 00:20:26
     [sftp-server.c sftp-server.8]
     add a 'read-only' mode to sftp-server(8) that disables open in write mode
     and all other fs-modifying protocol methods. bz#430 ok dtucker@

14 years ago - (dtucker) [loginrec.c] Use the SUSv3 specified name for the user name
dtucker [Sat, 9 Jan 2010 07:18:04 +0000 (07:18 +0000)] 
 - (dtucker) [loginrec.c] Use the SUSv3 specified name for the user name
   when using utmpx.  Patch from Ed Schouten.

14 years ago - (dtucker) [roaming_client.c] Wrap inttypes.h in an ifdef.
dtucker [Sat, 9 Jan 2010 05:40:48 +0000 (05:40 +0000)] 
 - (dtucker) [roaming_client.c] Wrap inttypes.h in an ifdef.

14 years ago - (dtucker) [defines.h] define PRIu64 for platforms that don't have it.
dtucker [Fri, 8 Jan 2010 22:25:54 +0000 (22:25 +0000)] 
 - (dtucker) [defines.h] define PRIu64 for platforms that don't have it.

14 years ago - (dtucker) Wrap use of IPPROTO_IPV6 in an ifdef for platforms that don't
dtucker [Fri, 8 Jan 2010 22:02:07 +0000 (22:02 +0000)] 
 - (dtucker) Wrap use of IPPROTO_IPV6 in an ifdef for platforms that don't
   have it.

14 years ago - dtucker@cvs.openbsd.org 2010/01/08 21:50:49
dtucker [Fri, 8 Jan 2010 21:54:31 +0000 (21:54 +0000)] 
   - dtucker@cvs.openbsd.org 2010/01/08 21:50:49
     [sftp.c]
     Fix two warnings: possibly used unitialized and use a nul byte instead of
     NULL pointer.  ok djm@

14 years ago - (dtucker) [roaming_serv.c] Include includes.h for u_intXX_t types.
dtucker [Fri, 8 Jan 2010 09:45:42 +0000 (09:45 +0000)] 
 - (dtucker) [roaming_serv.c] Include includes.h for u_intXX_t types.

14 years ago - (dtucker] [misc.c] Shrink the area covered by USE_ROUTINGDOMAIN more
dtucker [Fri, 8 Jan 2010 09:09:01 +0000 (09:09 +0000)] 
 - (dtucker] [misc.c] Shrink the area covered by USE_ROUTINGDOMAIN more
   to eliminate an unused variable warning.

14 years ago - (dtucker) [misc.c] Move the routingdomain ifdef to allow the socket to
dtucker [Fri, 8 Jan 2010 09:03:56 +0000 (09:03 +0000)] 
 - (dtucker) [misc.c] Move the routingdomain ifdef to allow the socket to
   be created.

14 years ago - (dtucker) [sftp.c] Expand ifdef for libedit to cover complete_is_remote
dtucker [Fri, 8 Jan 2010 08:56:33 +0000 (08:56 +0000)] 
 - (dtucker) [sftp.c] Expand ifdef for libedit to cover complete_is_remote
   too.

14 years ago - (dtucker) [configure.ac misc.c readconf.c servconf.c ssh-keyscan.c] Make
dtucker [Fri, 8 Jan 2010 08:53:52 +0000 (08:53 +0000)] 
 - (dtucker) [configure.ac misc.c readconf.c servconf.c ssh-keyscan.c] Make
   RoutingDomain an unsupported option on platforms that don't have it.

14 years ago - (dtucker) [sftp.c] ifdef out the sftp completion bits for platforms that
dtucker [Fri, 8 Jan 2010 08:50:02 +0000 (08:50 +0000)] 
 - (dtucker) [sftp.c] ifdef out the sftp completion bits for platforms that
   don't have libedit.

14 years ago - (dtucker) [Makefile.in] .c files do not belong in the OBJ lines.
dtucker [Fri, 8 Jan 2010 08:27:57 +0000 (08:27 +0000)] 
 - (dtucker) [Makefile.in] .c files do not belong in the OBJ lines.

14 years ago - (dtucker) [Makefile.in added roaming_client.c roaming_serv.c] Import new
dtucker [Fri, 8 Jan 2010 08:13:25 +0000 (08:13 +0000)] 
 - (dtucker) [Makefile.in added roaming_client.c roaming_serv.c] Import new
   files for roaming and add to Makefile.

