Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
fe5e26324d | ||
|
|
8ee5801025 | ||
|
|
4cf5740251 | ||
|
|
4ce9fd0e93 |
@@ -1,120 +1,26 @@
|
||||
20050120
|
||||
- (dtucker) OpenBSD CVS Sync
|
||||
- [email protected] 2005/01/19 13:11:47
|
||||
[auth-bsdauth.c auth2-chall.c]
|
||||
Have keyboard-interactive code call the drivers even for responses for
|
||||
invalid logins. This allows the drivers themselves to decide how to
|
||||
handle them and prevent leaking information where possible. Existing
|
||||
behaviour for bsdauth is maintained by checking authctxt->valid in the
|
||||
bsdauth driver. Note that any third-party kbdint drivers will now need
|
||||
to be able to handle responses for invalid logins. ok markus@
|
||||
- (dtucker) [auth-pam.c] Bug #971: Prevent leaking information about user
|
||||
existence via keyboard-interactive/pam, in conjunction with previous
|
||||
auth2-chall.c change; with Colin Watson and djm.
|
||||
|
||||
20041102
|
||||
- (dtucker) [configure.ac includes.h] Bug #947: Fix compile error on HP-UX
|
||||
10.x by testing for conflicts in shadow.h and undef'ing _INCLUDE__STDC__
|
||||
only if a conflict is detected.
|
||||
|
||||
20041019
|
||||
- (dtucker) [uidswap.c] Don't test dropping of gids for the root user or
|
||||
on Cygwin. Cygwin parts from vinschen at redhat com; ok djm@
|
||||
|
||||
20041016
|
||||
- (djm) [auth-pam.c] snprintf->strl*, fix server message length calculations;
|
||||
ok dtucker@
|
||||
|
||||
20041006
|
||||
- (dtucker) [README.privsep] Bug #939: update info about HP-UX Trusted Mode
|
||||
and other PAM platforms.
|
||||
- (dtucker) [monitor_mm.c openbsd-compat/xmmap.c] Bug #940: cast constants
|
||||
to void * to appease picky compilers (eg Tru64's "cc -std1").
|
||||
|
||||
20040930
|
||||
- (dtucker) [configure.ac] Set AC_PACKAGE_NAME. ok djm@
|
||||
|
||||
20040923
|
||||
- (dtucker) [openbsd-compat/bsd-snprintf.c] Previous change was off by one,
|
||||
which could have caused the justification to be wrong. ok djm@
|
||||
|
||||
20040921
|
||||
- (dtucker) [openbsd-compat/bsd-snprintf.c] Check for max length too.
|
||||
ok djm@
|
||||
- (dtucker) [contrib/cygwin/ssh-host-config] Update to match current Cygwin
|
||||
install process. Patch from vinschen at redhat.com.
|
||||
|
||||
20040912
|
||||
- (djm) [loginrec.c] Start KNF and tidy up of this long-neglected file.
|
||||
No change in resultant binary
|
||||
- (djm) [loginrec.c] __func__ifiy
|
||||
- (djm) [loginrec.c] xmalloc
|
||||
- (djm) [ssh.c sshd.c version.h] Don't divulge portable version in protocol
|
||||
banner. Suggested by deraadt@, ok mouring@, dtucker@
|
||||
- (dtucker) [configure.ac] Fix incorrect quoting and tests for cross-compile.
|
||||
Partly by & ok djm@.
|
||||
|
||||
20040911
|
||||
- (djm) [ssh-agent.c] unifdef some cygwin code; ok dtucker@
|
||||
- (dtucker) [auth-pam.c auth-pam.h session.c] Bug #890: Send output from
|
||||
failing PAM session modules to user then exit, similar to the way
|
||||
/etc/nologin is handled. ok djm@
|
||||
- (dtucker) [auth-pam.c] Relocate sshpam_store_conv(), no code change.
|
||||
- (djm) [auth2-kbdint.c auth2-none.c auth2-passwd.c auth2-pubkey.c]
|
||||
Make cygwin code more consistent with that which surrounds it
|
||||
- (dtucker) [auth-pam.c auth.h auth2-none.c auth2.c monitor.c monitor_wrap.c]
|
||||
Bug #892: Send messages from failing PAM account modules to the client via
|
||||
SSH2_MSG_USERAUTH_BANNER messages. Note that this will not happen with
|
||||
SSH2 kbdint authentication, which need to be dealt with separately. ok djm@
|
||||
- (dtucker) [session.c] Bug #927: make .hushlogin silent again. ok djm@
|
||||
- (dtucker) [configure.ac] Bug #321: Add cross-compile support to configure.
|
||||
Parts by chua at ayrnetworks.com, astrand at lysator.liu.se and me. ok djm@
|
||||
- (dtucker) [auth-krb5.c] Bug #922: Pass KRB5CCNAME to PAM. From deengert
|
||||
at anl.gov, ok djm@
|
||||
|
||||
20040830
|
||||
- (dtucker) [session.c openbsd-compat/bsd-cygwin_util.{c,h}] Bug #915: only
|
||||
copy required environment variables on Cygwin. Patch from vinschen at
|
||||
redhat.com, ok djm@
|
||||
- (dtucker) [regress/Makefile] Clean scp-ssh-wrapper.scp too. Patch from
|
||||
vinschen at redhat.com.
|
||||
- (dtucker) [Makefile.in contrib/ssh-copy-id] Bug #894: Improve portability
|
||||
of shell constructs. Patch from cjwatson at debian.org.
|
||||
|
||||
20040829
|
||||
- (dtucker) [openbsd-compat/getrrsetbyname.c] Prevent getrrsetbyname from
|
||||
failing with NOMEMORY if no sigs are returned and malloc(0) returns NULL.
