Compare commits

..
10 Commits
Author SHA1 Message Date
[email protected] 3eeda15eb9 upstream: Check if dbclient supports SHA1 before trying SHA1-based
KEX.

Dropbear 2025.87 removed SHA1 support by default, which means
diffie-hellman-group14-sha1 is not available.  Unfortunately there isn't a
flag to query supported KEX, so instead check MACs and if it doesn't have
SHA1 methods, assuming SHA1 based KEXes are likewise not available.  Spotted
by anton@.

OpenBSD-Regress-ID: acfa8e26c001cb18b9fb81a27271c3b51288d304
2025-03-16 15:00:02 +11:00
[email protected] 8e4bd6ebdb upstream: Remove redundant field of definition check
This will allow us to get rid of EC_GROUP_method_of() in the near future.

ok djm

OpenBSD-Commit-ID: b4a3d2e00990cf5c2ec6881c21ddca67327c2df8
2025-03-14 13:02:20 +11:00
Darren Tucker aab12549a9 MacOS 12 runners are deprecated, replace with 15. 2025-03-14 13:00:48 +11:00
[email protected] be8026caf9 upstream: Prime caches for DNS names needed for tests.
When running the SSHFP tests, particularly on an ephemeral VM, the first
query or two can fail for some reason, presumably because something isn't
fully initialized or something.  To work around this, issue queries for the
names we'll need before we need them.

OpenBSD-Regress-ID: 900841133540e7dead253407db5a874a6ed09eca
2025-03-13 19:08:53 +11:00
Damien Miller 7d5b6c7ec3 regenerate configure, config.h.in 2025-03-03 14:21:12 +11:00
[email protected] d58ae05bb7 upstream: fix PerSourcePenalty incorrectly using "crash" penalty when
LoginGraceTime was exceeded. Reported by irwin AT princeton.edu via bz3797