14 years ago - djm@cvs.openbsd.org 2010/01/04 02:25:15
dtucker [Fri, 8 Jan 2010 08:04:49 +0000 (08:04 +0000)] 
   - djm@cvs.openbsd.org 2010/01/04 02:25:15
     [sftp-server.c]
     bz#1566 don't unnecessarily dup() in and out fds for sftp-server;
     ok markus@

14 years ago - djm@cvs.openbsd.org 2010/01/04 02:03:57
dtucker [Fri, 8 Jan 2010 08:02:40 +0000 (08:02 +0000)] 
   - djm@cvs.openbsd.org 2010/01/04 02:03:57
     [sftp.c]
     Implement tab-completion of commands, local and remote filenames for sftp.
     Hacked on and off for some time by myself, mouring, Carlos Silva (via 2009
     Google Summer of Code) and polished to a fine sheen by myself again.
     It should deal more-or-less correctly with the ikky corner-cases presented
     by quoted filenames, but the UI could still be slightly improved.
     In particular, it is quite slow for remote completion on large directories.
     bz#200; ok markus@

14 years ago - dtucker@cvs.openbsd.org 2010/01/04 01:45:30
dtucker [Fri, 8 Jan 2010 07:58:05 +0000 (07:58 +0000)] 
   - dtucker@cvs.openbsd.org 2010/01/04 01:45:30
     [sshconnect2.c]
     Don't escape backslashes in the SSH2 banner.  bz#1533, patch from
     Michal Gorny via Gentoo.

14 years ago - jmc@cvs.openbsd.org 2009/12/29 18:03:32
dtucker [Fri, 8 Jan 2010 07:57:39 +0000 (07:57 +0000)] 
   - jmc@cvs.openbsd.org 2009/12/29 18:03:32
     [sshd_config.5 ssh_config.5]
     sort previous;

14 years ago - stevesk@cvs.openbsd.org 2009/12/29 16:38:41
dtucker [Fri, 8 Jan 2010 07:56:48 +0000 (07:56 +0000)] 
   - stevesk@cvs.openbsd.org 2009/12/29 16:38:41
     [sshd_config.5 readconf.c ssh_config.5 scp.1 servconf.c sftp.1 ssh.1]
     Rename RDomain config option to RoutingDomain to be more clear and
     consistent with other options.
     NOTE: if you currently use RDomain in the ssh client or server config,
     or ssh/sshd -o, you must update to use RoutingDomain.
     ok markus@ djm@

14 years ago - stevesk@cvs.openbsd.org 2009/12/25 19:40:21
dtucker [Fri, 8 Jan 2010 07:55:58 +0000 (07:55 +0000)] 
   - stevesk@cvs.openbsd.org 2009/12/25 19:40:21
     [readconf.c servconf.c misc.h ssh-keyscan.c misc.c]
     validate routing domain is in range 0-RT_TABLEID_MAX.
     'Looks right' deraadt@

14 years ago - djm@cvs.openbsd.org 2009/12/20 23:20:40
dtucker [Fri, 8 Jan 2010 07:54:17 +0000 (07:54 +0000)] 
   - djm@cvs.openbsd.org 2009/12/20 23:20:40
     [PROTOCOL]
     fix an incorrect magic number and typo in PROTOCOL; bz#1688
     report and fix from ueno AT unixuser.org

14 years ago - guenther@cvs.openbsd.org 2009/12/20 07:28:36
dtucker [Fri, 8 Jan 2010 07:53:43 +0000 (07:53 +0000)] 
   - guenther@cvs.openbsd.org 2009/12/20 07:28:36
     [ssh.c sftp.c scp.c]
     When passing user-controlled options with arguments to other programs,
     pass the option and option argument as separate argv entries and
     not smashed into one (e.g., as -l foo and not -lfoo).  Also, always
     pass a "--" argument to stop option parsing, so that a positional
     argument that starts with a '-' isn't treated as an option.  This
     fixes some error cases as well as the handling of hostnames and
     filenames that start with a '-'.
     Based on a diff by halex@
     ok halex@ djm@ deraadt@

14 years ago - markus@cvs.openbsd.org 2009/12/11 18:16:33
dtucker [Fri, 8 Jan 2010 07:52:27 +0000 (07:52 +0000)] 
   - markus@cvs.openbsd.org 2009/12/11 18:16:33
     [key.c]
     switch from 35 to the more common value of RSA_F4 == (2**16)+1 == 65537
     for the RSA public exponent; discussed with provos; ok djm@

14 years ago - dtucker@cvs.openbsd.org 2009/12/06 23:53:54
dtucker [Fri, 8 Jan 2010 07:51:47 +0000 (07:51 +0000)] 
   - dtucker@cvs.openbsd.org 2009/12/06 23:53:54
     [sftp.c]
     fix potential divide-by-zero in sftp's "df" output when talking to a server
     that reports zero files on the filesystem (Unix filesystems always have at
     least the root inode).  From Steve McClellan at radisys, ok djm@

14 years ago - djm@cvs.openbsd.org 2009/12/06 23:53:45
dtucker [Fri, 8 Jan 2010 07:51:14 +0000 (07:51 +0000)] 
   - djm@cvs.openbsd.org 2009/12/06 23:53:45
     [roaming_common.c]
     use socklen_t for getsockopt optlen parameter; reported by
     Steve.McClellan AT radisys.com, ok dtucker@

14 years ago - dtucker@cvs.openbsd.org 2009/12/06 23:41:15
dtucker [Fri, 8 Jan 2010 07:50:46 +0000 (07:50 +0000)] 
   - dtucker@cvs.openbsd.org 2009/12/06 23:41:15
     [sshconnect2.c]
     zap unused variable and strlen; from Steve McClellan, ok djm