|
||||
From Martin.Kraemer at Fujitsu-Siemens.com; ok djm@
|
||||
- (dtucker) OpenBSD CVS Sync
|
||||
- [email protected] 2004/08/23 11:48:09
|
||||
[authfile.c]
|
||||
fix error path, spotted by Martin.Kraemer AT Fujitsu-Siemens.com; ok markus
|
||||
- [email protected] 2004/08/23 11:48:47
|
||||
[channels.c]
|
||||
typo, spotted by Martin.Kraemer AT Fujitsu-Siemens.com; ok markus
|
||||
- [email protected] 2004/08/23 14:26:38
|
||||
[ssh-keysign.c ssh.c]
|
||||
Use permanently_set_uid() in ssh and ssh-keysign for consistency, matches
|
||||
change in Portable; ok markus@ (CVS ID sync only)
|
||||
- [email protected] 2004/08/23 14:29:23
|
||||
[ssh-keysign.c]
|
||||
Remove duplicate getuid(), suggested by & ok markus@
|
||||
- [email protected] 2004/08/26 16:00:55
|
||||
[ssh.1 sshd.8]
|
||||
get rid of references to rhosts authentication; with jmc@
|
||||
- [email protected] 2004/08/28 01:01:48
|
||||
[sshd.c]
|
||||
don't erroneously close stdin for !reexec case, from Dave Johnson;
|
||||
ok markus@
|
||||
- (dtucker) [configure.ac] Include sys/stream.h in sys/ptms.h header check,
|
||||
fixes configure warning on Solaris reported by wknox at mitre.org.
|
||||
- (dtucker) [regress/multiplex.sh] Skip test on platforms that do not
|
||||
support FD passing since multiplex requires it. Noted by tim@
|
||||
- (dtucker) [regress/dynamic-forward.sh] Allow time for connections to be torn
|
||||
down, needed on some platforms, should be harmless on others. Patch from
|
||||
jason at devrandom.org.
|
||||
- (dtucker) [regress/scp.sh] Make this work on Cygwin too, which doesn't like
|
||||
files ending in .exe that aren't binaries; patch from vinschen at redhat.com.
|
||||
- (dtucker) [Makefile.in] Get regress/Makefile symlink right for out-of-tree
|
||||
builds too, from vinschen at redhat.com.
|
||||
- (dtucker) [regress/agent-ptrace.sh] Skip ptrace test on OSF1/DUnix/Tru64
|
||||
too; patch from cmadams at hiwaay.net.
|
||||
- (dtucker) [configure.ac] Replace non-portable echo \n with extra echo.
|
||||
- (dtucker) [openbsd-compat/port-aix.c] Bug #712: Explicitly check for
|
||||
accounts with authentication configs that sshd can't support (ie
|
||||
SYSTEM=NONE and AUTH1=something).
|
||||
|
||||
20040828
|
||||
- (dtucker) [openbsd-compat/mktemp.c] Remove superfluous Cygwin #ifdef; from
|
||||
vinschen at redhat.com.
|
||||
|
||||
20040823
|
||||
- (djm) [ssh-rand-helper.c] Typo. Found by
|
||||
Martin.Kraemer AT Fujitsu-Siemens.com
|
||||
- (djm) [loginrec.c] Typo and bad args in error messages; Spotted by
|
||||
Martin.Kraemer AT Fujitsu-Siemens.com
|
||||
|
||||
20040817
|
||||
- (dtucker) [regress/README.regress] Note compatibility issues with GNU head.
|
||||
- (djm) OpenBSD CVS Sync
|
||||
@@ -1771,4 +1677,4 @@
|
||||
- (djm) Trim deprecated options from INSTALL. Mention UsePAM
|
||||
- (djm) Fix quote handling in sftp; Patch from admorten AT umich.edu
|
||||
|
||||
$Id: ChangeLog,v 1.3561 2004/10/19 06:33:33 dtucker Exp $
|
||||
$Id: ChangeLog,v 1.3517.2.4 2005/01/20 03:29:03 dtucker Exp $
|
||||
|
||||
+4
-1
@@ -22,7 +22,7 @@
|
||||
* THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
*/
|
||||
#include "includes.h"
|
||||
RCSID("$OpenBSD: auth-bsdauth.c,v 1.5 2002/06/30 21:59:45 deraadt Exp $");
|
||||
RCSID("$OpenBSD: auth-bsdauth.c,v 1.6 2005/01/19 13:11:47 dtucker Exp $");
|
||||
|
||||
#ifdef BSD_AUTH
|
||||
#include "xmalloc.h"
|
||||
@@ -83,6 +83,9 @@ bsdauth_respond(void *ctx, u_int numresponses, char **responses)
|
||||
Authctxt *authctxt = ctx;
|
||||
int authok;
|
||||
|
||||
if (!authctxt->valid)
|
||||
return -1;
|
||||
|
||||
if (authctxt->as == 0)
|
||||
error("bsdauth_respond: no bsd auth session");
|
||||
|
||||
|
||||
+70
-77
@@ -47,7 +47,7 @@
|
||||
|
||||
/* Based on $FreeBSD: src/crypto/openssh/auth2-pam-freebsd.c,v 1.11 2003/03/31 13:48:18 des Exp $ */
|
||||
#include "includes.h"
|
||||
RCSID("$Id: auth-pam.c,v 1.118 2004/10/16 08:52:44 djm Exp $");
|
||||
