Commit Graph
13131 Commits
Author SHA1 Message Date
Damien Miller b7ee13fbbb wrap SIGINFO in ifdef 2025-08-18 14:22:18 +10:00
[email protected] 289239046b upstream: Make ssh(1) and sshd(8) set IP QoS (aka IP_TOS, IPV6_TCLASS)
continually at runtime based on what sessions/channels are open.

Previously, ssh(1) and sshd(8) would pick a QoS value when they
were started and use it for the whole connection. This could
produce suboptimal choices for the QoS value, e.g. for multiplexed
sessions that started interactive but picked up a sftp client,
or sessions that moved large amounts of data via port forwarding.

Now the QoS value will change to the non-interactive IPQoS whenever
a "non-interactive" channel is open; basically any channel that lacks
a tty other than agent forwarding.

This is important now that the default interactive IPQoS is EF
(Expedited Forwarding), as many networks are configured to allow
only relatively small amounts of traffic of this class and they will
aggressively deprioritise the entire connection if this is exceeded.

NB. because ssh(1) and sshd(8) now change IP_TOS/IPV6_TCLASS
continually via setsockopt(), this commit requires a recent pledge(2)
change that landed recently in the OpenBSD kernel. Please ensure
you have updated to a kernel from within the last two weeks before
updating OpenSSH.

with job@ deraadt@

OpenBSD-Commit-ID: 325fc41717eecdf5e4b534bfa8d66817425b840f
2025-08-18 13:57:44 +10:00
[email protected] dc5147028f upstream: SIGINFO handler for sshd(8) to dump active
channels/sessions ok deraadt@

OpenBSD-Commit-ID: 9955cb6d157c6d7aa23a819e8ef61b1edabc8b7d
2025-08-18 13:50:31 +10:00
[email protected] f807a598c9 upstream: SIGINFO handler for ssh(1) to dump active
channels/sessions ok deraadt@

OpenBSD-Commit-ID: 12f88a5044bca40ef5f41ff61b1755d0e25df901
2025-08-18 13:50:30 +10:00
[email protected] 9b61679d73 upstream: add channel_report_open() to report (to logs) open
channels; ok deraadt@ (as part of bigger diff)

OpenBSD-Commit-ID: 7f691e25366c5621d7ed6f7f9018d868f7511c0d
2025-08-18 13:50:30 +10:00
[email protected] 80b5ffd22a upstream: make -E a no-op in sshd-auth. Redirecting logging to a
file doesn't work in this program as logging already goes via the parent
sshd-session process. ok dtucker@

OpenBSD-Commit-ID: 73325b9e69364117c18305f896c620a3abcf4f87
2025-08-18 13:50:29 +10:00
Damien Miller 3a039108bd allow some socket syscalls in seccomp sandbox
Allow getsockname(2), getpeername(2) and getsockopt(2).

Also allow setsockopt(2) but only IP_TOS and IPV6_TCLASS.

Note that systems that use the older socketcall(2) mux syscall will
not have IP_TOS and IPV6_TCLASS allowlisted. On these platforms,
these calls will be soft-blocked (i.e. will fail rather than
terminate the whole process with a sandbox violation).

Needed for upcoming IPQoS change; ok dtucker@
2025-08-18 13:46:37 +10:00
Damien Miller a00f5b02e1 handle futex_time64 properly in seccomp sandbox
Previously we only allowed __NR_futex, but some 32-bit systems
apparently support __NR_futex_time64. We had support for this
in the sandbox, but because of a macro error only __NR_futex was
allowlisted.

ok dtucker@
2025-08-18 13:44:53 +10:00
[email protected] 32deb00b38 upstream: Cast serial no for %lld to prevent compiler warnings on some
platforms.

OpenBSD-Commit-ID: afadd741622f16c6733d461c0d6053ed52868a57
2025-08-14 20:31:02 +10:00
[email protected] 883886c959 upstream: Cast serial no for %lld to prevent compiler warnings on some
platforms.

OpenBSD-Commit-ID: 46c6063284d318f7e4dc922479a3e394c94b0588
2025-08-14 20:01:14 +10:00
[email protected] fde5a4d2cd upstream: Cast serial no for %lld to prevent compiler warnings on some
platforms.

