]> andersk Git - openssh.git/log
openssh.git
16 years ago - (dtucker) [configure.ac defines.h] Shadow expiry does not work on QNX6 V_4_7
dtucker [Thu, 27 Sep 2007 10:46:14 +0000 (10:46 +0000)] 
 - (dtucker) [configure.ac defines.h] Shadow expiry does not work on QNX6
   so disable it for that platform.  From bacon at cs nyu edu.

16 years ago - (dtucker) [configure.ac atomicio.c] Fall back to including <sys/poll.h> if
dtucker [Thu, 27 Sep 2007 10:43:48 +0000 (10:43 +0000)] 
 - (dtucker) [configure.ac atomicio.c] Fall back to including <sys/poll.h> if
   we don't have <poll.h> (eq QNX).  From bacon at cs nyu edu.

16 years ago - (tim) [defines.h] Fix regression in long password support on OpenServer 6.
tim [Mon, 17 Sep 2007 15:33:47 +0000 (15:33 +0000)] 
 - (tim) [defines.h] Fix regression in long password support on OpenServer 6.
   Problem report and additional testing rac AT tenzing.org.

16 years ago - (tim) [configure.ac] Autoconf didn't define HAVE_LIBIAF because we
tim [Mon, 10 Sep 2007 23:25:16 +0000 (23:25 +0000)] 
 - (tim) [configure.ac] Autoconf didn't define HAVE_LIBIAF because we
   did a AC_CHECK_FUNCS within the AC_CHECK_LIB test.

16 years agodon't say it twice V_4_7_P1
djm [Tue, 4 Sep 2007 06:49:09 +0000 (06:49 +0000)] 
don't say it twice

16 years agocredit Jan Pechanec
djm [Tue, 4 Sep 2007 04:26:32 +0000 (04:26 +0000)] 
credit Jan Pechanec

16 years agoMention Jan Pechanec
dtucker [Tue, 4 Sep 2007 04:05:24 +0000 (04:05 +0000)] 
Mention Jan Pechanec

16 years ago - (dtucker) [INSTALL] Link to tcpwrappers.
dtucker [Fri, 17 Aug 2007 12:52:05 +0000 (12:52 +0000)] 
 - (dtucker) [INSTALL] Link to tcpwrappers.

16 years ago - (dtucker) [INSTALL] Give PAM its own heading.
dtucker [Fri, 17 Aug 2007 12:12:14 +0000 (12:12 +0000)] 
 - (dtucker) [INSTALL] Give PAM its own heading.

16 years ago - (dtucker) [INSTALL] the pid file is sshd.pid not ssh.pid.
dtucker [Fri, 17 Aug 2007 12:10:10 +0000 (12:10 +0000)] 
 - (dtucker) [INSTALL] the pid file is sshd.pid not ssh.pid.

16 years ago - (dtucker) [INSTALL] Group the parts describing random options and PAM
dtucker [Fri, 17 Aug 2007 12:03:09 +0000 (12:03 +0000)] 
 - (dtucker) [INSTALL] Group the parts describing random options and PAM
   implementations together which is hopefully more coherent.

16 years agotypo
dtucker [Fri, 17 Aug 2007 11:40:22 +0000 (11:40 +0000)] 
typo

16 years ago - (dtucker) [sshd.8] Many Linux variants use a single "!" to denote locked
dtucker [Thu, 16 Aug 2007 23:42:32 +0000 (23:42 +0000)] 
 - (dtucker) [sshd.8] Many Linux variants use a single "!" to denote locked
   accounts and that's what the code looks for, so make man page and code
   agree.  Pointed out by Roumen Petrov.

16 years ago - (dtucker) [session.c] Call PAM cleanup functions for unauthenticated
dtucker [Thu, 16 Aug 2007 13:28:04 +0000 (13:28 +0000)] 
 - (dtucker) [session.c] Call PAM cleanup functions for unauthenticated
   connections too.  Based on a patch from Sandro Wefel, with & ok djm@

16 years ago - stevesk@cvs.openbsd.org 2007/08/15 12:13:41
dtucker [Wed, 15 Aug 2007 12:20:22 +0000 (12:20 +0000)] 
   - stevesk@cvs.openbsd.org 2007/08/15 12:13:41
     [ssh_config.5]
     tun device forwarding now honours ExitOnForwardFailure; ok markus@

16 years ago - (dtucker) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec
dtucker [Wed, 15 Aug 2007 09:22:20 +0000 (09:22 +0000)] 
 - (dtucker) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec
   contrib/suse/openssh.spec] Crank version.