RCSID("$Id: auth-pam.c,v 1.114.2.1 2005/01/20 03:29:04 dtucker Exp $");
|
||||
|
||||
#ifdef USE_PAM
|
||||
#if defined(HAVE_SECURITY_PAM_APPL_H)
|
||||
@@ -186,6 +186,7 @@ static int sshpam_account_status = -1;
|
||||
static char **sshpam_env = NULL;
|
||||
static Authctxt *sshpam_authctxt = NULL;
|
||||
static const char *sshpam_password = NULL;
|
||||
static char badpw[] = "\b\n\r\177INCORRECT";
|
||||
|
||||
/* Some PAM implementations don't implement this */
|
||||
#ifndef HAVE_PAM_GETENVLIST
|
||||
@@ -490,51 +491,6 @@ sshpam_null_conv(int n, struct pam_message **msg,
|
||||
|
||||
static struct pam_conv null_conv = { sshpam_null_conv, NULL };
|
||||
|
||||
static int
|
||||
sshpam_store_conv(int n, struct pam_message **msg,
|
||||
struct pam_response **resp, void *data)
|
||||
{
|
||||
struct pam_response *reply;
|
||||
int i;
|
||||
size_t len;
|
||||
|
||||
debug3("PAM: %s called with %d messages", __func__, n);
|
||||
*resp = NULL;
|
||||
|
||||
if (n <= 0 || n > PAM_MAX_NUM_MSG)
|
||||
return (PAM_CONV_ERR);
|
||||
|
||||
if ((reply = malloc(n * sizeof(*reply))) == NULL)
|
||||
return (PAM_CONV_ERR);
|
||||
memset(reply, 0, n * sizeof(*reply));
|
||||
|
||||
for (i = 0; i < n; ++i) {
|
||||
switch (PAM_MSG_MEMBER(msg, i, msg_style)) {
|
||||
case PAM_ERROR_MSG:
|
||||
case PAM_TEXT_INFO:
|
||||
len = strlen(PAM_MSG_MEMBER(msg, i, msg));
|
||||
buffer_append(&loginmsg, PAM_MSG_MEMBER(msg, i, msg), len);
|
||||
buffer_append(&loginmsg, "\n", 1 );
|
||||
reply[i].resp_retcode = PAM_SUCCESS;
|
||||
break;
|
||||
default:
|
||||
goto fail;
|
||||
}
|
||||
}
|
||||
*resp = reply;
|
||||
return (PAM_SUCCESS);
|
||||
|
||||
fail:
|
||||
for(i = 0; i < n; i++) {
|
||||
if (reply[i].resp != NULL)
|
||||
xfree(reply[i].resp);
|
||||
}
|
||||
xfree(reply);
|
||||
return (PAM_CONV_ERR);
|
||||
}
|
||||
|
||||
static struct pam_conv store_conv = { sshpam_store_conv, NULL };
|
||||
|
||||
void
|
||||
sshpam_cleanup(void)
|
||||
{
|
||||
@@ -572,7 +528,7 @@ sshpam_init(Authctxt *authctxt)
|
||||
}
|
||||
debug("PAM: initializing for \"%s\"", user);
|
||||
sshpam_err =
|
||||
pam_start(SSHD_PAM_SERVICE, user, &store_conv, &sshpam_handle);
|
||||
pam_start(SSHD_PAM_SERVICE, user, &null_conv, &sshpam_handle);
|
||||
sshpam_authctxt = authctxt;
|
||||
|
||||
if (sshpam_err != PAM_SUCCESS) {
|
||||
@@ -654,7 +610,7 @@ sshpam_query(void *ctx, char **name, char **info,
|
||||
size_t plen;
|
||||
u_char type;
|
||||
char *msg;
|
||||
size_t len, mlen;
|
||||
size_t len;
|
||||
|
||||
debug3("PAM: %s entering", __func__);
|
||||
buffer_init(&buffer);
|
||||
@@ -667,27 +623,22 @@ sshpam_query(void *ctx, char **name, char **info,
|
||||
while (ssh_msg_recv(ctxt->pam_psock, &buffer) == 0) {
|
||||
type = buffer_get_char(&buffer);
|
||||
msg = buffer_get_string(&buffer, NULL);
|
||||
mlen = strlen(msg);
|
||||
switch (type) {
|
||||
case PAM_PROMPT_ECHO_ON:
|
||||
case PAM_PROMPT_ECHO_OFF:
|
||||
*num = 1;
|
||||
len = plen + mlen + 1;
|
||||
len = plen + strlen(msg) + 1;
|
||||
**prompts = xrealloc(**prompts, len);
|
||||
strlcpy(**prompts + plen, msg, len - plen);
|
||||
plen += mlen;
|
||||
plen += snprintf(**prompts + plen, len, "%s", msg);
|
||||
**echo_on = (type == PAM_PROMPT_ECHO_ON);
|
||||
xfree(msg);
|
||||
return (0);
|
||||
case PAM_ERROR_MSG:
|
||||
case PAM_TEXT_INFO:
|
||||
/* accumulate messages */
|
||||
len = plen + mlen + 2;
|
||||
len = plen + strlen(msg) + 2;
|
||||
**prompts = xrealloc(**prompts, len);
|
||||
strlcpy(**prompts + plen, msg, len - plen);
|
||||
plen += mlen;
|
||||
strlcat(**prompts + plen, "\n", len - plen);
|
||||
plen++;
|
||||
plen += snprintf(**prompts + plen, len, "%s\n", msg);
|
||||
xfree(msg);
|
||||
break;
|
||||
case PAM_SUCCESS:
|
||||
@@ -701,6 +652,12 @@ sshpam_query(void *ctx, char **name, char **info,
|
||||
**prompts = NULL;
|
||||
}
|
||||
if (type == PAM_SUCCESS) {
|
||||
if (!sshpam_authctxt->valid ||
|
||||
(sshpam_authctxt->pw->pw_uid == 0 &&
|