14 years ago - halex@cvs.openbsd.org 2009/11/22 13:18:00
dtucker [Fri, 8 Jan 2010 07:50:04 +0000 (07:50 +0000)] 
   - halex@cvs.openbsd.org 2009/11/22 13:18:00
     [sftp.c]
     make passing of zero-length arguments to ssh safe by
     passing "-<switch>" "<value>" rather than "-<switch><value>"
     ok dtucker@, guenther@, djm@

14 years ago - djm@cvs.openbsd.org 2009/11/20 03:24:07
dtucker [Fri, 8 Jan 2010 07:49:16 +0000 (07:49 +0000)] 
   - djm@cvs.openbsd.org 2009/11/20 03:24:07
     [misc.c]
     correct off-by-one in percent_expand(): we would fatal() when trying
     to expand EXPAND_MAX_KEYS, allowing only EXPAND_MAX_KEYS-1 to actually
     work.  Note that nothing in OpenSSH actually uses close to this limit at
     present.  bz#1607 from Jan.Pechanec AT Sun.COM

14 years ago - dtucker@cvs.openbsd.org 2009/11/20 00:59:36
dtucker [Fri, 8 Jan 2010 07:48:02 +0000 (07:48 +0000)] 
   - dtucker@cvs.openbsd.org 2009/11/20 00:59:36
     [sshconnect2.c]
     Use the HostKeyAlias when prompting for passwords.  bz#1039, ok djm@

14 years ago - djm@cvs.openbsd.org 2009/11/20 00:54:01
dtucker [Fri, 8 Jan 2010 06:10:36 +0000 (06:10 +0000)] 
   - djm@cvs.openbsd.org 2009/11/20 00:54:01
     [sftp.c]
     bz#1588 change "Connecting to host..." message to "Connected to host."
     and delay it until after the sftp protocol connection has been established.
     Avoids confusing sequence of messages when the underlying ssh connection
     experiences problems. ok dtucker@

14 years ago - dtucker@cvs.openbsd.org 2009/11/20 00:15:41
dtucker [Fri, 8 Jan 2010 06:09:50 +0000 (06:09 +0000)] 
   - dtucker@cvs.openbsd.org 2009/11/20 00:15:41
     [session.c]
     Warn but do not fail if stat()ing the subsystem binary fails.  This helps
     with chrootdirectory+forcecommand=sftp-server and restricted shells.
     bz #1599, ok djm.

14 years ago - djm@cvs.openbsd.org 2009/11/19 23:39:50
dtucker [Fri, 8 Jan 2010 06:09:11 +0000 (06:09 +0000)] 
   - djm@cvs.openbsd.org 2009/11/19 23:39:50
     [session.c]
     bz#1606: error when an attempt is made to connect to a server
     with ForceCommand=internal-sftp with a shell session (i.e. not a
     subsystem session). Avoids stuck client when attempting to ssh to such a
     service. ok dtucker@

14 years ago - djm@cvs.openbsd.org 2009/11/17 05:31:44
dtucker [Fri, 8 Jan 2010 06:08:35 +0000 (06:08 +0000)] 
   - djm@cvs.openbsd.org 2009/11/17 05:31:44
     [clientloop.c]
     fix incorrect exit status when multiplexing and channel ID 0 is recycled
     bz#1570 reported by peter.oliver AT eon-is.co.uk; ok dtucker

14 years ago - markus@cvs.openbsd.org 2009/11/11 21:37:03
dtucker [Fri, 8 Jan 2010 06:08:00 +0000 (06:08 +0000)] 
   - markus@cvs.openbsd.org 2009/11/11 21:37:03
     [channels.c channels.h]
     fix race condition in x11/agent channel allocation: don't read after
     the end of the select read/write fdset and make sure a reused FD
     is not touched before the pre-handlers are called.
     with and ok djm@

14 years ago - dtucker@cvs.openbsd.org 2009/11/10 04:30:45
dtucker [Fri, 8 Jan 2010 06:07:22 +0000 (06:07 +0000)] 
   - dtucker@cvs.openbsd.org 2009/11/10 04:30:45
     [sshconnect2.c channels.c sshconnect.c]
     Set close-on-exec on various descriptors so they don't get leaked to
     child processes.  bz #1643, patch from jchadima at redhat, ok deraadt.

14 years ago - djm@cvs.openbsd.org 2009/11/10 02:58:56
dtucker [Fri, 8 Jan 2010 06:06:47 +0000 (06:06 +0000)] 
   - djm@cvs.openbsd.org 2009/11/10 02:58:56
     [sshd_config.5]
     clarify that StrictModes does not apply to ChrootDirectory. Permissions
     and ownership are always checked when chrooting. bz#1532

14 years ago - djm@cvs.openbsd.org 2009/11/10 02:56:22
dtucker [Fri, 8 Jan 2010 06:05:59 +0000 (06:05 +0000)] 
   - djm@cvs.openbsd.org 2009/11/10 02:56:22
     [ssh_config.5]
     explain the constraints on LocalCommand some more so people don't
     try to abuse it.