16 years ago - (dtucker) [openbsd-compat/bsd-cray.c] Remove debug from signal handler.
dtucker [Wed, 15 Aug 2007 09:17:43 +0000 (09:17 +0000)] 
 - (dtucker) [openbsd-compat/bsd-cray.c] Remove debug from signal handler.
   ok djm@

16 years ago - markus@cvs.openbsd.org 2007/08/15 08:16:49
dtucker [Wed, 15 Aug 2007 09:14:52 +0000 (09:14 +0000)] 
   - markus@cvs.openbsd.org 2007/08/15 08:16:49
     [version.h]
     openssh 4.7

16 years ago - markus@cvs.openbsd.org 2007/08/15 08:14:46
dtucker [Wed, 15 Aug 2007 09:13:41 +0000 (09:13 +0000)] 
   - markus@cvs.openbsd.org 2007/08/15 08:14:46
     [clientloop.c]
     do NOT fall back to the trused x11 cookie if generation of an untrusted
     cookie fails; from security-alert at sun.com; ok dtucker

16 years ago - (dtucker) [session.c] Bug #1339: ensure that pam_setcred() is always
dtucker [Mon, 13 Aug 2007 13:11:56 +0000 (13:11 +0000)] 
 - (dtucker) [session.c] Bug #1339: ensure that pam_setcred() is always
   called with PAM_ESTABLISH_CRED at least once, which resolves a problem
   with pam_dhkeys.  Patch from David Leonard, ok djm@

16 years ago - (dtucker) [configure.ac] Bug #1343: Set DISABLE_FD_PASSING for QNX6. From.
dtucker [Fri, 10 Aug 2007 04:36:12 +0000 (04:36 +0000)] 
 - (dtucker) [configure.ac] Bug #1343: Set DISABLE_FD_PASSING for QNX6. From.
   Matt Kraai, ok djm@.

16 years ago - (dtucker) [auth-pam.c] Use sigdie here too. ok djm@
dtucker [Fri, 10 Aug 2007 04:32:34 +0000 (04:32 +0000)] 
 - (dtucker) [auth-pam.c] Use sigdie here too.  ok djm@

16 years agoCredit Bernhard Simon who also reported this.
dtucker [Thu, 9 Aug 2007 05:03:23 +0000 (05:03 +0000)] 
Credit Bernhard Simon who also reported this.

16 years ago - (dtucker) [defines.h] Remove _PATH_{CSHELL,SHELLS} which aren't
dtucker [Thu, 9 Aug 2007 04:37:52 +0000 (04:37 +0000)] 
 - (dtucker) [defines.h] Remove _PATH_{CSHELL,SHELLS} which aren't
   used anywhere and are a potential source of warnings.

16 years ago - (dtucker) [README.platform] Document the interaction between PermitRootLogin
dtucker [Thu, 9 Aug 2007 04:31:53 +0000 (04:31 +0000)] 
 - (dtucker) [README.platform] Document the interaction between PermitRootLogin
   and the AIX native login restrictions.

16 years ago - (dtucker) [openbsd-compat/port-aix.c] Comment typo.
dtucker [Thu, 9 Aug 2007 04:29:47 +0000 (04:29 +0000)] 
 - (dtucker) [openbsd-compat/port-aix.c] Comment typo.

16 years ago - djm@cvs.openbsd.org 2007/08/07 07:32:53
djm [Wed, 8 Aug 2007 04:32:41 +0000 (04:32 +0000)] 
   - djm@cvs.openbsd.org 2007/08/07 07:32:53
     [clientloop.c clientloop.h ssh.c]
     bz#1232: ensure that any specified LocalCommand is executed after the
     tunnel device is opened. Also, make failures to open a tunnel device
     fatal when ExitOnForwardFailure is active.
     Reported by h.goebel AT goebel-consult.de; ok dtucker markus reyk deraadt

16 years ago - sobrado@cvs.openbsd.org 2007/08/06 19:16:06
djm [Wed, 8 Aug 2007 04:29:58 +0000 (04:29 +0000)] 
   - sobrado@cvs.openbsd.org 2007/08/06 19:16:06
     [scp.1 scp.c]
     the ellipsis is not an optional argument; while here, sync the usage
     and synopsis of commands
     lots of good ideas by jmc@
     ok jmc@

16 years ago - ray@cvs.openbsd.org 2007/07/12 05:48:05
djm [Wed, 8 Aug 2007 04:28:26 +0000 (04:28 +0000)] 
   - ray@cvs.openbsd.org 2007/07/12 05:48:05
     [key.c]
     Delint: remove some unreachable statements, from Bret Lambert.
     OK markus@ and dtucker@.

