]> andersk Git - openssh.git/log
openssh.git
16 years ago - stevesk@cvs.openbsd.org 2007/09/11 23:49:09
djm [Mon, 17 Sep 2007 06:10:21 +0000 (06:10 +0000)] 
   - stevesk@cvs.openbsd.org 2007/09/11 23:49:09
     [sshpty.c]
     remove #if defined block not needed; ok markus@ dtucker@
     NB. RCS ID sync only

16 years ago - gilles@cvs.openbsd.org 2007/09/11 15:47:17
djm [Mon, 17 Sep 2007 06:09:15 +0000 (06:09 +0000)] 
   - gilles@cvs.openbsd.org 2007/09/11 15:47:17
     [session.c ssh-keygen.c sshlogin.c]
     use strcspn to properly overwrite '\n' in fgets returned buffer
     ok pyr@, ray@, millert@, moritz@, chl@

16 years ago - stevesk@cvs.openbsd.org 2007/09/11 04:36:29
djm [Mon, 17 Sep 2007 06:07:32 +0000 (06:07 +0000)] 
   - stevesk@cvs.openbsd.org 2007/09/11 04:36:29
     [sshpty.c]
     sort #include
     NB. RCS ID sync only

16 years ago - sobrado@cvs.openbsd.org 2007/09/09 11:38:01
djm [Mon, 17 Sep 2007 06:05:50 +0000 (06:05 +0000)] 
   - sobrado@cvs.openbsd.org 2007/09/09 11:38:01
     [ssh-add.c ssh-agent.1 ssh-agent.c ssh-keygen.c]
     sort synopsis and options in ssh-agent(1); usage is lowercase
     ok jmc@

16 years ago - djm@cvs.openbsd.org 2007/09/04 11:15:56
djm [Mon, 17 Sep 2007 02:06:57 +0000 (02:06 +0000)] 
   - djm@cvs.openbsd.org 2007/09/04 11:15:56
     [ssh.c sshconnect.c sshconnect.h]
     make ssh(1)'s ConnectTimeout option apply to both the TCP connection and
     SSH banner exchange (previously it just covered the TCP connection).
     This allows callers of ssh(1) to better detect and deal with stuck servers
     that accept a TCP connection but don't progress the protocol, and also
     makes ConnectTimeout useful for connections via a ProxyCommand;
     feedback and "looks ok" markus@

16 years ago - djm@cvs.openbsd.org 2007/09/04 03:21:03
djm [Mon, 17 Sep 2007 02:04:08 +0000 (02:04 +0000)] 
   - djm@cvs.openbsd.org 2007/09/04 03:21:03
     [clientloop.c monitor.c monitor_fdpass.c monitor_fdpass.h]
     [monitor_wrap.c ssh.c]
     make file descriptor passing code return an error rather than call fatal()
     when it encounters problems, and use this to make session multiplexing
     masters survive slaves failing to pass all stdio FDs; ok markus@

16 years ago - djm@cvs.openbsd.org 2007/08/23 03:23:26
djm [Mon, 17 Sep 2007 01:58:04 +0000 (01:58 +0000)] 
   - djm@cvs.openbsd.org 2007/08/23 03:23:26
     [sshconnect.c]
     Execute ProxyCommands with $SHELL rather than /bin/sh unconditionally

16 years ago - djm@cvs.openbsd.org 2007/08/23 03:22:16
djm [Mon, 17 Sep 2007 01:57:38 +0000 (01:57 +0000)] 
   - djm@cvs.openbsd.org 2007/08/23 03:22:16
     [auth2-none.c sshd_config sshd_config.5]
     Support "Banner=none" to disable displaying of the pre-login banner;
     ok dtucker@ deraadt@

16 years ago - djm@cvs.openbsd.org 2007/08/23 03:06:10
djm [Mon, 17 Sep 2007 01:55:25 +0000 (01:55 +0000)] 
   - djm@cvs.openbsd.org 2007/08/23 03:06:10
     [auth.h]
     login_cap.h doesn't belong here
     NB. RCS ID sync only for portable

16 years ago - djm@cvs.openbsd.org 2007/08/23 02:55:51
djm [Mon, 17 Sep 2007 01:54:24 +0000 (01:54 +0000)] 
   - djm@cvs.openbsd.org 2007/08/23 02:55:51
     [auth-passwd.c auth.c session.c]
     missed include bits from last commit
     NB. RCS ID sync only for portable

16 years ago - djm@cvs.openbsd.org 2007/08/23 02:49:43
djm [Mon, 17 Sep 2007 01:52:59 +0000 (01:52 +0000)] 
   - djm@cvs.openbsd.org 2007/08/23 02:49:43
     [auth-passwd.c auth.c session.c]
     unifdef HAVE_LOGIN_CAP; ok deraadt@ millert@
     NB. RCS ID sync only for portable

16 years ago - (dtucker) [openbsd-compat/bsd-asprintf.c] Plug mem leak in error path.
dtucker [Fri, 14 Sep 2007 00:04:15 +0000 (00:04 +0000)] 
 - (dtucker) [openbsd-compat/bsd-asprintf.c] Plug mem leak in error path.
   Patch from Jan.Pechanec at sun com.