||||
options.permit_root_login != PERMIT_YES))
|
||||
fatal("Internal error: PAM auth "
|
||||
"succeeded when it should have "
|
||||
"failed");
|
||||
import_environments(&buffer);
|
||||
*num = 0;
|
||||
**echo_on = 0;
|
||||
@@ -746,7 +703,12 @@ sshpam_respond(void *ctx, u_int num, char **resp)
|
||||
return (-1);
|
||||
}
|
||||
buffer_init(&buffer);
|
||||
buffer_put_cstring(&buffer, *resp);
|
||||
if (sshpam_authctxt->valid &&
|
||||
(sshpam_authctxt->pw->pw_uid != 0 ||
|
||||
options.permit_root_login == PERMIT_YES))
|
||||
buffer_put_cstring(&buffer, *resp);
|
||||
else
|
||||
buffer_put_cstring(&buffer, badpw);
|
||||
if (ssh_msg_send(ctxt->pam_psock, PAM_AUTHTOK, &buffer) == -1) {
|
||||
buffer_free(&buffer);
|
||||
return (-1);
|
||||
@@ -809,13 +771,11 @@ finish_pam(void)
|
||||
u_int
|
||||
do_pam_account(void)
|
||||
{
|
||||
debug("%s: called", __func__);
|
||||
if (sshpam_account_status != -1)
|
||||
return (sshpam_account_status);
|
||||
|
||||
sshpam_err = pam_acct_mgmt(sshpam_handle, 0);
|
||||
debug3("PAM: %s pam_acct_mgmt = %d (%s)", __func__, sshpam_err,
|
||||
pam_strerror(sshpam_handle, sshpam_err));
|
||||
debug3("PAM: %s pam_acct_mgmt = %d", __func__, sshpam_err);
|
||||
|
||||
if (sshpam_err != PAM_SUCCESS && sshpam_err != PAM_NEW_AUTHTOK_REQD) {
|
||||
sshpam_account_status = 0;
|
||||
@@ -845,7 +805,7 @@ void
|
||||
do_pam_setcred(int init)
|
||||
{
|
||||
sshpam_err = pam_set_item(sshpam_handle, PAM_CONV,
|
||||
(const void *)&store_conv);
|
||||
(const void *)&null_conv);
|
||||
if (sshpam_err != PAM_SUCCESS)
|
||||
fatal("PAM: failed to set PAM_CONV: %s",
|
||||
pam_strerror(sshpam_handle, sshpam_err));
|
||||
@@ -946,6 +906,51 @@ do_pam_chauthtok(void)
|
||||
pam_strerror(sshpam_handle, sshpam_err));
|
||||
}
|
||||
|
||||
static int
|
||||
sshpam_store_conv(int n, struct pam_message **msg,
|
||||
struct pam_response **resp, void *data)
|
||||
{
|
||||
struct pam_response *reply;
|
||||
int i;
|
||||
size_t len;
|
||||
|
||||
debug3("PAM: %s called with %d messages", __func__, n);
|
||||
*resp = NULL;
|
||||
|
||||
if (n <= 0 || n > PAM_MAX_NUM_MSG)
|
||||
return (PAM_CONV_ERR);
|
||||
|
||||
if ((reply = malloc(n * sizeof(*reply))) == NULL)
|
||||
return (PAM_CONV_ERR);
|
||||
memset(reply, 0, n * sizeof(*reply));
|
||||
|
||||
for (i = 0; i < n; ++i) {
|
||||
switch (PAM_MSG_MEMBER(msg, i, msg_style)) {
|
||||
case PAM_ERROR_MSG:
|
||||
case PAM_TEXT_INFO:
|
||||
len = strlen(PAM_MSG_MEMBER(msg, i, msg));
|
||||
buffer_append(&loginmsg, PAM_MSG_MEMBER(msg, i, msg), len);
|
||||
buffer_append(&loginmsg, "\n", 1 );
|
||||
reply[i].resp_retcode = PAM_SUCCESS;
|
||||
break;
|
||||
default:
|
||||
goto fail;
|
||||
}
|
||||
}
|
||||
*resp = reply;
|
||||
return (PAM_SUCCESS);
|
||||
|
||||
fail:
|
||||
for(i = 0; i < n; i++) {
|
||||
if (reply[i].resp != NULL)
|
||||
xfree(reply[i].resp);
|
||||
}
|
||||
xfree(reply);
|
||||
return (PAM_CONV_ERR);
|
||||
}
|
||||
|
||||
static struct pam_conv store_conv = { sshpam_store_conv, NULL };
|
||||
|
||||
void
|
||||
do_pam_session(void)
|
||||
{
|
||||
@@ -956,21 +961,10 @@ do_pam_session(void)
|
||||
fatal("PAM: failed to set PAM_CONV: %s",
|
||||
pam_strerror(sshpam_handle, sshpam_err));
|
||||
sshpam_err = pam_open_session(sshpam_handle, 0);
|
||||
if (sshpam_err == PAM_SUCCESS)
|
||||
sshpam_session_open = 1;
|
||||
else {
|
||||
sshpam_session_open = 0;
|
||||
disable_forwarding();
|
||||
error("PAM: pam_open_session(): %s",
|
||||
if (sshpam_err != PAM_SUCCESS)
|
||||
fatal("PAM: pam_open_session(): %s",
|
||||
pam_strerror(sshpam_handle, sshpam_err));
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
int
|
||||
is_pam_session_open(void)
|
||||
{
|
||||
return sshpam_session_open;
|
||||
sshpam_session_open = 1;
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -1093,7 +1087,6 @@ sshpam_auth_passwd(Authctxt *authctxt, const char *password)
|
||||
{
|
||||
int flags = (options.permit_empty_passwd == 0 ?