16 years ago - (tim) [buildpkg.sh.in] s|$FAKE_ROOT/${sysconfdir}|$FAKE_ROOT${sysconfdir}|
tim [Wed, 25 Jul 2007 04:40:59 +0000 (04:40 +0000)] 
 - (tim) [buildpkg.sh.in] s|$FAKE_ROOT/${sysconfdir}|$FAKE_ROOT${sysconfdir}|

16 years ago - (tim) [buildpkg.sh.in openssh.xml.in] Allow more flexibility where smf(5)
tim [Wed, 25 Jul 2007 04:16:07 +0000 (04:16 +0000)] 
 - (tim) [buildpkg.sh.in openssh.xml.in] Allow more flexibility where smf(5)
   files are installed.

16 years ago - (tim) [openbsd-compat/regress/closefromtest.c] Bug 1345: fix open() call.
tim [Wed, 25 Jul 2007 03:54:09 +0000 (03:54 +0000)] 
 - (tim) [openbsd-compat/regress/closefromtest.c] Bug 1345: fix open() call.
   Report/patch by David.Leonard AT quest.com

16 years ago - (tim) [openssh.xml.in] make FMRI match what package scripts use.
tim [Tue, 24 Jul 2007 20:13:42 +0000 (20:13 +0000)] 
 - (tim) [openssh.xml.in] make FMRI match what package scripts use.

16 years ago - (djm) bz#1325: Fix SELinux in permissive mode where it would
djm [Wed, 27 Jun 2007 22:48:02 +0000 (22:48 +0000)] 
 - (djm) bz#1325: Fix SELinux in permissive mode where it would
   incorrectly fatal() on errors. patch from cjwatson AT debian.org;
   ok dtucker

16 years ago - (dtucker) [atomicio.c configure.ac openbsd-compat/Makefile.in
dtucker [Mon, 25 Jun 2007 12:15:12 +0000 (12:15 +0000)] 
 - (dtucker) [atomicio.c configure.ac openbsd-compat/Makefile.in
   openbsd-compat/bsd-poll.{c,h} openbsd-compat/openbsd-compat.h]
   Add an implementation of poll() built on top of select(2).  Code from
   OpenNTPD with changes suggested by djm.  ok djm@

16 years ago - dtucker@cvs.openbsd.org 2007/06/25 12:02:27
dtucker [Mon, 25 Jun 2007 12:08:10 +0000 (12:08 +0000)] 
   - dtucker@cvs.openbsd.org 2007/06/25 12:02:27
     [atomicio.c]
     Include <poll.h> like the man page says rather than <sys/poll.h>.  ok djm@

16 years ago - (dtucker) [atomicio.c] Test for EWOULDBLOCK in atomiciov to match
dtucker [Mon, 25 Jun 2007 09:06:53 +0000 (09:06 +0000)] 
 - (dtucker) [atomicio.c] Test for EWOULDBLOCK in atomiciov to match
   atomicio.

16 years ago - dtucker@cvs.openbsd.org 2007/06/25 08:20:03
dtucker [Mon, 25 Jun 2007 09:04:46 +0000 (09:04 +0000)] 
   - dtucker@cvs.openbsd.org 2007/06/25 08:20:03
     [channels.c]
     Correct test for window updates every three packets; prevents sending
     window updates for every single packet.  ok markus@

16 years ago - djm@cvs.openbsd.org 2007/06/19 02:04:43
dtucker [Mon, 25 Jun 2007 09:04:12 +0000 (09:04 +0000)] 
   - djm@cvs.openbsd.org 2007/06/19 02:04:43
     [atomicio.c]
     if the fd passed to atomicio/atomiciov() is non blocking, then poll() to
     avoid a spin if it is not yet ready for reading/writing; ok dtucker@

16 years ago - djm@cvs.openbsd.org 2007/06/14 22:48:05
dtucker [Mon, 25 Jun 2007 08:59:17 +0000 (08:59 +0000)] 
   - djm@cvs.openbsd.org 2007/06/14 22:48:05
     [ssh.c]
     when waiting for the multiplex exit status, read until the master end
     writes an entire int of data *and* closes the client_fd; fixes mux
     regression spotted by dtucker, ok dtucker@

16 years ago - djm@cvs.openbsd.org 2007/06/14 21:43:25
dtucker [Mon, 25 Jun 2007 08:34:43 +0000 (08:34 +0000)] 
   - djm@cvs.openbsd.org 2007/06/14 21:43:25
     [ssh.c]
     handle EINTR when waiting for mux exit status properly

16 years ago - djm@cvs.openbsd.org 2007/06/13 00:21:27
dtucker [Mon, 25 Jun 2007 08:32:33 +0000 (08:32 +0000)] 
   - djm@cvs.openbsd.org 2007/06/13 00:21:27
     [scp.c]
     don't ftruncate() non-regular files; bz#1236 reported by wood AT
     xmission.com; ok dtucker@

16 years ago - (dtucker) [openbsd-compat/openssl-compat.h] Remove redundant definition
dtucker [Thu, 14 Jun 2007 13:47:31 +0000 (13:47 +0000)] 
 - (dtucker) [openbsd-compat/openssl-compat.h] Remove redundant definition
   of USE_BUILTIN_RIJNDAEL since the <0.9.6 test is covered by the
   subsequent <0.9.7 test.