OpenBSD-Commit-ID: 15644234b58abc9c6da2994f0422a5aa344a9e89
2025-08-14 19:39:55 +10:00
[email protected] ab5074dfb6 upstream: fix typo, ok markus dtucker
OpenBSD-Commit-ID: 8f223da7633752162c64a659c6cf55202703d870
2025-08-13 09:20:41 +10:00
[email protected] 8b6c1f402f upstream: Handle localtime_r() failure by return "UNKNOWN-TIME"
which is only used in user-visible contexts.  freebsd 288773 shows their
localtime_r() has failed at least once for unknown reason. discussed with djm

OpenBSD-Commit-ID: 68f4c92d46b2578d4594b0ed940958d597fd61ac
2025-08-13 09:20:40 +10:00
[email protected] 0e1b8aa27f upstream: ssh(1): add a warning when the connection negotiates a
non-post quantum safe key agreement algorithm.

Controlled via a new WarnWeakCrypto ssh_config option, defaulting
to on. This option might grow additional weak crypto warnings in
the future.

More details at https://openssh.com/pq.html

mostly by deraadt@ feedback dtucker@ ok deraadt@

OpenBSD-Commit-ID: 974ff243a1eccceac6a1a9d8fab3bcc89d74a2a4
2025-08-11 21:03:29 +10:00
[email protected] 2ebc638425 upstream: all state related to the ssh connection should live in
struct ssh or struct packet_state; one static int escaped this rule, so move
it to struct packet_state now.

ok millert tb

OpenBSD-Commit-ID: bd6737168bf61a836ffbdc99ee4803468db90a53
2025-08-07 09:45:02 +10:00
[email protected] 60b909fb11 upstream: Improve sentence. ok djm@
OpenBSD-Commit-ID: 9c481ddd6bad110af7e530ba90db41f6d5fe2273
2025-08-07 09:45:02 +10:00
[email protected] 9ffa98111d upstream: when refusing a certificate for user authentication, log
enough information to identify the certificate in addition to the reason why
it was being denied. Makes debugging certificate authz problems a bit easier.

ok dlg@

OpenBSD-Commit-ID: 4c4621b2e70412754b3fe7540af8f4bf02b722b1
2025-08-07 09:45:01 +10:00
[email protected] 2a31009c36 upstream: Use the operating system default DSCP marking for
non-interactive traffic

It seems the CS1 traffic class mark is considered ambiguous and therefore
somewhat unhelpful (see RFC 8622 for more considerations). But, the new
'LE' scavenger class (also proposed in RFC 8622) offers high probability
of excessive delays & high packet loss, which would be inappropriate
for use with, for example, X11 forwardings. In fact, it is not known to
SSH what's appropriate because SSH is not aware of the content of what
passing through session forwardings. Therefore, no marking is appropriate.
Non-interactive traffic simply is best effort.

OK djm@ deraadt@

OpenBSD-Commit-ID: db1da1a432ecd53fc28feb84287aedb6bec80b01
2025-08-07 09:45:01 +10:00
[email protected] 6ebd472c39 upstream: a bunch of the protocol extensions we support now have RFCs
and I-Ds that are more complete and detailed than what we have in the
PROTOCOL.* files. Refer to these when possible instead of documenting them
here.

OpenBSD-Commit-ID: 4fa5b0fcf5d5f24093d33d9e82c7ca4850d50d70
2025-08-05 14:05:39 +10:00
[email protected] ec3465f59c upstream: Deprecate support for IPv4 type-of-service (TOS) IPQoS
keywords

Type of Service (ToS) was deprecated in the late nineties and replaced
with the Differentiated Services architecture. Diffserv has significant
advantages for operators because this mechanism offers more granularity.

OpenSSH switched its default IPQoS from ToS to DSCP values in 2018.

IPQoS configurations with 'lowdelay', 'reliability', or 'throughput' will be
ignored and instead the system default QoS settings apply. Additionally, a
debug message is logged about the deprecation with a suggestion to use DSCP.

with/OK deraadt@ sthen@ djm@

OpenBSD-Commit-ID: 40c8c0c5cb20151a348728703536af2ec1c754ba
2025-08-05 14:04:26 +10:00
[email protected] 65909fa114 upstream: Set default IPQoS for interactive sessions to Expedited
Forwarding (EF)

Marking interactive session data with DSCP value EF (RFC3246, RFC3247)
helps inform the network on relative priority compared to other traffic.
This is especially useful for differentiated treatment over wireless media.