16 years ago - (tim) [configure.ac] Autoconf didn't define HAVE_LIBIAF because we
tim [Mon, 10 Sep 2007 23:24:17 +0000 (23:24 +0000)] 
 - (tim) [configure.ac] Autoconf didn't define HAVE_LIBIAF because we
   did a AC_CHECK_FUNCS within the AC_CHECK_LIB test.

16 years ago - (dtucker) [openbsd-compat/regress/closefromtest.c] Bug #1358: Always
dtucker [Mon, 10 Sep 2007 03:20:14 +0000 (03:20 +0000)] 
 - (dtucker) [openbsd-compat/regress/closefromtest.c] Bug #1358: Always
   return 0 on successful test.  From David.Leonard at quest com.

16 years agodon't say it twice
djm [Tue, 4 Sep 2007 06:49:39 +0000 (06:49 +0000)] 
don't say it twice

16 years agocredit Jan Pechanec
djm [Tue, 4 Sep 2007 04:26:32 +0000 (04:26 +0000)] 
credit Jan Pechanec

16 years agoMention Jan Pechanec
dtucker [Tue, 4 Sep 2007 04:05:24 +0000 (04:05 +0000)] 
Mention Jan Pechanec

16 years ago - (dtucker) [INSTALL] Link to tcpwrappers.
dtucker [Fri, 17 Aug 2007 12:52:05 +0000 (12:52 +0000)] 
 - (dtucker) [INSTALL] Link to tcpwrappers.

16 years ago - (dtucker) [INSTALL] Give PAM its own heading.
dtucker [Fri, 17 Aug 2007 12:12:14 +0000 (12:12 +0000)] 
 - (dtucker) [INSTALL] Give PAM its own heading.

16 years ago - (dtucker) [INSTALL] the pid file is sshd.pid not ssh.pid.
dtucker [Fri, 17 Aug 2007 12:10:10 +0000 (12:10 +0000)] 
 - (dtucker) [INSTALL] the pid file is sshd.pid not ssh.pid.

16 years ago - (dtucker) [INSTALL] Group the parts describing random options and PAM
dtucker [Fri, 17 Aug 2007 12:03:09 +0000 (12:03 +0000)] 
 - (dtucker) [INSTALL] Group the parts describing random options and PAM
   implementations together which is hopefully more coherent.

16 years agotypo
dtucker [Fri, 17 Aug 2007 11:40:22 +0000 (11:40 +0000)] 
typo

16 years ago - (dtucker) [sshd.8] Many Linux variants use a single "!" to denote locked
dtucker [Thu, 16 Aug 2007 23:42:32 +0000 (23:42 +0000)] 
 - (dtucker) [sshd.8] Many Linux variants use a single "!" to denote locked
   accounts and that's what the code looks for, so make man page and code
   agree.  Pointed out by Roumen Petrov.

16 years ago - (dtucker) [session.c] Call PAM cleanup functions for unauthenticated
dtucker [Thu, 16 Aug 2007 13:28:04 +0000 (13:28 +0000)] 
 - (dtucker) [session.c] Call PAM cleanup functions for unauthenticated
   connections too.  Based on a patch from Sandro Wefel, with & ok djm@

16 years ago - stevesk@cvs.openbsd.org 2007/08/15 12:13:41
dtucker [Wed, 15 Aug 2007 12:20:22 +0000 (12:20 +0000)] 
   - stevesk@cvs.openbsd.org 2007/08/15 12:13:41
     [ssh_config.5]
     tun device forwarding now honours ExitOnForwardFailure; ok markus@

16 years ago - (dtucker) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec
dtucker [Wed, 15 Aug 2007 09:22:20 +0000 (09:22 +0000)] 
 - (dtucker) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec
   contrib/suse/openssh.spec] Crank version.