OpenBSD-Commit-ID: 1ba3e490a5a9451359618c550d995380af454d25
2025-03-03 09:45:07 +11:00
Damien Miller 3b4adf2018 include __builtin_popcount replacement function
Some systems/compilers lack __builtin_popcount(), so replace it as
necessary. Reported by Dennis Clarke; ok dtucker@
2025-03-03 09:45:02 +11:00
Darren Tucker ef95df4089 Rebuild config files if Makefile changes.
This ensures paths are updated if they are changed by re-running configure.
Patch from rapier at psc.edu.
2025-03-01 10:28:59 +11:00
Darren Tucker de4bcb51c8 Update autoconf files for endian.h change. 2025-02-26 18:25:33 +11:00
Darren Tucker 4b8d141ec1 Check for le32toh, le64toh, htole64 individually.
It appears that at least some versions of endian.h in glibc do not have
the latter two, so check for and replace each one individually.
bz#3794, ok djm@
2025-02-26 18:24:58 +11:00
12 changed files with 192 additions and 33 deletions
+2 -2
View File
@@ -17,9 +17,9 @@ jobs:
target:
- ubuntu-20.04
- ubuntu-22.04
- macos-12
- macos-13
- macos-14
- macos-15
- windows-2019
- windows-2022
config: [default]
@@ -100,9 +100,9 @@ jobs:
- { target: ubuntu-22.04, config: selinux }
- { target: ubuntu-22.04, config: kitchensink }
- { target: ubuntu-22.04, config: without-openssl }
- { target: macos-12, config: pam }
- { target: macos-13, config: pam }
- { target: macos-14, config: pam }
- { target: macos-15, config: pam }
runs-on: ${{ matrix.target }}
steps:
- name: set cygwin git params
+1 -1
View File
@@ -267,7 +267,7 @@ $(MANPAGES): $(MANPAGES_IN)
$(FIXPATHSCMD) $${manpage} | $(FIXALGORITHMSCMD) > $@; \
fi
$(CONFIGFILES): $(CONFIGFILES_IN)
$(CONFIGFILES): $(CONFIGFILES_IN) Makefile
conffile=`echo $@ | sed 's/.out$$//'`; \
$(FIXPATHSCMD) $(srcdir)/$${conffile} > $@
+15
View File
@@ -363,10 +363,22 @@
don't. */
#undef HAVE_DECL_HOWMANY
/* Define to 1 if you have the declaration of `htole64', and to 0 if you
don't. */
#undef HAVE_DECL_HTOLE64
/* Define to 1 if you have the declaration of `h_errno', and to 0 if you
don't. */
#undef HAVE_DECL_H_ERRNO
/* Define to 1 if you have the declaration of `le32toh', and to 0 if you
don't. */
#undef HAVE_DECL_LE32TOH
/* Define to 1 if you have the declaration of `le64toh', and to 0 if you
don't. */
#undef HAVE_DECL_LE64TOH
/* Define to 1 if you have the declaration of `loginfailed', and to 0 if you
don't. */
#undef HAVE_DECL_LOGINFAILED
@@ -1736,6 +1748,9 @@
/* Set this to your mail directory if you do not have _PATH_MAILDIR */
#undef MAIL_DIRECTORY
/* Define if your compiler lacks __builtin_popcount */
#undef MISSING_BUILTIN_POPCOUNT
/* Need setpgrp to for controlling tty */
#undef NEED_SETPGRP
Vendored
+93
View File
@@ -11325,6 +11325,65 @@ then :
fi
ac_fn_check_decl "$LINENO" "le32toh" "ac_cv_have_decl_le32toh" "
#ifdef HAVE_SYS_TYPES_H
# include <sys/types.h>
#endif
#ifdef HAVE_STDINT_H
# include <stdint.h>
#endif
#ifdef HAVE_ENDIAN_H
# include <endian.h>
#endif
" "$ac_c_undeclared_builtin_options" "CFLAGS"
if test "x$ac_cv_have_decl_le32toh" = xyes
then :
ac_have_decl=1
else $as_nop
ac_have_decl=0
fi
printf "%s\n" "#define HAVE_DECL_LE32TOH $ac_have_decl" >>confdefs.h
ac_fn_check_decl "$LINENO" "le64toh" "ac_cv_have_decl_le64toh" "
#ifdef HAVE_SYS_TYPES_H
# include <sys/types.h>
#endif
#ifdef HAVE_STDINT_H
# include <stdint.h>
#endif
#ifdef HAVE_ENDIAN_H
# include <endian.h>
#endif
" "$ac_c_undeclared_builtin_options" "CFLAGS"
if test "x$ac_cv_have_decl_le64toh" = xyes
then :
ac_have_decl=1
else $as_nop
ac_have_decl=0
fi
printf "%s\n" "#define HAVE_DECL_LE64TOH $ac_have_decl" >>confdefs.h
ac_fn_check_decl "$LINENO" "htole64" "ac_cv_have_decl_htole64" "
#ifdef HAVE_SYS_TYPES_H
# include <sys/types.h>
#endif
#ifdef HAVE_STDINT_H
# include <stdint.h>
#endif
#ifdef HAVE_ENDIAN_H
# include <endian.h>
#endif
" "$ac_c_undeclared_builtin_options" "CFLAGS"