|
||||
PAM_DISALLOW_NULL_AUTHTOK : 0);
|
||||
static char badpw[] = "\b\n\r\177INCORRECT";
|
||||
|
||||
if (!options.use_pam || sshpam_handle == NULL)
|
||||
fatal("PAM: %s called when PAM disabled or failed to "
|
||||
|
||||
+3
-8
@@ -23,7 +23,7 @@
|
||||
* THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
*/
|
||||
#include "includes.h"
|
||||
RCSID("$OpenBSD: auth2-chall.c,v 1.21 2004/06/01 14:20:45 dtucker Exp $");
|
||||
RCSID("$OpenBSD: auth2-chall.c,v 1.22 2005/01/19 13:11:47 dtucker Exp $");
|
||||
|
||||
#include "ssh2.h"
|
||||
#include "auth.h"
|
||||
@@ -274,12 +274,7 @@ input_userauth_info_response(int type, u_int32_t seq, void *ctxt)
|
||||
}
|
||||
packet_check_eom();
|
||||
|
||||
if (authctxt->valid) {
|
||||
res = kbdintctxt->device->respond(kbdintctxt->ctxt,
|
||||
nresp, response);
|
||||
} else {
|
||||
res = -1;
|
||||
}
|
||||
res = kbdintctxt->device->respond(kbdintctxt->ctxt, nresp, response);
|
||||
|
||||
for (i = 0; i < nresp; i++) {
|
||||
memset(response[i], 'r', strlen(response[i]));
|
||||
@@ -291,7 +286,7 @@ input_userauth_info_response(int type, u_int32_t seq, void *ctxt)
|
||||
switch (res) {
|
||||
case 0:
|
||||
/* Success! */
|
||||
authenticated = 1;
|
||||
authenticated = authctxt->valid ? 1 : 0;
|
||||
break;
|
||||
case 1:
|
||||
/* Authentication needs further interaction */
|
||||
|
||||
+71
-103
@@ -1,4 +1,4 @@
|
||||
# $Id: configure.ac,v 1.231 2004/09/30 11:17:08 dtucker Exp $
|
||||
# $Id: configure.ac,v 1.226.2.1 2004/11/02 09:29:54 dtucker Exp $
|
||||
#
|
||||
# Copyright (c) 1999-2004 Damien Miller
|
||||
#
|
||||
@@ -14,7 +14,7 @@
|
||||
# ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
|
||||
# OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
AC_INIT(OpenSSH, Portable)
|
||||
AC_INIT
|
||||
AC_CONFIG_SRCDIR([ssh.c])
|
||||
|
||||
AC_CONFIG_HEADER(config.h)
|
||||
@@ -220,6 +220,7 @@ main() { if (NSVersionOfRunTimeLibrary("System") >= (60 << 16))
|
||||
AC_DEFINE(LOCKED_PASSWD_STRING, "*")
|
||||
AC_DEFINE(SPT_TYPE,SPT_PSTAT)
|
||||
check_for_hpux_broken_getaddrinfo=1
|
||||
check_for_conflicting_getspnam=1
|
||||
LIBS="$LIBS -lsec"
|
||||
AC_CHECK_LIB(xnet, t_error, ,AC_MSG_ERROR([*** -lxnet needed on HP-UX - check config.log ***]))
|
||||
;;
|
||||
@@ -506,17 +507,15 @@ AC_ARG_WITH(libs,
|
||||
)
|
||||
|
||||
AC_MSG_CHECKING(compiler and flags for sanity)
|
||||
AC_RUN_IFELSE(
|
||||
[AC_LANG_SOURCE([
|
||||
AC_TRY_RUN([
|
||||
#include <stdio.h>
|
||||
int main(){exit(0);}
|
||||
])],
|
||||
],
|
||||
[ AC_MSG_RESULT(yes) ],
|
||||
[
|
||||
AC_MSG_RESULT(no)
|
||||
AC_MSG_ERROR([*** compiler cannot create working executables, check config.log ***])
|
||||
],
|
||||
[ AC_MSG_WARN([cross compiling: not checking compiler sanity]) ]
|
||||
]
|
||||
)
|
||||
|
||||
# Checks for header files.
|
||||
@@ -527,17 +526,10 @@ AC_CHECK_HEADERS(bstring.h crypt.h dirent.h endian.h features.h \
|
||||
rpc/types.h security/pam_appl.h shadow.h stddef.h stdint.h \
|
||||
strings.h sys/dir.h sys/strtio.h sys/audit.h sys/bitypes.h \
|
||||
sys/bsdtty.h sys/cdefs.h sys/mman.h sys/ndir.h sys/prctl.h \
|
||||
sys/pstat.h sys/select.h sys/stat.h sys/stream.h \
|
||||
sys/pstat.h sys/ptms.h sys/select.h sys/stat.h sys/stream.h \
|
||||
sys/stropts.h sys/sysmacros.h sys/time.h sys/timers.h sys/un.h \
|
||||
time.h tmpdir.h ttyent.h usersec.h util.h utime.h utmp.h utmpx.h vis.h)
|
||||
|
||||
# sys/ptms.h requires sys/stream.h to be included first on Solaris
|
||||
AC_CHECK_HEADERS(sys/ptms.h, [], [], [
|
||||
#ifdef HAVE_SYS_STREAM_H
|
||||
# include <sys/stream.h>
|
||||
#endif
|
||||
])
|
||||
|
||||
# Checks for libraries.
|
||||
AC_CHECK_FUNC(yp_match, , AC_CHECK_LIB(nsl, yp_match))
|
||||
AC_CHECK_FUNC(setsockopt, , AC_CHECK_LIB(socket, setsockopt))
|
||||
@@ -649,7 +641,7 @@ AC_ARG_WITH(zlib-version-check,
|
||||
)
|
||||
|
||||
AC_MSG_CHECKING(for zlib 1.1.4 or greater)
|
||||
AC_RUN_IFELSE([AC_LANG_SOURCE([[
|
||||
AC_TRY_RUN([
|
||||
#include <zlib.h>
|
||||
int main()
|
||||
{
|
||||
@@ -661,7 +653,7 @@ int main()
|
||||
exit(0);
|
||||
exit(2);
|
||||
}
|
||||
]])],
|
||||
],
|
||||
AC_MSG_RESULT(yes),
|
||||
[ AC_MSG_RESULT(no)
|
||||
if test -z "$zlib_check_nonfatal" ; then
|
||||
@@ -674,8 +666,7 @@ If you are in doubt, upgrade zlib to version 1.1.4 or greater.])