16 years ago - (dtucker) [openbsd-compat/bsd-cray.c] Remove debug from signal handler.
dtucker [Wed, 15 Aug 2007 09:17:43 +0000 (09:17 +0000)] 
 - (dtucker) [openbsd-compat/bsd-cray.c] Remove debug from signal handler.
   ok djm@

16 years ago - markus@cvs.openbsd.org 2007/08/15 08:16:49
dtucker [Wed, 15 Aug 2007 09:14:52 +0000 (09:14 +0000)] 
   - markus@cvs.openbsd.org 2007/08/15 08:16:49
     [version.h]
     openssh 4.7

16 years ago - markus@cvs.openbsd.org 2007/08/15 08:14:46
dtucker [Wed, 15 Aug 2007 09:13:41 +0000 (09:13 +0000)] 
   - markus@cvs.openbsd.org 2007/08/15 08:14:46
     [clientloop.c]
     do NOT fall back to the trused x11 cookie if generation of an untrusted
     cookie fails; from security-alert at sun.com; ok dtucker

16 years ago - (dtucker) [session.c] Bug #1339: ensure that pam_setcred() is always
dtucker [Mon, 13 Aug 2007 13:11:56 +0000 (13:11 +0000)] 
 - (dtucker) [session.c] Bug #1339: ensure that pam_setcred() is always
   called with PAM_ESTABLISH_CRED at least once, which resolves a problem
   with pam_dhkeys.  Patch from David Leonard, ok djm@

16 years ago - (dtucker) [configure.ac] Bug #1343: Set DISABLE_FD_PASSING for QNX6. From.
dtucker [Fri, 10 Aug 2007 04:36:12 +0000 (04:36 +0000)] 
 - (dtucker) [configure.ac] Bug #1343: Set DISABLE_FD_PASSING for QNX6. From.
   Matt Kraai, ok djm@.

16 years ago - (dtucker) [auth-pam.c] Use sigdie here too. ok djm@
dtucker [Fri, 10 Aug 2007 04:32:34 +0000 (04:32 +0000)] 
 - (dtucker) [auth-pam.c] Use sigdie here too.  ok djm@

16 years agoCredit Bernhard Simon who also reported this.
dtucker [Thu, 9 Aug 2007 05:03:23 +0000 (05:03 +0000)] 
Credit Bernhard Simon who also reported this.

16 years ago - (dtucker) [defines.h] Remove _PATH_{CSHELL,SHELLS} which aren't
dtucker [Thu, 9 Aug 2007 04:37:52 +0000 (04:37 +0000)] 
 - (dtucker) [defines.h] Remove _PATH_{CSHELL,SHELLS} which aren't
   used anywhere and are a potential source of warnings.

16 years ago - (dtucker) [README.platform] Document the interaction between PermitRootLogin
dtucker [Thu, 9 Aug 2007 04:31:53 +0000 (04:31 +0000)] 
 - (dtucker) [README.platform] Document the interaction between PermitRootLogin
   and the AIX native login restrictions.

16 years ago - (dtucker) [openbsd-compat/port-aix.c] Comment typo.
dtucker [Thu, 9 Aug 2007 04:29:47 +0000 (04:29 +0000)] 
 - (dtucker) [openbsd-compat/port-aix.c] Comment typo.

16 years ago - djm@cvs.openbsd.org 2007/08/07 07:32:53
djm [Wed, 8 Aug 2007 04:32:41 +0000 (04:32 +0000)] 
   - djm@cvs.openbsd.org 2007/08/07 07:32:53
     [clientloop.c clientloop.h ssh.c]
     bz#1232: ensure that any specified LocalCommand is executed after the
     tunnel device is opened. Also, make failures to open a tunnel device
     fatal when ExitOnForwardFailure is active.
     Reported by h.goebel AT goebel-consult.de; ok dtucker markus reyk deraadt

16 years ago - sobrado@cvs.openbsd.org 2007/08/06 19:16:06
djm [Wed, 8 Aug 2007 04:29:58 +0000 (04:29 +0000)] 
   - sobrado@cvs.openbsd.org 2007/08/06 19:16:06
     [scp.1 scp.c]
     the ellipsis is not an optional argument; while here, sync the usage
     and synopsis of commands
     lots of good ideas by jmc@
     ok jmc@

16 years ago - ray@cvs.openbsd.org 2007/07/12 05:48:05
djm [Wed, 8 Aug 2007 04:28:26 +0000 (04:28 +0000)] 
   - ray@cvs.openbsd.org 2007/07/12 05:48:05
     [key.c]
     Delint: remove some unreachable statements, from Bret Lambert.
     OK markus@ and dtucker@.

16 years ago - (tim) [buildpkg.sh.in] s|$FAKE_ROOT/${sysconfdir}|$FAKE_ROOT${sysconfdir}|
tim [Wed, 25 Jul 2007 04:40:59 +0000 (04:40 +0000)] 
 - (tim) [buildpkg.sh.in] s|$FAKE_ROOT/${sysconfdir}|$FAKE_ROOT${sysconfdir}|

16 years ago - (tim) [buildpkg.sh.in openssh.xml.in] Allow more flexibility where smf(5)
tim [Wed, 25 Jul 2007 04:16:07 +0000 (04:16 +0000)] 
 - (tim) [buildpkg.sh.in openssh.xml.in] Allow more flexibility where smf(5)
   files are installed.

