Compare commits

...
13 Commits
Author SHA1 Message Date
Darren Tucker 975233e1ea Enable EPHEMERAL_VM to set a new password.
This fixes the Github VMs that have a locked password string for the
runner user.
2025-07-29 19:52:54 +10:00
Darren Tucker 06d6c932a1 Backport Github runner config changes from master.
This updates the V_10_0 branch to (largely) match recent changes to the
Github runner environment.
2025-07-29 19:44:39 +10:00
Darren Tucker b43f1dbd33 Replace Windows 2019 runners with 2025 ones.
The windows-2019 runners are being decomissioned.
2025-07-24 22:06:36 +10:00
[email protected] 78af391990 upstream: Fix mistracking of MaxStartups process exits in some
situations. At worst, this can cause all MaxStartups slots to fill and sshd
to refuse new connections.

Diagnosis by xnor; ok dtucker@

OpenBSD-Commit-ID: 10273033055552557196730f898ed6308b36a78d
2025-07-04 19:52:19 +10:00
Damien Miller 1c017628ac add sshd-auth to RPM spec files 2025-06-17 09:50:36 +10:00
Darren Tucker ddf0e14b73 Remove 9.7 branch from CI status page.
It's been obsolete long enough that github no longer reports its
status.
2025-05-22 10:52:31 +10:00
Darren Tucker 659a1ae0c8 Remove tcmalloc test from 10.0 branch.
It requires some changes in the test infrastructure that are in
the main branch, but are not in this branch and not worth backporting.
2025-05-21 18:47:47 +10:00
Darren Tucker 07d4a5bfcb Boringssl now puts libcrypto in a different place. 2025-05-21 16:56:36 +10:00
Darren Tucker cbe3b8ab01 Set runner pasword to random string.
The most recent version of the Github ubuntu-latest image sets the
password field to "!" which sshd considers to be a locked account,
breaking most of the tests.
2025-05-21 16:07:00 +10:00
Darren Tucker 977ef9f37c Add RUN_ONLY_TEST to limit which tests are run.
For testing, you can set the repo variable RUN_ONLY_TEST in your repo
(Repo -> Settings -> Security -> Actions -> Variables) to run only that test.
2025-05-21 15:05:12 +10:00
Darren Tucker cda6db7eba Move debug log output into separate workflow step.
Should reduce the need to scroll back to find out which test actually
failed.
2025-05-21 15:04:01 +10:00
Darren Tucker c99e3fe71a Backport test environment changes for Cygwin. 2025-05-21 15:03:09 +10:00
[email protected] 4b1f172fe9 upstream: fix a out-of-bounds read if the known_hosts file is
truncated after the hostname.

Reported by the OpenAI Security Research Team

ok deraadt@

OpenBSD-Commit-ID: c0b516d7c80c4779a403826f73bcd8adbbc54ebd
2025-04-30 15:28:07 +10:00
11 changed files with 116 additions and 47 deletions

No files matched your search

-4
View File
@@ -13,7 +13,3 @@ master :
9.8 :
[![C/C++ CI](https://github.com/openssh/openssh-portable/actions/workflows/c-cpp.yml/badge.svg?branch=V_9_8)](https://github.com/openssh/openssh-portable/actions/workflows/c-cpp.yml?query=branch:V_9_8)
[![C/C++ CI self-hosted](https://github.com/openssh/openssh-portable-selfhosted/actions/workflows/selfhosted.yml/badge.svg?branch=V_9_8)](https://github.com/openssh/openssh-portable-selfhosted/actions/workflows/selfhosted.yml?query=branch:V_9_8)
9.7 :
[![C/C++ CI](https://github.com/openssh/openssh-portable/actions/workflows/c-cpp.yml/badge.svg?branch=V_9_7)](https://github.com/openssh/openssh-portable/actions/workflows/c-cpp.yml?query=branch:V_9_7)