14 years ago - jmc@cvs.openbsd.org 2009/10/28 21:45:08
dtucker [Fri, 8 Jan 2010 06:05:26 +0000 (06:05 +0000)] 
   - jmc@cvs.openbsd.org 2009/10/28 21:45:08
     [sshd_config.5 sftp.1]
     tweak previous;

14 years ago - reyk@cvs.openbsd.org 2009/10/28 16:38:18
dtucker [Fri, 8 Jan 2010 06:03:46 +0000 (06:03 +0000)] 
   - reyk@cvs.openbsd.org 2009/10/28 16:38:18
     [ssh_config.5 sshd.c misc.h ssh-keyscan.1 readconf.h sshconnect.c
     channels.c channels.h servconf.h servconf.c ssh.1 ssh-keyscan.c scp.1
     sftp.1 sshd_config.5 readconf.c ssh.c misc.c]
     Allow to set the rdomain in ssh/sftp/scp/sshd and ssh-keyscan.
     ok markus@

14 years ago - andreas@cvs.openbsd.org 2009/10/24 11:23:42
dtucker [Fri, 8 Jan 2010 05:54:59 +0000 (05:54 +0000)] 
   - andreas@cvs.openbsd.org 2009/10/24 11:23:42
     [ssh.c]
     Request roaming to be enabled if UseRoaming is true and the server
     supports it.
     ok markus@

14 years ago - andreas@cvs.openbsd.org 2009/10/24 11:22:37
dtucker [Fri, 8 Jan 2010 05:53:31 +0000 (05:53 +0000)] 
   - andreas@cvs.openbsd.org 2009/10/24 11:22:37
     [roaming_common.c]
     Do the actual suspend/resume in the client. This won't be useful until
     the server side supports roaming.
     Most code from Martin Forssen, maf at appgate dot com. Some changes by
     me and markus@
     ok markus@

14 years ago - andreas@cvs.openbsd.org 2009/10/24 11:19:17
dtucker [Fri, 8 Jan 2010 05:52:32 +0000 (05:52 +0000)] 
   - andreas@cvs.openbsd.org 2009/10/24 11:19:17
     [ssh2.h]
     Define the KEX messages used when resuming a suspended connection.
     ok markus@

14 years ago - andreas@cvs.openbsd.org 2009/10/24 11:15:29
dtucker [Fri, 8 Jan 2010 05:51:40 +0000 (05:51 +0000)] 
   - andreas@cvs.openbsd.org 2009/10/24 11:15:29
     [clientloop.c]
     client_loop() must detect if the session has been suspended and resumed,
     and take appropriate action in that case.
     From Martin Forssen, maf at appgate dot com
     ok markus@

14 years ago - andreas@cvs.openbsd.org 2009/10/24 11:13:54
dtucker [Fri, 8 Jan 2010 05:50:41 +0000 (05:50 +0000)] 
   - andreas@cvs.openbsd.org 2009/10/24 11:13:54
     [sshconnect2.c kex.h kex.c]
     Let the client detect if the server supports roaming by looking
     for the resume@appgate.com kex algorithm.
     ok markus@

14 years ago - andreas@cvs.openbsd.org 2009/10/24 11:11:58
dtucker [Fri, 8 Jan 2010 05:49:52 +0000 (05:49 +0000)] 
   - andreas@cvs.openbsd.org 2009/10/24 11:11:58
     [roaming.h]
     Declarations needed for upcoming changes.
     ok markus@

14 years ago - (tim) [contrib/cygwin/Makefile] Install ssh-copy-id and ssh-copy-id.1
tim [Sat, 26 Dec 2009 23:40:47 +0000 (23:40 +0000)] 
 - (tim) [contrib/cygwin/Makefile] Install ssh-copy-id and ssh-copy-id.1
   Gzip all man pages. Patch from Corinna Vinschen.

14 years ago - (dtucker) [auth-krb5.c platform.{c,h} openbsd-compat/port-aix.{c,h}]
dtucker [Sun, 20 Dec 2009 23:49:21 +0000 (23:49 +0000)] 
 - (dtucker) [auth-krb5.c platform.{c,h} openbsd-compat/port-aix.{c,h}]
   Bug #1583: Use system's kerberos principal name on AIX if it's available.
   Based on a patch from and tested by Miguel Sanders.

14 years ago - (dtucker) Bug #1470: Disable OOM-killing of the listening sshd on Linux,
dtucker [Tue, 8 Dec 2009 02:39:48 +0000 (02:39 +0000)] 
 - (dtucker) Bug #1470: Disable OOM-killing of the listening sshd on Linux,
   based on a patch from Vaclav Ovsik and Colin Watson.  ok djm.