16 years ago - (dtucker) [openbsd-compat/openssl-compat.h] Merge USE_BUILTIN_RIJNDAEL
dtucker [Thu, 14 Jun 2007 13:38:39 +0000 (13:38 +0000)] 
 - (dtucker) [openbsd-compat/openssl-compat.h] Merge USE_BUILTIN_RIJNDAEL
   sections.  Fixes builds with early OpenSSL 0.9.6 versions.

16 years ago - (dtucker) [cipher-ctr.c umac.c openbsd-compat/openssl-compat.h] Move the
dtucker [Thu, 14 Jun 2007 13:21:32 +0000 (13:21 +0000)] 
 - (dtucker) [cipher-ctr.c umac.c openbsd-compat/openssl-compat.h] Move the
   USE_BUILTIN_RIJNDAEL compat goop to openssl-compat.h so it can be
   shared with umac.c.  Allows building with OpenSSL 0.9.5 again including
   umac support.  With tim@ djm@, ok djm.

16 years ago - dtucker@cvs.openbsd.org 2007/06/12 13:54:28
dtucker [Tue, 12 Jun 2007 14:02:07 +0000 (14:02 +0000)] 
   - dtucker@cvs.openbsd.org 2007/06/12 13:54:28
     [scp.c]
     Encode filename with strnvis if the name contains a newline (which can't
     be represented in the scp protocol), from bz #891.  ok markus@

16 years ago - jmc@cvs.openbsd.org 2007/06/12 13:43:55
dtucker [Tue, 12 Jun 2007 14:00:58 +0000 (14:00 +0000)] 
   - jmc@cvs.openbsd.org 2007/06/12 13:43:55
     [ssh.1]
     add -K to SYNOPSIS;

16 years ago - jmc@cvs.openbsd.org 2007/06/12 13:41:03
dtucker [Tue, 12 Jun 2007 14:00:27 +0000 (14:00 +0000)] 
   - jmc@cvs.openbsd.org 2007/06/12 13:41:03
     [ssh-add.1]
     identies -> identities;

16 years ago - dtucker@cvs.openbsd.org 2007/06/12 11:56:15
dtucker [Tue, 12 Jun 2007 13:44:36 +0000 (13:44 +0000)] 
   - dtucker@cvs.openbsd.org 2007/06/12 11:56:15
     [gss-genr.c]
     Pass GSS OID to gss_display_status to provide better information in
     error messages.  Patch from Simon Wilkinson via bz 1220.  ok djm@

16 years ago - djm@cvs.openbsd.org 2007/06/12 11:45:27
dtucker [Tue, 12 Jun 2007 13:44:10 +0000 (13:44 +0000)] 
   - djm@cvs.openbsd.org 2007/06/12 11:45:27
     [ssh.c]
     improved exit message from multiplex slave sessions; bz #1262
     reported by alexandre.nunes AT gmail.com; ok dtucker@

16 years ago - djm@cvs.openbsd.org 2007/06/12 11:15:17
dtucker [Tue, 12 Jun 2007 13:43:16 +0000 (13:43 +0000)] 
   - djm@cvs.openbsd.org 2007/06/12 11:15:17
     [ssh.c ssh.1]
     Add "-K" flag for ssh to set GSSAPIAuthentication=yes and
     GSSAPIDelegateCredentials=yes. This is symmetric with -k (disable GSSAPI)
     and is useful for hosts with /home on Kerberised NFS; bz #1312
     patch from Markus.Kuhn AT cl.cam.ac.uk; ok dtucker@ markus@

16 years ago - djm@cvs.openbsd.org 2007/06/12 11:11:08
dtucker [Tue, 12 Jun 2007 13:41:33 +0000 (13:41 +0000)] 
   - djm@cvs.openbsd.org 2007/06/12 11:11:08
     [ssh.c]
     fix slave exit value when a control master goes away without passing the
     full exit status by ensuring that the slave reads a full int. bz#1261
     reported by frekko AT gmail.com; ok markus@ dtucker@