16 years ago - (tim) [openbsd-compat/regress/closefromtest.c] Bug 1345: fix open() call.
tim [Wed, 25 Jul 2007 03:54:09 +0000 (03:54 +0000)] 
 - (tim) [openbsd-compat/regress/closefromtest.c] Bug 1345: fix open() call.
   Report/patch by David.Leonard AT quest.com

16 years ago - (tim) [openssh.xml.in] make FMRI match what package scripts use.
tim [Tue, 24 Jul 2007 20:13:42 +0000 (20:13 +0000)] 
 - (tim) [openssh.xml.in] make FMRI match what package scripts use.

16 years ago - (djm) bz#1325: Fix SELinux in permissive mode where it would
djm [Wed, 27 Jun 2007 22:48:02 +0000 (22:48 +0000)] 
 - (djm) bz#1325: Fix SELinux in permissive mode where it would
   incorrectly fatal() on errors. patch from cjwatson AT debian.org;
   ok dtucker

16 years ago - (dtucker) [atomicio.c configure.ac openbsd-compat/Makefile.in
dtucker [Mon, 25 Jun 2007 12:15:12 +0000 (12:15 +0000)] 
 - (dtucker) [atomicio.c configure.ac openbsd-compat/Makefile.in
   openbsd-compat/bsd-poll.{c,h} openbsd-compat/openbsd-compat.h]
   Add an implementation of poll() built on top of select(2).  Code from
   OpenNTPD with changes suggested by djm.  ok djm@

16 years ago - dtucker@cvs.openbsd.org 2007/06/25 12:02:27
dtucker [Mon, 25 Jun 2007 12:08:10 +0000 (12:08 +0000)] 
   - dtucker@cvs.openbsd.org 2007/06/25 12:02:27
     [atomicio.c]
     Include <poll.h> like the man page says rather than <sys/poll.h>.  ok djm@

16 years ago - (dtucker) [atomicio.c] Test for EWOULDBLOCK in atomiciov to match
dtucker [Mon, 25 Jun 2007 09:06:53 +0000 (09:06 +0000)] 
 - (dtucker) [atomicio.c] Test for EWOULDBLOCK in atomiciov to match
   atomicio.

16 years ago - dtucker@cvs.openbsd.org 2007/06/25 08:20:03
dtucker [Mon, 25 Jun 2007 09:04:46 +0000 (09:04 +0000)] 
   - dtucker@cvs.openbsd.org 2007/06/25 08:20:03
     [channels.c]
     Correct test for window updates every three packets; prevents sending
     window updates for every single packet.  ok markus@

16 years ago - djm@cvs.openbsd.org 2007/06/19 02:04:43
dtucker [Mon, 25 Jun 2007 09:04:12 +0000 (09:04 +0000)] 
   - djm@cvs.openbsd.org 2007/06/19 02:04:43
     [atomicio.c]
     if the fd passed to atomicio/atomiciov() is non blocking, then poll() to
     avoid a spin if it is not yet ready for reading/writing; ok dtucker@

16 years ago - djm@cvs.openbsd.org 2007/06/14 22:48:05
dtucker [Mon, 25 Jun 2007 08:59:17 +0000 (08:59 +0000)] 
   - djm@cvs.openbsd.org 2007/06/14 22:48:05
     [ssh.c]
     when waiting for the multiplex exit status, read until the master end
     writes an entire int of data *and* closes the client_fd; fixes mux
     regression spotted by dtucker, ok dtucker@

16 years ago - djm@cvs.openbsd.org 2007/06/14 21:43:25
dtucker [Mon, 25 Jun 2007 08:34:43 +0000 (08:34 +0000)] 
   - djm@cvs.openbsd.org 2007/06/14 21:43:25
     [ssh.c]
     handle EINTR when waiting for mux exit status properly

16 years ago - djm@cvs.openbsd.org 2007/06/13 00:21:27
dtucker [Mon, 25 Jun 2007 08:32:33 +0000 (08:32 +0000)] 
   - djm@cvs.openbsd.org 2007/06/13 00:21:27
     [scp.c]
     don't ftruncate() non-regular files; bz#1236 reported by wood AT
     xmission.com; ok dtucker@

16 years ago - (dtucker) [openbsd-compat/openssl-compat.h] Remove redundant definition
dtucker [Thu, 14 Jun 2007 13:47:31 +0000 (13:47 +0000)] 
 - (dtucker) [openbsd-compat/openssl-compat.h] Remove redundant definition
   of USE_BUILTIN_RIJNDAEL since the <0.9.6 test is covered by the
   subsequent <0.9.7 test.