[![C/C++ CI self-hosted](https://github.com/openssh/openssh-portable-selfhosted/actions/workflows/selfhosted.yml/badge.svg?branch=V_9_7)](https://github.com/openssh/openssh-portable-selfhosted/actions/workflows/selfhosted.yml?query=branch:V_9_7)
+11
View File
@@ -13,6 +13,10 @@ if [ "$config" = "" ]; then
config="default"
fi
if [ ! -z "${LTESTS}" ]; then
OVERRIDE_LTESTS="${LTESTS}"
fi
unset CC CFLAGS CPPFLAGS LDFLAGS LTESTS SUDO
TEST_TARGET="tests compat-tests"
@@ -144,6 +148,8 @@ case "$config" in
TCMALLOC_STACKTRACE_METHOD=generic_fp
TEST_SSH_SSHD_ENV="TCMALLOC_STACKTRACE_METHOD=generic_fp"
export TCMALLOC_STACKTRACE_METHOD TEST_SSH_SSHD_ENV
SKIP_LTESTS="agent-restrict"
;;
krb5|heimdal)
CONFIGFLAGS="--with-kerberos5"
@@ -392,5 +398,10 @@ if [ -x "$(which plink 2>/dev/null)" ]; then
export REGRESS_INTEROP_PUTTY
fi
if [ ! -z "${OVERRIDE_LTESTS}" ]; then
echo >&2 "Overriding LTESTS, was '${LTESTS}', now '${OVERRIDE_LTESTS}'"
LTESTS="${OVERRIDE_LTESTS}"
fi
export CC CFLAGS CPPFLAGS LDFLAGS LTESTS SUDO
export TEST_TARGET TEST_SSH_UNSAFE_PERMISSIONS TEST_SSH_FAIL_FATAL
-12
View File
@@ -21,18 +21,6 @@ if [ ! -z "$SUDO" ] && [ ! -z "$TEST_SSH_HOSTBASED_AUTH" ]; then
done
fi
output_failed_logs() {
for i in regress/failed*.log; do
if [ -f "$i" ]; then
echo -------------------------------------------------------------------------
echo LOGFILE $i
cat $i
echo -------------------------------------------------------------------------
fi
done
}
trap output_failed_logs 0
env=""
if [ ! -z "${SUDO}" ]; then
env="${env} SUDO=${SUDO}"
+41 -5
View File
@@ -1,8 +1,17 @@
#!/bin/sh
config="$1"
target="$2"
PACKAGES=""
. .github/configs $@
echo Running as:
id
echo Environment:
set
. .github/configs ${config}
host=`./config.guess`
echo "config.guess: $host"
@@ -10,9 +19,17 @@ case "$host" in
*cygwin)
PACKAGER=setup
echo Setting CYGWIN system environment variable.
setx CYGWIN "binmode"
setx CYGWIN "winsymlinks:native"
echo Removing extended ACLs so umask works as expected.
set -x
setfacl -b . regress
icacls regress /c /t /q /Inheritance:d
icacls regress /c /t /q /Grant ${USERNAME}:F
icacls regress /c /t /q /Remove:g "Authenticated Users" \
BUILTIN\\Administrators BUILTIN Everyone System Users
takeown /F regress
icacls regress
set +x
PACKAGES="$PACKAGES,autoconf,automake,cygwin-devel,gcc-core"
PACKAGES="$PACKAGES,make,openssl,libssl-devel,zlib-devel"
;;
@@ -24,7 +41,7 @@ case "$host" in
PACKAGER=apt
esac
TARGETS=$@
TARGETS=${config}
INSTALL_FIDO_PPA="no"
export DEBIAN_FRONTEND=noninteractive
@@ -184,7 +201,8 @@ while [ ! -z "$PACKAGES" ] && [ "$tries" -gt "0" ]; do
fi
;;
setup)
if /cygdrive/c/setup.exe -q -P `echo "$PACKAGES" | tr ' ' ,`; then
setup="/cygdrive/$(echo "${CYGWIN_SETUP}" | tr -d : | tr '\' '/')"
if "${setup}" -q -P `echo "$PACKAGES" | tr ' ' ,`; then
PACKAGES=""
fi
;;
@@ -240,7 +258,7 @@ if [ ! -z "${INSTALL_BORINGSSL}" ]; then
cd ${HOME}/boringssl && mkdir build && cd build &&
cmake -GNinja -DCMAKE_POSITION_INDEPENDENT_CODE=ON .. && ninja &&
mkdir -p /opt/boringssl/lib &&
cp ${HOME}/boringssl/build/crypto/libcrypto.a /opt/boringssl/lib &&
cp ${HOME}/boringssl/build/libcrypto.a /opt/boringssl/lib &&
cp -r ${HOME}/boringssl/include /opt/boringssl)
fi
@@ -280,3 +298,21 @@ if [ ! -z "${INSTALL_PUTTY}" ]; then
)