16 years ago - djm@cvs.openbsd.org 2007/06/12 08:24:20
dtucker [Tue, 12 Jun 2007 13:41:06 +0000 (13:41 +0000)] 
   - djm@cvs.openbsd.org 2007/06/12 08:24:20
     [scp.c]
     make scp try to skip FIFOs rather than blocking when nothing is listening.
     depends on the platform supporting sane O_NONBLOCK semantics for open
     on FIFOs (apparently POSIX does not mandate this), which OpenBSD does.
     bz #856; report by cjwatson AT debian.org; ok markus@

16 years ago - djm@cvs.openbsd.org 2007/06/12 08:20:00
dtucker [Tue, 12 Jun 2007 13:40:39 +0000 (13:40 +0000)] 
   - djm@cvs.openbsd.org 2007/06/12 08:20:00
     [ssh-gss.h gss-serv.c gss-genr.c]
     relocate server-only GSSAPI code from libssh to server; bz #1225
     patch from simon AT sxw.org.uk; ok markus@ dtucker@

16 years ago - djm@cvs.openbsd.org 2007/06/12 07:41:00
dtucker [Tue, 12 Jun 2007 13:39:52 +0000 (13:39 +0000)] 
   - djm@cvs.openbsd.org 2007/06/12 07:41:00
     [ssh-add.1]
     better document ssh-add's -d option (delete identies from agent), bz#1224
     new text based on some provided by andrewmc-debian AT celt.dias.ie;
     ok dtucker@

16 years ago - markus@cvs.openbsd.org 2007/06/11 09:14:00
dtucker [Tue, 12 Jun 2007 13:38:53 +0000 (13:38 +0000)] 
   - markus@cvs.openbsd.org 2007/06/11 09:14:00
     [channels.h]
     increase default channel windows; ok djm

16 years ago - markus@cvs.openbsd.org 2007/06/11 08:04:44
djm [Mon, 11 Jun 2007 08:33:15 +0000 (08:33 +0000)] 
   - markus@cvs.openbsd.org 2007/06/11 08:04:44
     [channels.c]
     send 'window adjust' messages every tree packets and do not wait
     until 50% of the window is consumed.  ok djm dtucker

16 years ago - (dtucker) [includes.h] Bug #1243: HAVE_PATHS -> HAVE_PATHS_H. Should
dtucker [Mon, 11 Jun 2007 04:44:02 +0000 (04:44 +0000)] 
 - (dtucker) [includes.h] Bug #1243: HAVE_PATHS -> HAVE_PATHS_H.  Should
   prevent warnings about redefinitions of various things in paths.h.
   Spotted by cartmanltd at hotmail.com.

16 years ago - (dtucker) [openbsd-compat/bsd-misc.c] According to the spec the "remainder"
dtucker [Mon, 11 Jun 2007 04:34:53 +0000 (04:34 +0000)] 
 - (dtucker) [openbsd-compat/bsd-misc.c] According to the spec the "remainder"
   argument to nanosleep may be NULL.  Currently this never happens in OpenSSH,
   but check anyway in case this changes or the code gets used elsewhere.

16 years ago - (djm) [configure.ac umac.c] If platform doesn't provide swap32(3), then
djm [Mon, 11 Jun 2007 04:15:42 +0000 (04:15 +0000)] 
 - (djm) [configure.ac umac.c] If platform doesn't provide swap32(3), then
   fallback to provided bit-swizzing functions

16 years ago - jmc@cvs.openbsd.org 2007/06/08 07:48:09
djm [Mon, 11 Jun 2007 04:07:12 +0000 (04:07 +0000)] 
   - jmc@cvs.openbsd.org 2007/06/08 07:48:09
     [sshd_config.5]
     oops, here too: put the MAC list into a display, like we do for
     ciphers, since groff has trouble with wide lines;

16 years ago - jmc@cvs.openbsd.org 2007/06/08 07:43:46
djm [Mon, 11 Jun 2007 04:06:32 +0000 (04:06 +0000)] 
   - jmc@cvs.openbsd.org 2007/06/08 07:43:46
     [ssh_config.5]
     put the MAC list into a display, like we do for ciphers,
     since groff has trouble handling wide lines;

16 years ago - pvalchev@cvs.openbsd.org 2007/06/08 04:40:40
djm [Mon, 11 Jun 2007 04:04:42 +0000 (04:04 +0000)] 
   - pvalchev@cvs.openbsd.org 2007/06/08 04:40:40
     [ssh_config]
     Add a "MACs" line after "Ciphers" with the default MAC algorithms,
     to ease people who want to tweak both (eg. for performance reasons).
     ok deraadt@ djm@ dtucker@