14 years ago - (dtucker) Bug #1677: add conditionals around the source for ssh-askpass.
dtucker [Mon, 7 Dec 2009 00:32:36 +0000 (00:32 +0000)] 
 - (dtucker) Bug #1677: add conditionals around the source for ssh-askpass.

14 years ago - (dtucker) Bug #1160: use pkg-config for opensc config if it's available.
dtucker [Mon, 7 Dec 2009 00:15:43 +0000 (00:15 +0000)] 
 - (dtucker) Bug #1160: use pkg-config for opensc config if it's available.
   Tested by Martin Paljak.

14 years ago - (tim) [opensshd.init.in] If PidFile is set in sshd_config, use it.
tim [Sat, 21 Nov 2009 03:32:15 +0000 (03:32 +0000)] 
 - (tim) [opensshd.init.in] If PidFile is set in sshd_config, use it.
   Bug 1628. OK dtucker@

14 years ago - (djm) [ssh-rand-helper.c] Print error and usage() when passed command-
djm [Fri, 20 Nov 2009 04:16:35 +0000 (04:16 +0000)] 
 - (djm) [ssh-rand-helper.c] Print error and usage() when passed command-
   line arguments as none are supported. Exit when passed unrecognised
   commandline flags. bz#1568 from gson AT araneus.fi

14 years ago - (djm) [contrib/gnome-ssh-askpass2.c] Make askpass dialog desktop-modal.
djm [Wed, 18 Nov 2009 06:51:59 +0000 (06:51 +0000)] 
 - (djm) [contrib/gnome-ssh-askpass2.c] Make askpass dialog desktop-modal.
   bz#1645, patch from jchadima AT redhat.com

14 years ago - (djm) [channels.c misc.c misc.h sshd.c] add missing setsockopt() to
djm [Wed, 18 Nov 2009 06:48:30 +0000 (06:48 +0000)] 
 - (djm) [channels.c misc.c misc.h sshd.c] add missing setsockopt() to
   set IPV6_V6ONLY for local forwarding with GatwayPorts=yes. Unify
   setting IPV6_V6ONLY behind a new function misc.c:sock_set_v6only()
   report and fix from jan.kratochvil AT redhat.com

14 years ago - (dtucker) [authfile.c] Fall back to 3DES for the encryption of private
dtucker [Sat, 7 Nov 2009 05:03:14 +0000 (05:03 +0000)] 
 - (dtucker) [authfile.c] Fall back to 3DES for the encryption of private
    keys when built with OpenSSL versions that don't do AES.

14 years ago - (dtucker) [authfile.c] Add OpenSSL compat header so this still builds with
dtucker [Thu, 5 Nov 2009 09:43:16 +0000 (09:43 +0000)] 
 - (dtucker) [authfile.c] Add OpenSSL compat header so this still builds with
   older versions of OpenSSL.

14 years ago - (dtucker) [session.c openbsd-compat/port-linux.{c,h}] Bug #1637: if selinux
dtucker [Sat, 24 Oct 2009 04:04:12 +0000 (04:04 +0000)] 
 - (dtucker) [session.c openbsd-compat/port-linux.{c,h}] Bug #1637: if selinux
   is enabled set the security context to "sftpd_t" before running the
   internal sftp server   Based on a patch from jchadima at redhat.

14 years ago - (dtucker) [mdoc2man.awk] Teach it to understand the .Ux macro.
dtucker [Sat, 24 Oct 2009 00:52:42 +0000 (00:52 +0000)] 
 - (dtucker) [mdoc2man.awk] Teach it to understand the .Ux macro.

14 years ago - dtucker@cvs.openbsd.org 2009/10/24 00:48:34
dtucker [Sat, 24 Oct 2009 00:50:17 +0000 (00:50 +0000)] 
   - dtucker@cvs.openbsd.org 2009/10/24 00:48:34
     [ssh-keygen.1]
     ssh-keygen now uses AES-128 for private keys

14 years ago - djm@cvs.openbsd.org 2009/10/23 01:57:11
dtucker [Sat, 24 Oct 2009 00:47:58 +0000 (00:47 +0000)] 
   - djm@cvs.openbsd.org 2009/10/23 01:57:11
     [sshconnect2.c]
     disallow a hostile server from checking jpake auth by sending an
     out-of-sequence success message. (doesn't affect code enabled by default)

14 years ago - djm@cvs.openbsd.org 2009/10/22 22:26:13
dtucker [Sat, 24 Oct 2009 00:46:43 +0000 (00:46 +0000)] 
   - djm@cvs.openbsd.org 2009/10/22 22:26:13
     [authfile.c]
     switch from 3DES to AES-128 for encryption of passphrase-protected
     SSH protocol 2 private keys; ok several

14 years ago - sobrado@cvs.openbsd.org 2009/10/22 15:02:12
dtucker [Sat, 24 Oct 2009 00:42:44 +0000 (00:42 +0000)] 
   - sobrado@cvs.openbsd.org 2009/10/22 15:02:12
     [ssh-agent.1 ssh-add.1 ssh.1]
     write UNIX-domain in a more consistent way; while here, replace a
     few remaining ".Tn UNIX" macros with ".Ux" ones.
     pointed out by ratchov@, thanks!
     ok jmc@