if test "x$ac_cv_have_decl_htole64" = xyes
then :
ac_have_decl=1
else $as_nop
ac_have_decl=0
fi
printf "%s\n" "#define HAVE_DECL_HTOLE64 $ac_have_decl" >>confdefs.h
# On some platforms (eg SunOS4) sys/audit.h requires sys/[time|types|label.h]
# to be included first.
ac_fn_c_check_header_compile "$LINENO" "sys/audit.h" "ac_cv_header_sys_audit_h" "
@@ -16726,6 +16785,40 @@ then :
fi
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking whether compiler supports __builtin_popcount" >&5
printf %s "checking whether compiler supports __builtin_popcount... " >&6; }
cat confdefs.h - <<_ACEOF >conftest.$ac_ext
/* end confdefs.h. */
#include <stdlib.h>
int
main (void)
{
int x = 123, y;
y = __builtin_popcount(123);
exit(y == 6 ? 0 : -1);
;
return 0;
}
_ACEOF
if ac_fn_c_try_link "$LINENO"
then :
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5
printf "%s\n" "yes" >&6; }
else $as_nop
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5
printf "%s\n" "no" >&6; }
printf "%s\n" "#define MISSING_BUILTIN_POPCOUNT 1" >>confdefs.h
fi
rm -f core conftest.err conftest.$ac_objext conftest.beam \
conftest$ac_exeext conftest.$ac_ext
ac_fn_check_decl "$LINENO" "bzero" "ac_cv_have_decl_bzero" "$ac_includes_default" "$ac_c_undeclared_builtin_options" "CFLAGS"
if test "x$ac_cv_have_decl_bzero" = xyes
then :
+25
View File
@@ -536,6 +536,18 @@ AC_CHECK_HEADERS([ \
wchar.h \
])
AC_CHECK_DECLS([le32toh, le64toh, htole64], [], [], [
#ifdef HAVE_SYS_TYPES_H
# include <sys/types.h>
#endif
#ifdef HAVE_STDINT_H
# include <stdint.h>
#endif
#ifdef HAVE_ENDIAN_H
# include <endian.h>
#endif
])
# On some platforms (eg SunOS4) sys/audit.h requires sys/[time|types|label.h]
# to be included first.
AC_CHECK_HEADERS([sys/audit.h], [], [], [
@@ -2029,6 +2041,19 @@ AC_CHECK_FUNCS([ \
warn \
])
AC_MSG_CHECKING([whether compiler supports __builtin_popcount])
AC_LINK_IFELSE([AC_LANG_PROGRAM([[
#include <stdlib.h>
]],
[[ int x = 123, y;
y = __builtin_popcount(123);
exit(y == 6 ? 0 : -1); ]])],
[ AC_MSG_RESULT([yes]) ], [
AC_MSG_RESULT([no])
AC_DEFINE([MISSING_BUILTIN_POPCOUNT], [1], [Define if your compiler lacks __builtin_popcount])
]
)
AC_CHECK_DECLS([bzero, memmem])
dnl Wide character support.
+21 -7
View File
@@ -646,7 +646,9 @@ struct winsize {
# endif /* WORDS_BIGENDIAN */
#endif /* BYTE_ORDER */
#ifndef HAVE_ENDIAN_H
#if (defined(HAVE_DECL_LE32TOH) && HAVE_DECL_LE32TOH == 0) || \
(defined(HAVE_DECL_LE64TOH) && HAVE_DECL_LE64TOH == 0) || \
(defined(HAVE_DECL_HTOLE64) && HAVE_DECL_HTOLE64 == 0)
# define openssh_swap32(v) \
(uint32_t)(((uint32_t)(v) & 0xff) << 24 | \
((uint32_t)(v) & 0xff00) << 8 | \
@@ -662,13 +664,25 @@ struct winsize {
((uint64_t)(v) & 0xff000000000000ULL) >> 40 | \
((uint64_t)(v) & 0xff00000000000000ULL) >> 56)
# ifdef WORDS_BIGENDIAN
# define le32toh(v) (openssh_swap32(v))
# define le64toh(v) (openssh_swap64(v))
# define htole64(v) (openssh_swap64(v))
# if defined(HAVE_DECL_LE32TOH) && HAVE_DECL_LE32TOH == 0
# define le32toh(v) (openssh_swap32(v))
# endif
# if defined(HAVE_DECL_LE64TOH) && HAVE_DECL_LE64TOH == 0
# define le64toh(v) (openssh_swap64(v))
# endif
# if defined(HAVE_DECL_HTOLE64) && HAVE_DECL_HTOLE64 == 0
# define htole64(v) (openssh_swap64(v))
# endif
# else
# define le32toh(v) ((uint32_t)v)
# define le64toh(v) ((uint64_t)v)
# define htole64(v) ((uint64_t)v)
# if defined(HAVE_DECL_LE32TOH) && HAVE_DECL_LE32TOH == 0
# define le32toh(v) ((uint32_t)v)
# endif
# if defined(HAVE_DECL_LE64TOH) && HAVE_DECL_LE64TOH == 0
# define le64toh(v) ((uint64_t)v)
# endif
# if defined(HAVE_DECL_HTOLE64) && HAVE_DECL_HTOLE64 == 0
# define htole64(v) ((uint64_t)v)
# endif
# endif
#endif
+6 -2
View File
@@ -177,10 +177,14 @@ static inline uint32_t core_num__u32_8__from_le_bytes(uint8_t buf[4]) {
}
static inline uint32_t core_num__u8_6__count_ones(uint8_t x0) {