|
||||
else
|
||||
AC_MSG_WARN([zlib version may have security problems])
|
||||
fi
|
||||
],
|
||||
[ AC_MSG_WARN([cross compiling: not checking zlib version]) ]
|
||||
]
|
||||
)
|
||||
|
||||
dnl UnixWare 2.x
|
||||
@@ -729,20 +720,16 @@ AC_EGREP_CPP(FOUNDIT,
|
||||
)
|
||||
|
||||
AC_MSG_CHECKING([whether struct dirent allocates space for d_name])
|
||||
AC_RUN_IFELSE(
|
||||
[AC_LANG_SOURCE([[
|
||||
AC_TRY_RUN(
|
||||
[
|
||||
#include <sys/types.h>
|
||||
#include <dirent.h>
|
||||
int main(void){struct dirent d;exit(sizeof(d.d_name)<=sizeof(char));}
|
||||
]])],
|
||||
],
|
||||
[AC_MSG_RESULT(yes)],
|
||||
[
|
||||
AC_MSG_RESULT(no)
|
||||
AC_DEFINE(BROKEN_ONE_BYTE_DIRENT_D_NAME)
|
||||
],
|
||||
[
|
||||
AC_MSG_WARN([cross compiling: assuming BROKEN_ONE_BYTE_DIRENT_D_NAME])
|
||||
AC_DEFINE(BROKEN_ONE_BYTE_DIRENT_D_NAME)
|
||||
]
|
||||
)
|
||||
|
||||
@@ -902,32 +889,28 @@ AC_CHECK_DECLS(h_errno, , ,[#include <netdb.h>])
|
||||
AC_CHECK_FUNCS(setresuid, [
|
||||
dnl Some platorms have setresuid that isn't implemented, test for this
|
||||
AC_MSG_CHECKING(if setresuid seems to work)
|
||||
AC_RUN_IFELSE(
|
||||
[AC_LANG_SOURCE([[
|
||||
AC_TRY_RUN([
|
||||
#include <stdlib.h>
|
||||
#include <errno.h>
|
||||
int main(){errno=0; setresuid(0,0,0); if (errno==ENOSYS) exit(1); else exit(0);}
|
||||
]])],
|
||||
],
|
||||
[AC_MSG_RESULT(yes)],
|
||||
[AC_DEFINE(BROKEN_SETRESUID)
|
||||
AC_MSG_RESULT(not implemented)],
|
||||
[AC_MSG_WARN([cross compiling: not checking setresuid])]
|
||||
AC_MSG_RESULT(not implemented)]
|
||||
)
|
||||
])
|
||||
|
||||
AC_CHECK_FUNCS(setresgid, [
|
||||
dnl Some platorms have setresgid that isn't implemented, test for this
|
||||
AC_MSG_CHECKING(if setresgid seems to work)
|
||||
AC_RUN_IFELSE(
|
||||
[AC_LANG_SOURCE([[
|
||||
AC_TRY_RUN([
|
||||
#include <stdlib.h>
|
||||
#include <errno.h>
|
||||
int main(){errno=0; setresgid(0,0,0); if (errno==ENOSYS) exit(1); else exit(0);}
|
||||
]])],
|
||||
],
|
||||
[AC_MSG_RESULT(yes)],
|
||||
[AC_DEFINE(BROKEN_SETRESGID)
|
||||
AC_MSG_RESULT(not implemented)],
|
||||
[AC_MSG_WARN([cross compiling: not checking setresuid])]
|
||||
AC_MSG_RESULT(not implemented)]
|
||||
)
|
||||
])
|
||||
|
||||
@@ -953,18 +936,17 @@ AC_CHECK_FUNC(getpagesize,
|
||||
# Check for broken snprintf
|
||||
if test "x$ac_cv_func_snprintf" = "xyes" ; then
|
||||
AC_MSG_CHECKING([whether snprintf correctly terminates long strings])
|
||||
AC_RUN_IFELSE(
|
||||
[AC_LANG_SOURCE([[
|
||||
AC_TRY_RUN(
|
||||
[
|
||||
#include <stdio.h>
|
||||
int main(void){char b[5];snprintf(b,5,"123456789");exit(b[4]!='\0');}
|
||||
]])],
|
||||
],
|
||||
[AC_MSG_RESULT(yes)],
|
||||
[
|
||||
AC_MSG_RESULT(no)
|
||||
AC_DEFINE(BROKEN_SNPRINTF)
|
||||
AC_MSG_WARN([****** Your snprintf() function is broken, complain to your vendor])
|
||||
],
|
||||
[ AC_MSG_WARN([cross compiling: Assuming working snprintf()]) ]
|
||||
]
|
||||
)
|
||||
fi
|
||||
|
||||
@@ -1123,6 +1105,24 @@ main(void)
|
||||
)
|
||||
fi
|
||||
|
||||
if test "x$check_for_conflicting_getspnam" = "x1"; then
|
||||
AC_MSG_CHECKING(for conflicting getspnam in shadow.h)
|
||||
AC_COMPILE_IFELSE(
|
||||
[
|
||||
#include <shadow.h>
|
||||
int main(void) {exit(0);}
|
||||
],
|
||||
[
|
||||
AC_MSG_RESULT(no)
|
||||
],
|
||||
[
|
||||
AC_MSG_RESULT(yes)
|
||||
AC_DEFINE(GETSPNAM_CONFLICTING_DEFS, 1,
|
||||
[Conflicting defs for getspnam])
|
||||
]
|
||||
)
|
||||
fi
|
||||
|
||||
AC_FUNC_GETPGRP
|
||||
|
||||
# Check for PAM libs
|
||||
@@ -1225,8 +1225,8 @@ AC_TRY_LINK_FUNC(RAND_add, AC_DEFINE(HAVE_OPENSSL),
|
||||
|
||||
# Determine OpenSSL header version
|
||||
AC_MSG_CHECKING([OpenSSL header version])
|
||||
AC_RUN_IFELSE(
|
||||
[AC_LANG_SOURCE([[
|
||||
AC_TRY_RUN(
|
||||
[
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
#include <openssl/opensslv.h>
|
||||
@@ -1244,7 +1244,7 @@ int main(void) {
|
||||
|
||||
exit(0);
|
||||
}
|
||||
]])],
|
||||
],
|
||||
[
|
||||
ssl_header_ver=`cat conftest.sslincver`
|
||||
AC_MSG_RESULT($ssl_header_ver)
|
||||
@@ -1252,16 +1252,13 @@ int main(void) {
|
||||
[
|
||||
AC_MSG_RESULT(not found)
|
||||
AC_MSG_ERROR(OpenSSL version header not found.)