14 years ago - sobrado@cvs.openbsd.org 2009/10/22 12:35:53
dtucker [Sat, 24 Oct 2009 00:41:34 +0000 (00:41 +0000)] 
   - sobrado@cvs.openbsd.org 2009/10/22 12:35:53
     [ssh.1 ssh-agent.1 ssh-add.1]
     use the UNIX-related macros (.At and .Ux) where appropriate.
     ok jmc@

14 years ago - sobrado@cvs.openbsd.org 2009/10/17 12:10:39
dtucker [Sat, 24 Oct 2009 00:41:05 +0000 (00:41 +0000)] 
   - sobrado@cvs.openbsd.org 2009/10/17 12:10:39
     [sftp-server.c]
     sort flags.

14 years ago - (dtucker) OpenBSD CVS Sync
dtucker [Sat, 24 Oct 2009 00:40:32 +0000 (00:40 +0000)] 
 - (dtucker) OpenBSD CVS Sync
   - djm@cvs.openbsd.org 2009/10/11 23:03:15
     [hostfile.c]
     mention the host name that we are looking for in check_host_in_hostfile()

14 years ago - markus@cvs.openbsd.org 2009/10/08 18:04:27
dtucker [Sun, 11 Oct 2009 22:37:22 +0000 (22:37 +0000)] 
   - markus@cvs.openbsd.org 2009/10/08 18:04:27
     [regress/test-exec.sh]
     re-enable protocol v1 for the tests.

14 years ago - dtucker@cvs.openbsd.org 2009/10/11 10:41:26
dtucker [Sun, 11 Oct 2009 10:52:10 +0000 (10:52 +0000)] 
   - dtucker@cvs.openbsd.org 2009/10/11 10:41:26
     [sftp-client.c]
     d_type isn't portable so use lstat to get dirent modes.  Suggested by and
     "looks sane" deraadt@

14 years ago - jmc@cvs.openbsd.org 2009/10/08 20:42:12
dtucker [Sun, 11 Oct 2009 10:51:40 +0000 (10:51 +0000)] 
   - jmc@cvs.openbsd.org 2009/10/08 20:42:12
     [sshd_config.5 ssh_config.5 sshd.8 ssh.1]
     some tweaks now that protocol 1 is not offered by default; ok markus

14 years ago - (dtucker) OpenBSD CVS Sync
dtucker [Sun, 11 Oct 2009 10:51:08 +0000 (10:51 +0000)] 
 - (dtucker) OpenBSD CVS Sync
   - markus@cvs.openbsd.org 2009/10/08 14:03:41
     [sshd_config readconf.c ssh_config.5 servconf.c sshd_config.5]
     disable protocol 1 by default (after a transition period of about 10 years)
     ok deraadt

14 years ago - (dtucker) [configure.ac sftp-client.c] Remove the gyrations required for
dtucker [Sun, 11 Oct 2009 10:50:20 +0000 (10:50 +0000)] 
 - (dtucker) [configure.ac sftp-client.c] Remove the gyrations required for
   dirent d_type and DTTOIF as we've switched OpenBSD to the more portable
   lstat.

14 years ago - (dtucker) d_type is not mandated by POSIX, so add fallback code using
dtucker [Wed, 7 Oct 2009 07:56:10 +0000 (07:56 +0000)] 
 - (dtucker) d_type is not mandated by POSIX, so add fallback code using
    stat(), needed on at least cygwin.

14 years ago - (dtucker) [configure.ac sftp-client.c] DOTTIF is in fs/ffs/dir.h on at
dtucker [Wed, 7 Oct 2009 04:49:48 +0000 (04:49 +0000)] 
 - (dtucker) [configure.ac sftp-client.c] DOTTIF is in fs/ffs/dir.h on at
   least dragonflybsd.

14 years ago - (dtucker) [regress/portnum.sh] Import new test.
dtucker [Wed, 7 Oct 2009 00:00:58 +0000 (00:00 +0000)] 
 - (dtucker) [regress/portnum.sh] Import new test.

14 years agofix id
dtucker [Tue, 6 Oct 2009 23:58:40 +0000 (23:58 +0000)] 
fix id

14 years ago - dtucker@cvs.openbsd.org 2009/10/06 23:51:49
dtucker [Tue, 6 Oct 2009 23:54:31 +0000 (23:54 +0000)] 
   - dtucker@cvs.openbsd.org 2009/10/06 23:51:49
     [regress/ssh2putty.sh]
     Add OpenBSD tag to make syncs easier

14 years ago - djm@cvs.openbsd.org 2009/08/20 18:43:07
dtucker [Tue, 6 Oct 2009 23:46:29 +0000 (23:46 +0000)] 
   - djm@cvs.openbsd.org 2009/08/20 18:43:07
     [ssh-com-sftp.sh]
     fix one sftp -D ... => sftp -P ... conversion that I missed; from Carlos
     Silva for Google Summer of Code