Following the reconciled IETF Diffserv to IEEE 802.11 mappings (RFC 8325),
traffic marked with DSCP value EF maps to User Priority 6 in QoS Control,
in turn mapping to the high priority WMM AC_VO access category.

OK djm@

OpenBSD-Commit-ID: aadda7b9da794d70d7c6b381a861a0610afce1b3
2025-08-05 14:04:25 +10:00
Darren Tucker d1c6c67a50 Disable security key tests for bigendian interop 2025-08-02 14:49:40 +10:00
Darren Tucker e85248df3f Comment out atime restore test.
This works on filesystems mounted 'noatime', but on others the stat()
resets atime causing the test to fail.
2025-08-02 12:51:42 +10:00
Darren Tucker b1c4cedbee Replace fbsd64ppc VM with physical host.
Run 64bit bigendian interop test on NetBSD arm64be instead.
2025-08-01 19:43:27 +10:00
[email protected] 284abbed9a upstream: Plug leak in case where sigp is passed as NULL. Coverity CID
483725, ok djm@

OpenBSD-Commit-ID: 47cf7b399c84e102b670b9f97ab6926c9a7256b5
2025-07-31 17:55:23 +10:00
[email protected] dc630e6d81 upstream: unbreak WITH_OPENSSL=no builds, also allowing ed25519
keys to be used via PKCS#11 when OpenSSH is built without libcrypto.

OpenBSD-Commit-ID: ecf26fdf7591bf2c98bac5136fbc36e0b59c3fc2
2025-07-30 14:41:43 +10:00
[email protected] a5bec2cdfc upstream: fix variable name in disabled code
OpenBSD-Commit-ID: 5612e979575d5da933c8b720d296423fd84392f5
2025-07-30 14:30:09 +10:00
Damien Miller 5e4bfe6c16 more ec/ed25519 fixing 2025-07-26 19:19:46 +10:00
Damien Miller 2603098959 repair build for libcrypto without ed25519 support 2025-07-26 14:27:53 +10:00
[email protected] a729163c56 upstream: regression tests for Ed25519 keys in PKCS#11 tokens
OpenBSD-Regress-ID: 50067c0716abfea3a526b4a0c8f1fe15e7665c0f
2025-07-26 11:58:07 +10:00
[email protected] 361ff0ca30 upstream: Support ed25519 keys hosted on PKCS#11 tokens.
Tested on Yubikeys and against SoftHSM2.

feedback/ok tb@

OpenBSD-Commit-ID: 90ddb6529f2e12e98e8bba21d8592e60579ce2e4
2025-07-26 11:57:57 +10:00
[email protected] 2b530cc300 upstream: update our PKCS#11 API header to v3.0;
feedback/ok tb@

OpenBSD-Commit-ID: e67fa6a26e515c2b1fb7b0d1519d138aafb3e017
2025-07-26 11:54:10 +10:00
Damien Miller 550d2a4a66 another attempt at fixing !EC builds 2025-07-25 23:04:33 +10:00
[email protected] ed1e370d84 upstream: Don't snprintf a NULL since not all platforms support it.
OpenBSD-Commit-ID: 6e0c268e40047e96fab6bc56dc340580b537183b
2025-07-25 22:09:27 +10:00
Damien Miller eedab8db12 unbreak !EC builds 2025-07-25 16:21:43 +10:00
[email protected] 203f5ac6cf upstream: test code now needs to link ssh-pkcs11-client.c any time
sshkey.c is included