16 years ago - pvalchev@cvs.openbsd.org 2007/06/07 19:37:34
djm [Mon, 11 Jun 2007 04:01:42 +0000 (04:01 +0000)] 
   - pvalchev@cvs.openbsd.org 2007/06/07 19:37:34
     [kex.h mac.c mac.h monitor_wrap.c myproposal.h packet.c ssh.1]
     [ssh_config.5 sshd.8 sshd_config.5]
     Add a new MAC algorithm for data integrity, UMAC-64 (not default yet,
     must specify umac-64@openssh.com). Provides about 20% end-to-end speedup
     compared to hmac-md5. Represents a different approach to message
     authentication to that of HMAC that may be beneficial if HMAC based on
     one of its underlying hash algorithms is found to be vulnerable to a
     new attack.  http://www.ietf.org/rfc/rfc4418.txt
     in conjunction with and OK djm@

16 years ago - (djm) Bugzilla #1306: silence spurious error messages from hang-on-exit
djm [Mon, 11 Jun 2007 03:03:16 +0000 (03:03 +0000)] 
 - (djm) Bugzilla #1306: silence spurious error messages from hang-on-exit
   fix; tested by dtucker@ and jochen.kirn AT gmail.com

16 years agospacing
djm [Mon, 11 Jun 2007 02:52:24 +0000 (02:52 +0000)] 
spacing

16 years ago - (dtucker) [mdoc2man.awk] Add support for %R references, used for RFCs.
dtucker [Tue, 5 Jun 2007 10:01:16 +0000 (10:01 +0000)] 
 - (dtucker) [mdoc2man.awk] Add support for %R references, used for RFCs.

16 years ago - (dtucker) [mdoc2man.awk] Remove trailing "$" from Mdocdate regex so
dtucker [Tue, 5 Jun 2007 09:30:47 +0000 (09:30 +0000)] 
 - (dtucker) [mdoc2man.awk] Remove trailing "$" from Mdocdate regex so
   mindrot's cvs doesn't expand it on us.

16 years ago - (dtucker) [mdoc2man.awk] Teach it to deal with $Mdocdate tags that
dtucker [Tue, 5 Jun 2007 09:16:59 +0000 (09:16 +0000)] 
 - (dtucker) [mdoc2man.awk] Teach it to deal with $Mdocdate tags that
   OpenBSD's cvs now adds.

16 years ago - djm@cvs.openbsd.org 2007/06/05 06:52:37
dtucker [Tue, 5 Jun 2007 08:30:18 +0000 (08:30 +0000)] 
   - djm@cvs.openbsd.org 2007/06/05 06:52:37
     [kex.c monitor_wrap.c packet.c mac.h kex.h mac.c]
     Preserve MAC ctx between packets, saving 2xhash calls per-packet.
     Yields around a 12-16% end-to-end speedup for arcfour256/hmac-md5
     patch from markus@ tested dtucker@ and myself, ok markus@ and me (I'm
     committing at his request)

16 years ago - djm@cvs.openbsd.org 2007/06/02 09:04:58
dtucker [Tue, 5 Jun 2007 08:29:35 +0000 (08:29 +0000)] 
   - djm@cvs.openbsd.org 2007/06/02 09:04:58
     [bufbn.c]
     memory leak on error path; from arnaud.lacombe.1 AT ulaval.ca

16 years ago - djm@cvs.openbsd.org 2007/05/31 23:34:29
dtucker [Tue, 5 Jun 2007 08:28:20 +0000 (08:28 +0000)] 
   - djm@cvs.openbsd.org 2007/05/31 23:34:29
     [packet.c]
     gc unreachable code; spotted by Tavis Ormandy

16 years ago - jmc@cvs.openbsd.org 2007/05/31 19:20:16
dtucker [Tue, 5 Jun 2007 08:27:13 +0000 (08:27 +0000)] 
   - jmc@cvs.openbsd.org 2007/05/31 19:20:16
     [scp.1 ssh_config.5 sftp-server.8 ssh-agent.1 sshd_config.5 sftp.1
     ssh-keygen.1 ssh-keyscan.1 ssh-add.1 sshd.8 ssh.1 ssh-keysign.8]
     convert to new .Dd format;
     (We will need to teach mdoc2man.awk to understand this too.)

16 years ago - djm@cvs.openbsd.org 2007/05/30 05:58:13
dtucker [Tue, 5 Jun 2007 08:23:28 +0000 (08:23 +0000)] 
   - djm@cvs.openbsd.org 2007/05/30 05:58:13
     [kex.c]
     tidy: KNF, ARGSUSED and u_int

16 years ago - djm@cvs.openbsd.org 2007/05/22 10:18:52
dtucker [Tue, 5 Jun 2007 08:22:32 +0000 (08:22 +0000)] 
   - djm@cvs.openbsd.org 2007/05/22 10:18:52
     [sshd.c]
     zap double include; from p_nowaczyk AT o2.pl
     (not required in -portable, Id sync only)

17 years ago - (dtucker) [auth-pam.c] Return empty string if fgets fails in
dtucker [Sun, 20 May 2007 05:26:07 +0000 (05:26 +0000)] 
 - (dtucker) [auth-pam.c] Return empty string if fgets fails in
   sshpam_tty_conv.  Patch from ldv at altlinux.org.