16 years ago - (dtucker) [openbsd-compat/openssl-compat.h] Merge USE_BUILTIN_RIJNDAEL
dtucker [Thu, 14 Jun 2007 13:38:39 +0000 (13:38 +0000)] 
 - (dtucker) [openbsd-compat/openssl-compat.h] Merge USE_BUILTIN_RIJNDAEL
   sections.  Fixes builds with early OpenSSL 0.9.6 versions.

16 years ago - (dtucker) [cipher-ctr.c umac.c openbsd-compat/openssl-compat.h] Move the
dtucker [Thu, 14 Jun 2007 13:21:32 +0000 (13:21 +0000)] 
 - (dtucker) [cipher-ctr.c umac.c openbsd-compat/openssl-compat.h] Move the
   USE_BUILTIN_RIJNDAEL compat goop to openssl-compat.h so it can be
   shared with umac.c.  Allows building with OpenSSL 0.9.5 again including
   umac support.  With tim@ djm@, ok djm.

16 years ago - dtucker@cvs.openbsd.org 2007/06/12 13:54:28
dtucker [Tue, 12 Jun 2007 14:02:07 +0000 (14:02 +0000)] 
   - dtucker@cvs.openbsd.org 2007/06/12 13:54:28
     [scp.c]
     Encode filename with strnvis if the name contains a newline (which can't
     be represented in the scp protocol), from bz #891.  ok markus@

16 years ago - jmc@cvs.openbsd.org 2007/06/12 13:43:55
dtucker [Tue, 12 Jun 2007 14:00:58 +0000 (14:00 +0000)] 
   - jmc@cvs.openbsd.org 2007/06/12 13:43:55
     [ssh.1]
     add -K to SYNOPSIS;

16 years ago - jmc@cvs.openbsd.org 2007/06/12 13:41:03
dtucker [Tue, 12 Jun 2007 14:00:27 +0000 (14:00 +0000)] 
   - jmc@cvs.openbsd.org 2007/06/12 13:41:03
     [ssh-add.1]
     identies -> identities;

16 years ago - dtucker@cvs.openbsd.org 2007/06/12 11:56:15
dtucker [Tue, 12 Jun 2007 13:44:36 +0000 (13:44 +0000)] 
   - dtucker@cvs.openbsd.org 2007/06/12 11:56:15
     [gss-genr.c]
     Pass GSS OID to gss_display_status to provide better information in
     error messages.  Patch from Simon Wilkinson via bz 1220.  ok djm@

16 years ago - djm@cvs.openbsd.org 2007/06/12 11:45:27
dtucker [Tue, 12 Jun 2007 13:44:10 +0000 (13:44 +0000)] 
   - djm@cvs.openbsd.org 2007/06/12 11:45:27
     [ssh.c]
     improved exit message from multiplex slave sessions; bz #1262
     reported by alexandre.nunes AT gmail.com; ok dtucker@

16 years ago - djm@cvs.openbsd.org 2007/06/12 11:15:17
dtucker [Tue, 12 Jun 2007 13:43:16 +0000 (13:43 +0000)] 
   - djm@cvs.openbsd.org 2007/06/12 11:15:17
     [ssh.c ssh.1]
     Add "-K" flag for ssh to set GSSAPIAuthentication=yes and
     GSSAPIDelegateCredentials=yes. This is symmetric with -k (disable GSSAPI)
     and is useful for hosts with /home on Kerberised NFS; bz #1312
     patch from Markus.Kuhn AT cl.cam.ac.uk; ok dtucker@ markus@

16 years ago - djm@cvs.openbsd.org 2007/06/12 11:11:08
dtucker [Tue, 12 Jun 2007 13:41:33 +0000 (13:41 +0000)] 
   - djm@cvs.openbsd.org 2007/06/12 11:11:08
     [ssh.c]
     fix slave exit value when a control master goes away without passing the
     full exit status by ensuring that the slave reads a full int. bz#1261
     reported by frekko AT gmail.com; ok markus@ dtucker@

16 years ago - djm@cvs.openbsd.org 2007/06/12 08:24:20
dtucker [Tue, 12 Jun 2007 13:41:06 +0000 (13:41 +0000)] 
   - djm@cvs.openbsd.org 2007/06/12 08:24:20
     [scp.c]
     make scp try to skip FIFOs rather than blocking when nothing is listening.
     depends on the platform supporting sane O_NONBLOCK semantics for open
     on FIFOs (apparently POSIX does not mandate this), which OpenBSD does.
     bz #856; report by cjwatson AT debian.org; ok markus@

16 years ago - djm@cvs.openbsd.org 2007/06/12 08:20:00
dtucker [Tue, 12 Jun 2007 13:40:39 +0000 (13:40 +0000)] 
   - djm@cvs.openbsd.org 2007/06/12 08:20:00
     [ssh-gss.h gss-serv.c gss-genr.c]
     relocate server-only GSSAPI code from libssh to server; bz #1225
     patch from simon AT sxw.org.uk; ok markus@ dtucker@