OpenBSD-Regress-ID: 9d07188eae9a96801c3150b3433bb220626d4443
2025-07-25 13:36:22 +10:00
Damien Miller 33b4f05c8d update clang-16 -> clang-19 2025-07-25 12:48:29 +10:00
Damien Miller 03e9e993ef include ssh-pkcs11-client.o as common dep 2025-07-25 12:48:29 +10:00
Damien Miller 2f5269938a remove vestigial stub 2025-07-25 12:48:28 +10:00
[email protected] bf33a73c40 upstream: this should include stdlib.h explicitly
OpenBSD-Commit-ID: 1c0cc5c3838344b33ae4ab7aa62c01530357bf29
2025-07-25 09:38:38 +10:00
[email protected] 9f8ccc3b81 upstream: less stale reference to PKCS#1 1.5 hash OIDs; feedback
from tb@

OpenBSD-Commit-ID: 9fda77978491a130a7b77d87d40c79277b796721
2025-07-25 09:30:38 +10:00
[email protected] 1641ab8744 upstream: factor out encoding of a raw ed25519 signature into its
ssh form into a separate function

OpenBSD-Commit-ID: 3711c6d6b52dde0bd1f17884da5cddb8716f1b64
2025-07-25 09:23:17 +10:00
[email protected] a8c0e5c871 upstream: Help OpenSSH's PKCS#11 support kick its meth habit.
The PKCS#11 code in OpenSSH used the libcrypto public key method API
(e.g. the delightfully named RSA_meth_free()) to delegate signing
operations to external keys. This had one advantage - that it was
basically transparent to callers, but also had a big disadvantage -
that we'd manually have to track the method implementations, their
state and their relationships to the underlying PKCS#11 objects.

This rips this out and replaces it with explicit delegation to
PKCS#11 code for externally hosted keys via the ssh-pkcs11-helper
subprocess. This is very similar to how we handle FIDO keys in
OpenSSH (i.e. via ssh-sk-helper). All we need to track now is a
much simpler mapping of public key -> helper subprocess.

Kicking our libcrypto meth dependency also makes it much easier
to support Ed25519 keys in PKCS#11, which will happen in a subsequent
commit.

feedback / ok tb@

OpenBSD-Commit-ID: a5a1eaf57971cf15e0cdc5a513e313541c8a35f0
2025-07-25 09:23:16 +10:00
Darren Tucker 259c66aebe Remove DEBUG_ACTIONS variable.
If needed it can be set in github if needed.
2025-07-24 22:02:49 +10:00
[email protected] 40fb2dc4ec upstream: add a ssh_config RefuseConnection option that, when
encountered while processing an active section in a configuration file,
terminates ssh(1) with an error message that contains the argument to the
option.

This may be useful for expressing reminders or warnings in config
files, for example:

Match host foo
       RefuseConnection "foo is deprecated, use splork instead"

ok djg

OpenBSD-Commit-ID: 5b0072fcd08ad3932ab21e27bbaa66b008d44237
2025-07-23 15:26:50 +10:00
[email protected] defc806574 upstream: Add missing inter-library dependencies to LDADD and
DPADD. ok tb@ deraadt@

OpenBSD-Commit-ID: a05e13a7e2c0b65bb4b47184fef731243431c6ff
2025-07-23 15:26:49 +10:00
Jan Tojnar e6805e2a6b Add gnome-ssh-askpass4 for GNOME 40+
GTK 3 has been in maintenance mode for a while now, and it is on the road
to being abandoned. As a result, the dialogue looks out of place on modern
systems.

We could port it to GTK 4 but without the program being registered as an
application (i.e. having a .desktop file), GNOME Shell would ask for
permission to grab input every time.

Let’s instead use the GNOME Shell’s native prompt through the unstable
Gcr API.
2025-07-14 15:29:15 -07:00
Damien Miller f9dc519259 let ga_init() fail gracefully if getgrouplist does
Apparently getgrouplist() can fail on OSX for when passed a non-existent
group name. Other platforms seem to return a group list consisting of
the numeric gid passed to the function.

This makes ga_init() handle this failure case gracefully, where it will
return success but with an empty group list array.

bz3848; ok dtucker@
2025-07-11 17:20:27 -07:00
[email protected] f01a899b92 upstream: add a "Match Group NoSuchGroup" to exercise groupaccess.c
OpenBSD-Regress-ID: 7ff58e6f0eb21eb9064dd0cfa78c3b6f34b5f713
2025-07-12 09:28:37 +10:00
Damien Miller 1052fa62b3 more diagnostics when getgrouplist fails 2025-07-11 15:36:49 -07:00