17 years ago - (dtucker) [auth-pam.c] malloc+memset -> calloc. Patch from
dtucker [Sun, 20 May 2007 05:20:08 +0000 (05:20 +0000)] 
 - (dtucker) [auth-pam.c] malloc+memset -> calloc.  Patch from
   ldv at altlinux.org.

17 years ago - jolan@cvs.openbsd.org 2007/05/17 23:53:41
dtucker [Sun, 20 May 2007 05:11:33 +0000 (05:11 +0000)] 
   - jolan@cvs.openbsd.org 2007/05/17 23:53:41
     [sshconnect2.c]
     djm owes me a vb and a tism cd for breaking ssh compilation

17 years ago - djm@cvs.openbsd.org 2007/05/17 20:52:13
dtucker [Sun, 20 May 2007 05:10:16 +0000 (05:10 +0000)] 
   - djm@cvs.openbsd.org 2007/05/17 20:52:13
     [monitor.c]
     pass received SIGINT from monitor to postauth child so it can clean
     up properly. bz#1196, patch from senthilkumar_sen AT hotpop.com;
     ok markus@

17 years ago - djm@cvs.openbsd.org 2007/05/17 20:48:13
dtucker [Sun, 20 May 2007 05:09:42 +0000 (05:09 +0000)] 
   - djm@cvs.openbsd.org 2007/05/17 20:48:13
     [sshconnect2.c]
     fall back to gethostname() when the outgoing connection is not
     on a socket, such as is the case when ProxyCommand is used.
     Gives hostbased auth an opportunity to work; bz#616, report
     and feedback stuart AT kaloram.com; ok markus@

17 years ago - djm@cvs.openbsd.org 2007/05/17 07:55:29
dtucker [Sun, 20 May 2007 05:09:04 +0000 (05:09 +0000)] 
   - djm@cvs.openbsd.org 2007/05/17 07:55:29
     [sftp-server.c]
     bz#1286 stop reading and processing commands when input or output buffer
     is nearly full, otherwise sftp-server would happily try to grow the
     input/output buffers past the maximum supported by the buffer API and
     promptly fatal()
     based on patch from Thue Janus Kristensen; feedback & ok dtucker@

17 years ago - djm@cvs.openbsd.org 2007/05/17 07:50:31
dtucker [Sun, 20 May 2007 05:08:15 +0000 (05:08 +0000)] 
   - djm@cvs.openbsd.org 2007/05/17 07:50:31
     [log.c]
     save and restore errno when logging; ok deraadt@

17 years ago - dtucker@cvs.openbsd.org 2007/04/23 10:15:39
dtucker [Sun, 20 May 2007 05:03:15 +0000 (05:03 +0000)] 
   - dtucker@cvs.openbsd.org 2007/04/23 10:15:39
     [servconf.c]
     Remove debug() left over from development.  ok deraadt@

17 years ago - stevesk@cvs.openbsd.org 2007/04/18 01:12:43
dtucker [Sun, 20 May 2007 04:59:32 +0000 (04:59 +0000)] 
   - stevesk@cvs.openbsd.org 2007/04/18 01:12:43
     [sftp-server.c]
     cast "%llu" format spec to (unsigned long long); do not assume a
     u_int64_t arg is the same as 'unsigned long long'.
     from Dmitry V. Levin <ldv@altlinux.org>
     ok markus@ 'Yes, that looks correct' millert@

17 years ago - stevesk@cvs.openbsd.org 2007/04/14 22:01:58
dtucker [Sun, 20 May 2007 04:58:41 +0000 (04:58 +0000)] 
   - stevesk@cvs.openbsd.org 2007/04/14 22:01:58
     [auth2.c]
     remove unused macro; from Dmitry V. Levin <ldv@altlinux.org>

17 years ago20070509
tim [Wed, 9 May 2007 22:57:43 +0000 (22:57 +0000)] 
20070509
 - (tim) [configure.ac] Bug #1287: Add missing test for ucred.h.