14 years ago - djm@cvs.openbsd.org 2009/08/13 01:11:55
dtucker [Tue, 6 Oct 2009 23:43:57 +0000 (23:43 +0000)] 
   - djm@cvs.openbsd.org 2009/08/13 01:11:55
     [sftp-batch.sh sftp-badcmds.sh sftp.sh sftp-cmds.sh sftp-glob.sh]
     date: 2009/08/13 01:11:19;  author: djm;  state: Exp;  lines: +10 -7
     Swizzle options: "-P sftp_server_path" moves to "-D sftp_server_path",
     add "-P port" to match scp(1). Fortunately, the -P option is only really
     used by our regression scripts.
     part of larger patch from carlosvsilvapt@gmail.com for his Google Summer
     of Code work; ok deraadt markus

14 years ago - djm@cvs.openbsd.org 2009/08/13 00:57:17
dtucker [Tue, 6 Oct 2009 23:31:56 +0000 (23:31 +0000)] 
   - djm@cvs.openbsd.org 2009/08/13 00:57:17
     [regress/Makefile]
     regression test for port number parsing. written as part of the a2port
     change that went into 5.2 but I forgot to commit it at the time...

14 years ago - dtucker@cvs.openbsd.org 2009/05/05 07:51:36
dtucker [Tue, 6 Oct 2009 23:30:57 +0000 (23:30 +0000)] 
   - dtucker@cvs.openbsd.org 2009/05/05 07:51:36
     [regress/multiplex.sh]
     Always specify ssh_config for multiplex tests: prevents breakage caused
     by options in ~/.ssh/config.  From Dan Peterson.

14 years ago - djm@cvs.openbsd.org 2008/12/07 22:17:48
dtucker [Tue, 6 Oct 2009 23:30:06 +0000 (23:30 +0000)] 
   - djm@cvs.openbsd.org 2008/12/07 22:17:48
     [regress/addrmatch.sh]
     match string "passwordauthentication" only at start of line, not anywhere
     in sshd -T output

14 years ago - djm@cvs.openbsd.org 2009/10/06 04:46:40
dtucker [Tue, 6 Oct 2009 22:02:18 +0000 (22:02 +0000)] 
   - djm@cvs.openbsd.org 2009/10/06 04:46:40
     [session.c]
     bz#1596: fflush(NULL) before exec() to ensure that everying (motd
     in particular) has made it out before the streams go away.

14 years ago - grunk@cvs.openbsd.org 2009/10/01 11:37:33
dtucker [Tue, 6 Oct 2009 22:01:50 +0000 (22:01 +0000)] 
   - grunk@cvs.openbsd.org 2009/10/01 11:37:33
     [dh.c]
     fix a cast
     ok djm@ markus@

14 years ago - djm@cvs.openbsd.org 2009/09/01 14:43:17
dtucker [Tue, 6 Oct 2009 22:01:03 +0000 (22:01 +0000)] 
   - djm@cvs.openbsd.org 2009/09/01 14:43:17
     [ssh-agent.c]
     fix a race condition in ssh-agent that could result in a wedged or
     spinning agent: don't read off the end of the allocated fd_sets, and
     don't issue blocking read/write on agent sockets - just fall back to
     select() on retriable read/write errors. bz#1633 reported and tested
     by "noodle10000 AT googlemail.com"; ok dtucker@ markus@

14 years ago - djm@cvs.openbsd.org 2009/08/31 21:01:29
dtucker [Tue, 6 Oct 2009 21:47:47 +0000 (21:47 +0000)] 
   - djm@cvs.openbsd.org 2009/08/31 21:01:29
     [sftp-server.8]
     document -e and -h; prodded by jmc@

14 years ago - djm@cvs.openbsd.org 2009/08/31 20:56:02
dtucker [Tue, 6 Oct 2009 21:47:24 +0000 (21:47 +0000)] 
   - djm@cvs.openbsd.org 2009/08/31 20:56:02
     [sftp-server.c]
     check correct variable for error message, spotted by martynas@

14 years ago - djm@cvs.openbsd.org 2009/08/27 17:44:52
dtucker [Tue, 6 Oct 2009 21:47:02 +0000 (21:47 +0000)] 
   - djm@cvs.openbsd.org 2009/08/27 17:44:52
     [authfd.c ssh-add.c authfd.h]
     Do not fall back to adding keys without contraints (ssh-add -c / -t ...)
     when the agent refuses the constrained add request. This was a useful
     migration measure back in 2002 when constraints were new, but just
     adds risk now.
     bz #1612, report and patch from dkg AT fifthhorseman.net; ok markus@

14 years ago - djm@cvs.openbsd.org 2009/08/27 17:43:00
dtucker [Tue, 6 Oct 2009 21:46:21 +0000 (21:46 +0000)] 
   - djm@cvs.openbsd.org 2009/08/27 17:43:00
     [sftp-server.8]
     allow setting an explicit umask on the commandline to override whatever
     default the user has. bz#1229; ok dtucker@ deraadt@ markus@