/usr/local/bin/plink -V
fi
# If we're running on an ephemeral VM, set a random password and set
# up to run the password auth test.
if [ ! -z "${EPHEMERAL_VM}" ]; then
# This is the github "target" as specified in the yml file.
# In particular, ubuntu-latest sets the password field to the locked
# value, so unless we reset it here most of the tests will fail.
case "${target}" in
ubuntu-*)
echo ${target} target: setting random password.
openssl rand -base64 9 >regress/password
pw=$(tr -d '\n' <regress/password | openssl passwd -6 -stdin)
sudo usermod --password "${pw}" runner
sudo usermod --unlock runner
;;
esac
fi
+31 -9
View File
@@ -1,5 +1,15 @@
name: C/C++ CI
# For testing, you can set variables in your repo (Repo -> Settings ->
# Security -> Actions -> Variables) to restrict the tests that are run.
# The supported variables are:
#
# RUN_ONLY_TARGET_CONFIG: Run only the single matching target and config,
# separated by spaces, eg "ubuntu-latest default". All other tests will
# fail immediately.
#
# LTESTS: Override the set of tests run.
on:
push:
paths: [ '**.c', '**.h', '**.m4', '**.sh', '**/Makefile.in', 'configure.ac', '.github/configs', '.github/workflows/c-cpp.yml' ]
@@ -22,14 +32,14 @@ jobs:
- macos-13
- macos-14
- macos-15
- windows-2019
- windows-2022
- windows-2025
config: [default]
# Then we include any extra configs we want to test for specific VMs.
# Valgrind slows things down quite a bit, so start them first.
include:
- { target: windows-2019, config: cygwin-release }
- { target: windows-2022, config: cygwin-release }
- { target: windows-2025, config: cygwin-release }
- { target: ubuntu-22.04, config: c89 }
- { target: ubuntu-22.04, config: clang-11 }
- { target: ubuntu-22.04, config: clang-12-Werror }
@@ -102,7 +112,6 @@ jobs:
- { target: ubuntu-latest, config: putty-0.83 }
- { target: ubuntu-latest, config: putty-snapshot }
- { target: ubuntu-latest, config: zlib-develop }
- { target: ubuntu-latest, config: tcmalloc }
- { target: ubuntu-latest, config: musl }
- { target: ubuntu-22.04-arm, config: kitchensink }
- { target: ubuntu-24.04-arm, config: kitchensink }
@@ -110,16 +119,26 @@ jobs:
- { target: macos-14, config: pam }
- { target: macos-15, config: pam }
runs-on: ${{ matrix.target }}
env:
EPHEMERAL_VM: yes
steps:
- name: check RUN_ONLY_TARGET_CONFIG
if: vars.RUN_ONLY_TARGET_CONFIG != ''
run: sh -c 'if [ "${{ vars.RUN_ONLY_TARGET_CONFIG }}" != "${{ matrix.target }} ${{matrix.config }}" ]; then exit 1; else exit 0; fi'
- name: set cygwin git params
if: ${{ startsWith(matrix.target, 'windows') }}
run: git config --global core.autocrlf input
- name: install cygwin
id: cygwin_install
if: ${{ startsWith(matrix.target, 'windows') }}
uses: cygwin/cygwin-install-action@master
env:
CYGWIN: "winsymlinks:native"
- uses: actions/checkout@main