|
||||
],
|
||||
[
|
||||
AC_MSG_WARN([cross compiling: not checking])
|
||||
]
|
||||
)
|
||||
|
||||
# Determine OpenSSL library version
|
||||
AC_MSG_CHECKING([OpenSSL library version])
|
||||
AC_RUN_IFELSE(
|
||||
[AC_LANG_SOURCE([[
|
||||
AC_TRY_RUN(
|
||||
[
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
#include <openssl/opensslv.h>
|
||||
@@ -1280,7 +1277,7 @@ int main(void) {
|
||||
|
||||
exit(0);
|
||||
}
|
||||
]])],
|
||||
],
|
||||
[
|
||||
ssl_library_ver=`cat conftest.ssllibver`
|
||||
AC_MSG_RESULT($ssl_library_ver)
|
||||
@@ -1288,20 +1285,17 @@ int main(void) {
|
||||
[
|
||||
AC_MSG_RESULT(not found)
|
||||
AC_MSG_ERROR(OpenSSL library not found.)
|
||||
],
|
||||
[
|
||||
AC_MSG_WARN([cross compiling: not checking])
|
||||
]
|
||||
)
|
||||
|
||||
# Sanity check OpenSSL headers
|
||||
AC_MSG_CHECKING([whether OpenSSL's headers match the library])
|
||||
AC_RUN_IFELSE(
|
||||
[AC_LANG_SOURCE([[
|
||||
AC_TRY_RUN(
|
||||
[
|
||||
#include <string.h>
|
||||
#include <openssl/opensslv.h>
|
||||
int main(void) { exit(SSLeay() == OPENSSL_VERSION_NUMBER ? 0 : 1); }
|
||||
]])],
|
||||
],
|
||||
[
|
||||
AC_MSG_RESULT(yes)
|
||||
],
|
||||
@@ -1310,9 +1304,6 @@ int main(void) { exit(SSLeay() == OPENSSL_VERSION_NUMBER ? 0 : 1); }
|
||||
AC_MSG_ERROR([Your OpenSSL headers do not match your library.
|
||||
Check config.log for details.
|
||||
Also see contrib/findssl.sh for help identifying header/library mismatches.])
|
||||
],
|
||||
[
|
||||
AC_MSG_WARN([cross compiling: not checking])
|
||||
]
|
||||
)
|
||||
|
||||
@@ -1333,12 +1324,12 @@ fi
|
||||
|
||||
# Check wheter OpenSSL seeds itself
|
||||
AC_MSG_CHECKING([whether OpenSSL's PRNG is internally seeded])
|
||||
AC_RUN_IFELSE(
|
||||
[AC_LANG_SOURCE([[
|
||||
AC_TRY_RUN(
|
||||
[
|
||||
#include <string.h>
|
||||
#include <openssl/rand.h>
|
||||
int main(void) { exit(RAND_status() == 1 ? 0 : 1); }
|
||||
]])],
|
||||
],
|
||||
[
|
||||
OPENSSL_SEEDS_ITSELF=yes
|
||||
AC_MSG_RESULT(yes)
|
||||
@@ -1348,12 +1339,6 @@ int main(void) { exit(RAND_status() == 1 ? 0 : 1); }
|
||||
# Default to use of the rand helper if OpenSSL doesn't
|
||||
# seed itself
|
||||
USE_RAND_HELPER=yes
|
||||
],
|
||||
[
|
||||
AC_MSG_WARN([cross compiling: assuming yes])