16 years ago - djm@cvs.openbsd.org 2007/06/12 07:41:00
dtucker [Tue, 12 Jun 2007 13:39:52 +0000 (13:39 +0000)] 
   - djm@cvs.openbsd.org 2007/06/12 07:41:00
     [ssh-add.1]
     better document ssh-add's -d option (delete identies from agent), bz#1224
     new text based on some provided by andrewmc-debian AT celt.dias.ie;
     ok dtucker@

16 years ago - markus@cvs.openbsd.org 2007/06/11 09:14:00
dtucker [Tue, 12 Jun 2007 13:38:53 +0000 (13:38 +0000)] 
   - markus@cvs.openbsd.org 2007/06/11 09:14:00
     [channels.h]
     increase default channel windows; ok djm

16 years ago - markus@cvs.openbsd.org 2007/06/11 08:04:44
djm [Mon, 11 Jun 2007 08:33:15 +0000 (08:33 +0000)] 
   - markus@cvs.openbsd.org 2007/06/11 08:04:44
     [channels.c]
     send 'window adjust' messages every tree packets and do not wait
     until 50% of the window is consumed.  ok djm dtucker

16 years ago - (dtucker) [includes.h] Bug #1243: HAVE_PATHS -> HAVE_PATHS_H. Should
dtucker [Mon, 11 Jun 2007 04:44:02 +0000 (04:44 +0000)] 
 - (dtucker) [includes.h] Bug #1243: HAVE_PATHS -> HAVE_PATHS_H.  Should
   prevent warnings about redefinitions of various things in paths.h.
   Spotted by cartmanltd at hotmail.com.

16 years ago - (dtucker) [openbsd-compat/bsd-misc.c] According to the spec the "remainder"
dtucker [Mon, 11 Jun 2007 04:34:53 +0000 (04:34 +0000)] 
 - (dtucker) [openbsd-compat/bsd-misc.c] According to the spec the "remainder"
   argument to nanosleep may be NULL.  Currently this never happens in OpenSSH,
   but check anyway in case this changes or the code gets used elsewhere.

16 years ago - (djm) [configure.ac umac.c] If platform doesn't provide swap32(3), then
djm [Mon, 11 Jun 2007 04:15:42 +0000 (04:15 +0000)] 
 - (djm) [configure.ac umac.c] If platform doesn't provide swap32(3), then
   fallback to provided bit-swizzing functions

16 years ago - jmc@cvs.openbsd.org 2007/06/08 07:48:09
djm [Mon, 11 Jun 2007 04:07:12 +0000 (04:07 +0000)] 
   - jmc@cvs.openbsd.org 2007/06/08 07:48:09
     [sshd_config.5]
     oops, here too: put the MAC list into a display, like we do for
     ciphers, since groff has trouble with wide lines;

16 years ago - jmc@cvs.openbsd.org 2007/06/08 07:43:46
djm [Mon, 11 Jun 2007 04:06:32 +0000 (04:06 +0000)] 
   - jmc@cvs.openbsd.org 2007/06/08 07:43:46
     [ssh_config.5]
     put the MAC list into a display, like we do for ciphers,
     since groff has trouble handling wide lines;

16 years ago - pvalchev@cvs.openbsd.org 2007/06/08 04:40:40
djm [Mon, 11 Jun 2007 04:04:42 +0000 (04:04 +0000)] 
   - pvalchev@cvs.openbsd.org 2007/06/08 04:40:40
     [ssh_config]
     Add a "MACs" line after "Ciphers" with the default MAC algorithms,
     to ease people who want to tweak both (eg. for performance reasons).
     ok deraadt@ djm@ dtucker@

16 years ago - pvalchev@cvs.openbsd.org 2007/06/07 19:37:34
djm [Mon, 11 Jun 2007 04:01:42 +0000 (04:01 +0000)] 
   - pvalchev@cvs.openbsd.org 2007/06/07 19:37:34
     [kex.h mac.c mac.h monitor_wrap.c myproposal.h packet.c ssh.1]
     [ssh_config.5 sshd.8 sshd_config.5]
     Add a new MAC algorithm for data integrity, UMAC-64 (not default yet,
     must specify umac-64@openssh.com). Provides about 20% end-to-end speedup
     compared to hmac-md5. Represents a different approach to message
     authentication to that of HMAC that may be beneficial if HMAC based on
     one of its underlying hash algorithms is found to be vulnerable to a
     new attack.  http://www.ietf.org/rfc/rfc4418.txt
     in conjunction with and OK djm@