17 years agotrim pasto
dtucker [Sun, 29 Apr 2007 07:14:48 +0000 (07:14 +0000)] 
trim pasto

17 years ago - (dtucker) [configure.ac defines.h] Have configure check for offsetof
dtucker [Sun, 29 Apr 2007 05:06:44 +0000 (05:06 +0000)] 
 - (dtucker) [configure.ac defines.h] Have configure check for offsetof
   to prevent redefinition warnings.

17 years ago - (dtucker) [configure.ac defines.h] Prevent warnings about __attribute__
dtucker [Sun, 29 Apr 2007 04:49:21 +0000 (04:49 +0000)] 
 - (dtucker) [configure.ac defines.h] Prevent warnings about __attribute__
   __nonnull__ for versions of GCC that don't support it.

17 years ago - (dtucker) [configure.ac defines.h] Have configure check for MAXSYMLINKS
dtucker [Sun, 29 Apr 2007 04:39:02 +0000 (04:39 +0000)] 
 - (dtucker) [configure.ac defines.h] Have configure check for MAXSYMLINKS
   so we don't get redefinition warnings.

17 years ago - (dtucker) [openbsd-compat/xmmap.c] Include stdlib.h for mkstemp prototype.
dtucker [Sun, 29 Apr 2007 04:02:43 +0000 (04:02 +0000)] 
 - (dtucker) [openbsd-compat/xmmap.c] Include stdlib.h for mkstemp prototype.

17 years ago - (dtucker) [configure.ac openbsd-compat/getrrsetbyname.c] Bug #1299: Use the
dtucker [Sun, 29 Apr 2007 03:58:06 +0000 (03:58 +0000)] 
 - (dtucker) [configure.ac openbsd-compat/getrrsetbyname.c] Bug #1299: Use the
   platform's _res if it has one.  Should fix problem of DNSSEC record lookups
   on NetBSD as reported by Curt Sampson.

17 years ago - (dtucker) [auth-shadow.c loginrec.c] Include time.h for time(2) prototype.
dtucker [Sun, 29 Apr 2007 02:10:57 +0000 (02:10 +0000)] 
 - (dtucker) [auth-shadow.c loginrec.c] Include time.h for time(2) prototype.

17 years ago - (dtucker) [openbsd-compat/bsd-misc.c] Include unistd.h and sys/types.h
dtucker [Sun, 29 Apr 2007 02:06:55 +0000 (02:06 +0000)] 
 - (dtucker) [openbsd-compat/bsd-misc.c] Include unistd.h and sys/types.h
   for select(2) prototype.

17 years ago - (dtucker) [INSTALL] prngd lives at sourceforge these days.
dtucker [Fri, 6 Apr 2007 02:25:08 +0000 (02:25 +0000)] 
 - (dtucker) [INSTALL] prngd lives at sourceforge these days.

17 years ago - (dtucker) [INSTALL] Update the systems that have PAM as standard. Link
dtucker [Fri, 6 Apr 2007 02:21:47 +0000 (02:21 +0000)] 
 - (dtucker) [INSTALL] Update the systems that have PAM as standard.  Link
   to OpenPAM too.

17 years ago20070326
tim [Mon, 26 Mar 2007 16:35:28 +0000 (16:35 +0000)] 
20070326
 - (tim) [auth.c configure.ac defines.h session.c openbsd-compat/port-uw.c
   openbsd-compat/port-uw.h openbsd-compat/xcrypt.c] Rework libiaf test/defines
   to account for IRIX having libiaf but not set_id(). Patch with & ok dtucker@

17 years ago - (dtucker) [Makefile.in configure.ac] Replace single-purpose LIBSELINUX,
dtucker [Sun, 25 Mar 2007 08:26:01 +0000 (08:26 +0000)] 
 - (dtucker) [Makefile.in configure.ac] Replace single-purpose LIBSELINUX,
   LIBWRAP and LIBPAM variables in Makefile with the general-purpose
   SSHDLIBS.  "I like" djm@

17 years ago - (dtucker) [regress/agent-getpeereid.sh] Do peereid test if we have
dtucker [Wed, 21 Mar 2007 10:45:48 +0000 (10:45 +0000)] 
 - (dtucker) [regress/agent-getpeereid.sh] Do peereid test if we have
   HAVE_GETPEERUCRED too.  Also from Jan Pechanec.

17 years ago - (dtucker) [configure.ac openbsd-compat/bsd-getpeereid.c] Bug #1287: Use
dtucker [Wed, 21 Mar 2007 10:39:57 +0000 (10:39 +0000)] 
 - (dtucker) [configure.ac openbsd-compat/bsd-getpeereid.c] Bug #1287: Use
   getpeerucred to implement getpeereid (currently only Solaris 10 and up).
   Patch by Jan.Pechanec at Sun.

This page took 0.122238 seconds and 4 git commands to generate.