- name: setup CI system
run: sh ./.github/setup_ci.sh ${{ matrix.config }}
run: sh ./.github/setup_ci.sh ${{ matrix.config }} ${{ matrix.target }}
env:
CYGWIN_SETUP: ${{ steps.cygwin_install.outputs.setup }}
- name: autoreconf
run: sh -c autoreconf
- name: configure
@@ -138,6 +157,13 @@ jobs:
env:
TEST_SSH_UNSAFE_PERMISSIONS: 1
TEST_SSH_HOSTBASED_AUTH: yes
LTESTS: ${{ vars.LTESTS }}
- name: show logs
if: failure()
run: for i in regress/failed*.log; do echo ====; echo logfile $i; echo =====; cat $i; done
- name: chown logs
if: failure()
run: test -x "$(which sudo 2>&1)" && sudo chown -R "${LOGNAME}" regress
- name: save logs
if: failure()
uses: actions/upload-artifact@main
@@ -146,8 +172,4 @@ jobs:
path: |
config.h
config.log
regress/*.log
regress/valgrind-out/
regress/asan.log.*
regress/msan.log.*
regress/log/*
regress/
+5 -2
View File
@@ -11,7 +11,6 @@ jobs:
runs-on: ${{ matrix.host }}
timeout-minutes: 600
env:
DEBUG_ACTIONS: false
HOST: ${{ matrix.host }}
TARGET_HOST: ${{ matrix.target }}
TARGET_CONFIG: ${{ matrix.config }}
@@ -49,8 +48,9 @@ jobs:
- obsd51
- obsd67
- obsd72
- obsd73
- obsd74
- obsd76
- obsd77
- obsdsnap
- obsdsnap-i386
- omnios
@@ -129,6 +129,9 @@ jobs:
- name: make tests
run: vmrun ./.github/run_test.sh ${{ matrix.config }}
timeout-minutes: 600
- name: show logs
if: failure()
run: vmrun 'for i in regress/failed*.log; do echo ====; echo logfile $i; echo =====; cat $i; done'
- name: save logs
if: failure()
uses: actions/upload-artifact@main
+3 -2
View File
@@ -11,7 +11,6 @@ jobs:
if: github.repository == 'openssh/openssh-portable-selfhosted'
runs-on: ${{ matrix.host }}
env:
DEBUG_ACTIONS: true
EPHEMERAL: true
HOST: ${{ matrix.host }}
TARGET_HOST: ${{ matrix.target }}
@@ -43,7 +42,9 @@ jobs:
run: sshfs_mount
working-directory: ${{ runner.temp }}
- name: update source
run: vmrun "cd /usr/src && cvs up -dPA usr.bin/ssh regress/usr.bin/ssh"
run: vmrun "cd /usr/src && cvs -q up -dPA usr.bin/ssh regress/usr.bin/ssh usr.bin/nc"
- name: update netcat
run: vmrun "cd /usr/src/usr.bin/nc && make clean all && sudo make install"
- name: make clean
run: vmrun "cd /usr/src/usr.bin/ssh && make obj && make clean && cd /usr/src/regress/usr.bin/ssh && make obj && make clean && sudo chmod -R g-w /usr/src /usr/obj"
- name: make
+1
View File
@@ -367,6 +367,7 @@ fi
%defattr(-,root,root)
%dir %attr(0111,root,root) %{_var}/empty/sshd
%attr(0755,root,root) %{_sbindir}/sshd
%attr(0755,root,root) %{_libexecdir}/openssh/sshd-auth
%attr(0755,root,root) %{_libexecdir}/openssh/sshd-session
%attr(0755,root,root) %{_libexecdir}/openssh/sftp-server
%attr(0644,root,root) %{_mandir}/man8/sshd.8*
+1
View File
@@ -211,6 +211,7 @@ rm -rf $RPM_BUILD_ROOT
%attr(0755,root,root) %{_sbindir}/sshd
%attr(0755,root,root) %dir %{_libdir}/ssh
%attr(0755,root,root) %{_libdir}/ssh/sftp-server