14 years ago - djm@cvs.openbsd.org 2009/08/27 17:33:49
dtucker [Tue, 6 Oct 2009 21:45:48 +0000 (21:45 +0000)] 
   - djm@cvs.openbsd.org 2009/08/27 17:33:49
     [ssh-keygen.c]
     force use of correct hash function for random-art signature display
     as it was inheriting the wrong one when bubblebabble signatures were
     activated; bz#1611 report and patch from fwojcik+openssh AT besh.com;
     ok markus@

14 years ago - djm@cvs.openbsd.org 2009/08/27 17:28:52
dtucker [Tue, 6 Oct 2009 21:44:42 +0000 (21:44 +0000)] 
   - djm@cvs.openbsd.org 2009/08/27 17:28:52
     [sftp-server.c]
     allow setting an explicit umask on the commandline to override whatever
     default the user has. bz#1229; ok dtucker@ deraadt@ markus@

14 years ago - dtucker@cvs.openbsd.org 2009/08/20 23:54:28
dtucker [Tue, 6 Oct 2009 21:39:57 +0000 (21:39 +0000)] 
   - dtucker@cvs.openbsd.org 2009/08/20 23:54:28
     [mux.c]
     subsystem_flag is defined in ssh.c so it's extern; ok djm

14 years ago - jmc@cvs.openbsd.org 2009/08/19 04:56:03
dtucker [Tue, 6 Oct 2009 21:39:09 +0000 (21:39 +0000)] 
   - jmc@cvs.openbsd.org 2009/08/19 04:56:03
     [sftp.1]
     ether -> either;

14 years ago - djm@cvs.openbsd.org 2009/08/18 21:15:59
dtucker [Tue, 6 Oct 2009 21:38:23 +0000 (21:38 +0000)] 
  - djm@cvs.openbsd.org 2009/08/18 21:15:59
     [sftp.1]
     fix "get" command usage, spotted by jmc@

14 years ago - djm@cvs.openbsd.org 2009/08/18 18:36:21
dtucker [Tue, 6 Oct 2009 21:37:48 +0000 (21:37 +0000)] 
   - djm@cvs.openbsd.org 2009/08/18 18:36:21
     [sftp-client.h sftp.1 sftp-client.c sftp.c]
     recursive transfer support for get/put and on the commandline
     work mostly by carlosvsilvapt@gmail.com for the Google Summer of Code
     with some tweaks by me; "go for it" deraadt@

14 years ago - dtucker@cvs.openbsd.org 2009/08/16 23:29:26
dtucker [Tue, 6 Oct 2009 21:36:05 +0000 (21:36 +0000)] 
   - dtucker@cvs.openbsd.org 2009/08/16 23:29:26
     [sshd_config.5]
     Add PubkeyAuthentication to the list allowed in a Match block (bz #1577)

14 years ago - fgsch@cvs.openbsd.org 2009/08/15 18:56:34
dtucker [Tue, 6 Oct 2009 21:35:32 +0000 (21:35 +0000)] 
   - fgsch@cvs.openbsd.org 2009/08/15 18:56:34
     [auth.h]
     remove unused define. markus@ ok.
     (Id sync only, Portable still uses this.)

14 years ago - djm@cvs.openbsd.org 2009/08/14 18:17:49
dtucker [Tue, 6 Oct 2009 21:24:19 +0000 (21:24 +0000)] 
   - djm@cvs.openbsd.org 2009/08/14 18:17:49
     [sftp-client.c]
     make the "get_handle: ..." error messages vaguely useful by allowing
     callers to specify their own error message strings.

14 years ago - jmc@cvs.openbsd.org 2009/08/13 13:39:54
dtucker [Tue, 6 Oct 2009 21:23:44 +0000 (21:23 +0000)] 
   - jmc@cvs.openbsd.org 2009/08/13 13:39:54
     [sftp.1 sftp.c]
     sync synopsis and usage();

14 years ago - djm@cvs.openbsd.org 2009/08/13 01:11:19
dtucker [Tue, 6 Oct 2009 21:23:06 +0000 (21:23 +0000)] 
   - djm@cvs.openbsd.org 2009/08/13 01:11:19
     [sftp.1 sftp.c]
     Swizzle options: "-P sftp_server_path" moves to "-D sftp_server_path",
     add "-P port" to match scp(1). Fortunately, the -P option is only really
     used by our regression scripts.
     part of larger patch from carlosvsilvapt@gmail.com for his Google Summer
     of Code work; ok deraadt markus

14 years ago - jmc@cvs.openbsd.org 2009/08/12 06:31:42
dtucker [Tue, 6 Oct 2009 21:22:20 +0000 (21:22 +0000)] 
  - jmc@cvs.openbsd.org 2009/08/12 06:31:42
     [sftp.1]
     sort options;

This page took 0.098094 seconds and 4 git commands to generate.