16 years ago - (djm) Bugzilla #1306: silence spurious error messages from hang-on-exit
djm [Mon, 11 Jun 2007 03:03:16 +0000 (03:03 +0000)] 
 - (djm) Bugzilla #1306: silence spurious error messages from hang-on-exit
   fix; tested by dtucker@ and jochen.kirn AT gmail.com

16 years agospacing
djm [Mon, 11 Jun 2007 02:52:24 +0000 (02:52 +0000)] 
spacing

17 years ago - (dtucker) [mdoc2man.awk] Add support for %R references, used for RFCs.
dtucker [Tue, 5 Jun 2007 10:01:16 +0000 (10:01 +0000)] 
 - (dtucker) [mdoc2man.awk] Add support for %R references, used for RFCs.

17 years ago - (dtucker) [mdoc2man.awk] Remove trailing "$" from Mdocdate regex so
dtucker [Tue, 5 Jun 2007 09:30:47 +0000 (09:30 +0000)] 
 - (dtucker) [mdoc2man.awk] Remove trailing "$" from Mdocdate regex so
   mindrot's cvs doesn't expand it on us.

17 years ago - (dtucker) [mdoc2man.awk] Teach it to deal with $Mdocdate tags that
dtucker [Tue, 5 Jun 2007 09:16:59 +0000 (09:16 +0000)] 
 - (dtucker) [mdoc2man.awk] Teach it to deal with $Mdocdate tags that
   OpenBSD's cvs now adds.

17 years ago - djm@cvs.openbsd.org 2007/06/05 06:52:37
dtucker [Tue, 5 Jun 2007 08:30:18 +0000 (08:30 +0000)] 
   - djm@cvs.openbsd.org 2007/06/05 06:52:37
     [kex.c monitor_wrap.c packet.c mac.h kex.h mac.c]
     Preserve MAC ctx between packets, saving 2xhash calls per-packet.
     Yields around a 12-16% end-to-end speedup for arcfour256/hmac-md5
     patch from markus@ tested dtucker@ and myself, ok markus@ and me (I'm
     committing at his request)

17 years ago - djm@cvs.openbsd.org 2007/06/02 09:04:58
dtucker [Tue, 5 Jun 2007 08:29:35 +0000 (08:29 +0000)] 
   - djm@cvs.openbsd.org 2007/06/02 09:04:58
     [bufbn.c]
     memory leak on error path; from arnaud.lacombe.1 AT ulaval.ca

17 years ago - djm@cvs.openbsd.org 2007/05/31 23:34:29
dtucker [Tue, 5 Jun 2007 08:28:20 +0000 (08:28 +0000)] 
   - djm@cvs.openbsd.org 2007/05/31 23:34:29
     [packet.c]
     gc unreachable code; spotted by Tavis Ormandy

17 years ago - jmc@cvs.openbsd.org 2007/05/31 19:20:16
dtucker [Tue, 5 Jun 2007 08:27:13 +0000 (08:27 +0000)] 
   - jmc@cvs.openbsd.org 2007/05/31 19:20:16
     [scp.1 ssh_config.5 sftp-server.8 ssh-agent.1 sshd_config.5 sftp.1
     ssh-keygen.1 ssh-keyscan.1 ssh-add.1 sshd.8 ssh.1 ssh-keysign.8]
     convert to new .Dd format;
     (We will need to teach mdoc2man.awk to understand this too.)

17 years ago - djm@cvs.openbsd.org 2007/05/30 05:58:13
dtucker [Tue, 5 Jun 2007 08:23:28 +0000 (08:23 +0000)] 
   - djm@cvs.openbsd.org 2007/05/30 05:58:13
     [kex.c]
     tidy: KNF, ARGSUSED and u_int

17 years ago - djm@cvs.openbsd.org 2007/05/22 10:18:52
dtucker [Tue, 5 Jun 2007 08:22:32 +0000 (08:22 +0000)] 
   - djm@cvs.openbsd.org 2007/05/22 10:18:52
     [sshd.c]
     zap double include; from p_nowaczyk AT o2.pl
     (not required in -portable, Id sync only)

17 years ago - (dtucker) [auth-pam.c] Return empty string if fgets fails in
dtucker [Sun, 20 May 2007 05:26:07 +0000 (05:26 +0000)] 
 - (dtucker) [auth-pam.c] Return empty string if fgets fails in
   sshpam_tty_conv.  Patch from ldv at altlinux.org.

17 years ago - (dtucker) [auth-pam.c] malloc+memset -> calloc. Patch from
dtucker [Sun, 20 May 2007 05:20:08 +0000 (05:20 +0000)] 
 - (dtucker) [auth-pam.c] malloc+memset -> calloc.  Patch from
   ldv at altlinux.org.