|
||||
# This is safe, since all recent OpenSSL versions will
|
||||
# complain at runtime if not seeded correctly.
|
||||
OPENSSL_SEEDS_ITSELF=yes
|
||||
]
|
||||
)
|
||||
|
||||
@@ -1920,8 +1905,8 @@ if test "x$ac_cv_have_int64_t" = "xno" -a \
|
||||
exit 1;
|
||||
else
|
||||
dnl test snprintf (broken on SCO w/gcc)
|
||||
AC_RUN_IFELSE(
|
||||
[AC_LANG_SOURCE([[
|
||||
AC_TRY_RUN(
|
||||
[
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
#ifdef HAVE_SNPRINTF
|
||||
@@ -1944,8 +1929,7 @@ main()
|
||||
#else
|
||||
main() { exit(0); }
|
||||
#endif
|
||||
]])], [ true ], [ AC_DEFINE(BROKEN_SNPRINTF) ],
|
||||
AC_MSG_WARN([cross compiling: Assuming working snprintf()])
|
||||
], [ true ], [ AC_DEFINE(BROKEN_SNPRINTF) ]
|
||||
)
|
||||
fi
|
||||
|
||||
@@ -2050,14 +2034,13 @@ fi
|
||||
dnl make sure we're using the real structure members and not defines
|
||||
AC_CACHE_CHECK([for msg_accrights field in struct msghdr],
|
||||
ac_cv_have_accrights_in_msghdr, [
|
||||
AC_COMPILE_IFELSE(
|
||||
AC_TRY_RUN(
|
||||
[
|
||||
#include <sys/types.h>
|
||||
#include <sys/socket.h>
|
||||
#include <sys/uio.h>
|
||||
int main() {
|
||||
#ifdef msg_accrights
|
||||
#error "msg_accrights is a macro"
|
||||
exit(1);
|
||||
#endif
|
||||
struct msghdr m;
|
||||
@@ -2075,14 +2058,13 @@ fi
|
||||
|
||||
AC_CACHE_CHECK([for msg_control field in struct msghdr],
|
||||
ac_cv_have_control_in_msghdr, [
|
||||
AC_COMPILE_IFELSE(
|
||||
AC_TRY_RUN(
|
||||
[
|
||||
#include <sys/types.h>
|
||||
#include <sys/socket.h>
|
||||
#include <sys/uio.h>
|
||||
int main() {
|
||||
#ifdef msg_control
|
||||
#error "msg_control is a macro"
|
||||
exit(1);
|
||||
#endif
|
||||
struct msghdr m;
|
||||
@@ -2416,10 +2398,6 @@ if test ! -z "$MAIL" ; then
|
||||
AC_DEFINE_UNQUOTED(MAIL_DIRECTORY, "$maildir")
|
||||
fi
|
||||
|
||||
if test ! -z "$cross_compiling" && test "x$cross_compiling" = "xyes"; then
|
||||
AC_MSG_WARN([cross compiling: Disabling /dev/ptmx test])
|
||||
disable_ptmx_check=yes
|
||||
fi
|
||||
if test -z "$no_dev_ptmx" ; then
|
||||
if test "x$disable_ptmx_check" != "xyes" ; then
|
||||
AC_CHECK_FILE("/dev/ptmx",
|
||||
@@ -2430,17 +2408,12 @@ if test -z "$no_dev_ptmx" ; then
|
||||
)
|
||||
fi
|
||||
fi
|
||||
|
||||
if test ! -z "$cross_compiling" && test "x$cross_compiling" != "xyes"; then
|
||||
AC_CHECK_FILE("/dev/ptc",
|
||||
[
|
||||
AC_DEFINE_UNQUOTED(HAVE_DEV_PTS_AND_PTC)
|
||||
have_dev_ptc=1
|
||||
]
|
||||
)
|
||||
else
|
||||
AC_MSG_WARN([cross compiling: Disabling /dev/ptc test])
|
||||
fi
|
||||
AC_CHECK_FILE("/dev/ptc",
|
||||
[
|
||||
AC_DEFINE_UNQUOTED(HAVE_DEV_PTS_AND_PTC)
|
||||
have_dev_ptc=1
|
||||
]
|
||||
)
|
||||
|
||||
# Options from here on. Some of these are preset by platform above
|
||||
AC_ARG_WITH(mantype,
|
||||
@@ -2537,17 +2510,13 @@ fi
|
||||
# check for /etc/default/login and use it if present.
|
||||
AC_ARG_ENABLE(etc-default-login,
|
||||
[ --disable-etc-default-login Disable using PATH from /etc/default/login [no]],,
|
||||
[ AC_CHECK_FILE("/etc/default/login",
|
||||
[ external_path_file=/etc/default/login ])
|
||||
[
|
||||
AC_CHECK_FILE("/etc/default/login", [ external_path_file=/etc/default/login ])
|
||||
|
||||
if test ! -z "$cross_compiling" && test "x$cross_compiling" = "xyes";
|
||||
then
|
||||
AC_MSG_WARN([cross compiling: Disabling /etc/default/login test])
|
||||
elif test "x$external_path_file" = "x/etc/default/login"; then
|
||||
AC_DEFINE(HAVE_ETC_DEFAULT_LOGIN)
|
||||
fi
|
||||
]
|
||||
)
|
||||
if test "x$external_path_file" = "x/etc/default/login"; then
|
||||
AC_DEFINE(HAVE_ETC_DEFAULT_LOGIN)
|
||||
fi
|
||||
])
|
||||
|
||||
dnl BSD systems use /etc/login.conf so --with-default-path= has no effect
|
||||
if test $ac_cv_func_login_getcapbool = "yes" -a \
|
||||
@@ -3047,8 +3016,7 @@ echo " Libraries: ${LIBWRAP} ${LIBPAM} ${LIBS}"
|
||||
echo ""
|
||||
|
||||
if test "x$MAKE_PACKAGE_SUPPORTED" = "xyes" ; then
|
||||
echo "SVR4 style packages are supported with \"make package\""
|
||||
echo ""
|
||||
echo "SVR4 style packages are supported with \"make package\"\n"
|
||||
fi
|
||||
|
||||
if test "x$PAM_MSG" = "xyes" ; then
|
||||
|
||||
+1
-1
@@ -185,7 +185,7 @@ static /**/const char *const rcsid[] = { (char *)rcsid, "\100(#)" msg }
|
||||
* On HP-UX 11.11, shadow.h and prot.h provide conflicting declarations
|
||||
* of getspnam when _INCLUDE__STDC__ is defined, so we unset it here.
|
||||
*/
|
||||
#ifdef __hpux
|
||||
#ifdef GETSPNAM_CONFLICTING_DEFS
|
||||
# ifdef _INCLUDE__STDC__
|
||||
# undef _INCLUDE__STDC__
|
||||
# endif
|
||||
|
||||
Reference in New Issue
Block a user