%attr(0755,root,root) %{_libdir}/ssh/sshd-auth
%attr(0755,root,root) %{_libdir}/ssh/sshd-session
%attr(4711,root,root) %{_libdir}/ssh/ssh-keysign
%attr(0755,root,root) %{_libdir}/ssh/ssh-pkcs11-helper
+7 -1
View File
@@ -1,4 +1,4 @@
/* $OpenBSD: hostfile.c,v 1.95 2023/02/21 06:48:18 dtucker Exp $ */
/* $OpenBSD: hostfile.c,v 1.96 2025/04/30 05:23:15 djm Exp $ */
/*
* Author: Tatu Ylonen <ylo@cs.hut.fi>
* Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
@@ -810,6 +810,12 @@ hostkeys_foreach_file(const char *path, FILE *f, hostkeys_foreach_fn *callback,
/* Find the end of the host name portion. */
for (cp2 = cp; *cp2 && *cp2 != ' ' && *cp2 != '\t'; cp2++)
;
if (*cp2 == '\0') {
verbose_f("truncated line at %s:%lu", path, linenum);
if ((options & HKF_WANT_MATCH) == 0)
goto bad;
continue;
}
lineinfo.hosts = cp;
*cp2++ = '\0';
+16 -12
View File
@@ -289,8 +289,10 @@ child_finish(struct early_child *child)
{
if (children_active == 0)
fatal_f("internal error: children_active underflow");
if (child->pipefd != -1)
if (child->pipefd != -1) {
srclimit_done(child->pipefd);
close(child->pipefd);
}
sshbuf_free(child->config);
sshbuf_free(child->keys);
free(child->id);
@@ -311,6 +313,7 @@ child_close(struct early_child *child, int force_final, int quiet)
if (!quiet)
debug_f("enter%s", force_final ? " (forcing)" : "");
if (child->pipefd != -1) {
srclimit_done(child->pipefd);
close(child->pipefd);
child->pipefd = -1;
}
@@ -1039,7 +1042,6 @@ server_accept_loop(int *sock_in, int *sock_out, int *newsock, int *config_s,
if (ret <= 0) {
if (children[i].early)
listening--;
srclimit_done(children[i].pipefd);
child_close(&(children[i]), 0, 0);
continue;
}
@@ -1078,23 +1080,19 @@ server_accept_loop(int *sock_in, int *sock_out, int *newsock, int *config_s,
}
/* FALLTHROUGH */
case 0:
/* child exited preauth */
/* child closed pipe */
if (children[i].early)
listening--;
srclimit_done(children[i].pipefd);
debug3_f("child %lu for %s closed pipe",
(long)children[i].pid, children[i].id);
child_close(&(children[i]), 0, 0);
break;
case 1:
if (children[i].config) {
error_f("startup pipe %d (fd=%d)"
" early read", i, children[i].pipefd);
if (children[i].early)
listening--;
if (children[i].pid > 0)
kill(children[i].pid, SIGTERM);
srclimit_done(children[i].pipefd);
child_close(&(children[i]), 0, 0);
break;
" early read",
i, children[i].pipefd);
goto problem_child;
}
if (children[i].early && c == '\0') {
/* child has finished preliminaries */
@@ -1114,6 +1112,12 @@ server_accept_loop(int *sock_in, int *sock_out, int *newsock, int *config_s,
"child %ld for %s in state %d",
(int)c, (long)children[i].pid,
children[i].id, children[i].early);
problem_child:
if (children[i].early)
listening--;
if (children[i].pid > 0)
kill(children[i].pid, SIGTERM);
child_close(&(children[i]), 0, 0);
}
break;
}