17 years ago - jolan@cvs.openbsd.org 2007/05/17 23:53:41
dtucker [Sun, 20 May 2007 05:11:33 +0000 (05:11 +0000)] 
   - jolan@cvs.openbsd.org 2007/05/17 23:53:41
     [sshconnect2.c]
     djm owes me a vb and a tism cd for breaking ssh compilation

17 years ago - djm@cvs.openbsd.org 2007/05/17 20:52:13
dtucker [Sun, 20 May 2007 05:10:16 +0000 (05:10 +0000)] 
   - djm@cvs.openbsd.org 2007/05/17 20:52:13
     [monitor.c]
     pass received SIGINT from monitor to postauth child so it can clean
     up properly. bz#1196, patch from senthilkumar_sen AT hotpop.com;
     ok markus@

17 years ago - djm@cvs.openbsd.org 2007/05/17 20:48:13
dtucker [Sun, 20 May 2007 05:09:42 +0000 (05:09 +0000)] 
   - djm@cvs.openbsd.org 2007/05/17 20:48:13
     [sshconnect2.c]
     fall back to gethostname() when the outgoing connection is not
     on a socket, such as is the case when ProxyCommand is used.
     Gives hostbased auth an opportunity to work; bz#616, report
     and feedback stuart AT kaloram.com; ok markus@

17 years ago - djm@cvs.openbsd.org 2007/05/17 07:55:29
dtucker [Sun, 20 May 2007 05:09:04 +0000 (05:09 +0000)] 
   - djm@cvs.openbsd.org 2007/05/17 07:55:29
     [sftp-server.c]
     bz#1286 stop reading and processing commands when input or output buffer
     is nearly full, otherwise sftp-server would happily try to grow the
     input/output buffers past the maximum supported by the buffer API and
     promptly fatal()
     based on patch from Thue Janus Kristensen; feedback & ok dtucker@

17 years ago - djm@cvs.openbsd.org 2007/05/17 07:50:31
dtucker [Sun, 20 May 2007 05:08:15 +0000 (05:08 +0000)] 
   - djm@cvs.openbsd.org 2007/05/17 07:50:31
     [log.c]
     save and restore errno when logging; ok deraadt@

17 years ago - dtucker@cvs.openbsd.org 2007/04/23 10:15:39
dtucker [Sun, 20 May 2007 05:03:15 +0000 (05:03 +0000)] 
   - dtucker@cvs.openbsd.org 2007/04/23 10:15:39
     [servconf.c]
     Remove debug() left over from development.  ok deraadt@

17 years ago - stevesk@cvs.openbsd.org 2007/04/18 01:12:43
dtucker [Sun, 20 May 2007 04:59:32 +0000 (04:59 +0000)] 
   - stevesk@cvs.openbsd.org 2007/04/18 01:12:43
     [sftp-server.c]
     cast "%llu" format spec to (unsigned long long); do not assume a
     u_int64_t arg is the same as 'unsigned long long'.
     from Dmitry V. Levin <ldv@altlinux.org>
     ok markus@ 'Yes, that looks correct' millert@

17 years ago - stevesk@cvs.openbsd.org 2007/04/14 22:01:58
dtucker [Sun, 20 May 2007 04:58:41 +0000 (04:58 +0000)] 
   - stevesk@cvs.openbsd.org 2007/04/14 22:01:58
     [auth2.c]
     remove unused macro; from Dmitry V. Levin <ldv@altlinux.org>

17 years ago20070509
tim [Wed, 9 May 2007 22:57:43 +0000 (22:57 +0000)] 
20070509
 - (tim) [configure.ac] Bug #1287: Add missing test for ucred.h.

17 years agotrim pasto
dtucker [Sun, 29 Apr 2007 07:14:48 +0000 (07:14 +0000)] 
trim pasto

17 years ago - (dtucker) [configure.ac defines.h] Have configure check for offsetof
dtucker [Sun, 29 Apr 2007 05:06:44 +0000 (05:06 +0000)] 
 - (dtucker) [configure.ac defines.h] Have configure check for offsetof
   to prevent redefinition warnings.

17 years ago - (dtucker) [configure.ac defines.h] Prevent warnings about __attribute__
dtucker [Sun, 29 Apr 2007 04:49:21 +0000 (04:49 +0000)] 
 - (dtucker) [configure.ac defines.h] Prevent warnings about __attribute__
   __nonnull__ for versions of GCC that don't support it.

17 years ago - (dtucker) [configure.ac defines.h] Have configure check for MAXSYMLINKS
dtucker [Sun, 29 Apr 2007 04:39:02 +0000 (04:39 +0000)] 
 - (dtucker) [configure.ac defines.h] Have configure check for MAXSYMLINKS
   so we don't get redefinition warnings.

This page took 2.256357 seconds and 4 git commands to generate.