#ifdef _MSC_VER
#if defined(_MSC_VER)
return __popcnt(x0);
#else
#elif !defined(MISSING_BUILTIN_POPCOUNT)
return __builtin_popcount(x0);
#else
const uint8_t v[16] = { 0, 1, 1, 2, 1, 2, 2, 3, 1, 2, 2, 3, 2, 3, 3, 4 };
return v[x0 & 0xf] + v[(x0 >> 4) & 0xf];
#endif
}
+9 -1
View File
@@ -49,6 +49,11 @@ echo '#define KRML_HOST_EPRINTF(...)'
echo '#define KRML_HOST_EXIT(x) fatal_f("internal error")'
echo
__builtin_popcount_replacement='
const uint8_t v[16] = { 0, 1, 1, 2, 1, 2, 2, 3, 1, 2, 2, 3, 2, 3, 3, 4 };
return v[x0 & 0xf] + v[(x0 >> 4) & 0xf];
'
for i in $FILES; do
echo "/* from $i */"
# Changes to all files:
@@ -62,7 +67,10 @@ for i in $FILES; do
# Replace endian functions with versions that work.
perl -0777 -pe 's/(static inline void core_num__u64_9__to_le_bytes.*\n)([^}]*\n)/\1 v = htole64(v);\n\2/' |
perl -0777 -pe 's/(static inline uint64_t core_num__u64_9__from_le_bytes.*?)return v;/\1return le64toh(v);/s' |
perl -0777 -pe 's/(static inline uint32_t core_num__u32_8__from_le_bytes.*?)return v;/\1return le32toh(v);/s'
perl -0777 -pe 's/(static inline uint32_t core_num__u32_8__from_le_bytes.*?)return v;/\1return le32toh(v);/s' |
# Compat for popcount.
perl -0777 -pe 's/\#ifdef (_MSC_VER)(.*?return __popcnt\(x0\);)/\#if defined(\1)\2/s' |
perl -0777 -pe "s/\\#else(\\n\\s+return __builtin_popcount\\(x0\\);)/\\#elif !defined(MISSING_BUILTIN_POPCOUNT)\\1\\n#else$__builtin_popcount_replacement/s"
;;
# Default: pass through.
*)
+12 -5
View File
@@ -1,4 +1,4 @@
# $OpenBSD: dropbear-kex.sh,v 1.3 2024/06/19 10:10:46 dtucker Exp $
# $OpenBSD: dropbear-kex.sh,v 1.4 2025/03/11 07:42:08 dtucker Exp $
# Placed in the Public Domain.
tid="dropbear kex"
@@ -10,8 +10,14 @@ fi
cp $OBJ/sshd_proxy $OBJ/sshd_proxy.bak
kex="curve25519-sha256 [email protected]"
if $SSH -Q kex | grep 'diffie-hellman-group14-sha1'; then
kex="$kex diffie-hellman-group14-sha256 diffie-hellman-group14-sha1"
if $SSH -Q kex | grep 'diffie-hellman-group14-sha256' >/dev/null; then
kex="$kex diffie-hellman-group14-sha256"
fi
# There's no flag to query KEX, so if MACs does not contain SHA1, assume
# there's also SHA1-based KEX methods either.
if $SSH -Q kex | grep 'diffie-hellman-group14-sha1' >/dev/null && \
$DBCLIENT -m help hst 2>&1 | grep -- '-sha1' >/dev/null ; then
kex="$kex diffie-hellman-group14-sha1"
fi
for k in $kex; do
@@ -19,8 +25,9 @@ for k in $kex; do
rm -f ${COPY}
# dbclient doesn't have switch for kex, so force in server
(cat $OBJ/sshd_proxy.bak; echo "KexAlgorithms $k") >$OBJ/sshd_proxy
env HOME=$OBJ dbclient -y -i $OBJ/.dropbear/id_ed25519 2>$OBJ/dbclient.log \
-J "$OBJ/ssh_proxy.sh" somehost cat ${DATA} > ${COPY}
env HOME=$OBJ \
${DBCLIENT} -y -i $OBJ/.dropbear/id_ed25519 2>$OBJ/dbclient.log \
-J "$OBJ/ssh_proxy.sh" somehost cat ${DATA} > ${COPY}
if [ $? -ne 0 ]; then
fail "ssh cat $DATA failed"
fi
+7 -1
View File
@@ -1,4 +1,4 @@
# $OpenBSD: sshfp-connect.sh,v 1.4 2021/09/01 00:50:27 dtucker Exp $
# $OpenBSD: sshfp-connect.sh,v 1.5 2025/03/11 11:46:44 dtucker Exp $
# Placed in the Public Domain.
# This test requires external setup and thus is skipped unless
@@ -29,6 +29,12 @@ if ! $SSH -Q key-plain | grep ssh-rsa >/dev/null; then
elif [ -z "${TEST_SSH_SSHFP_DOMAIN}" ]; then
skip "TEST_SSH_SSHFP_DOMAIN not set."
else
# Prime any DNS caches and resolvers.
for i in sshtest sshtest-sha1 sshtest-sha256; do
host -t sshfp ${i}.${TEST_SSH_SSHFP_DOMAIN} >/dev/null 2>&1
host -t sshfp ${i}-bad.${TEST_SSH_SSHFP_DOMAIN} >/dev/null 2>&1
done
# Set RSA host key to match fingerprints above.
mv $OBJ/sshd_proxy $OBJ/sshd_proxy.orig
$SUDO cp $SRC/rsa_openssh.prv $OBJ/host.ssh-rsa
+1 -1
View File
@@ -386,7 +386,7 @@ srclimit_penalise(struct xaddr *addr, int penalty_type)
reason = "penalty: connection prohibited by RefuseConnection";
break;
case SRCLIMIT_PENALTY_GRACE_EXCEEDED:
penalty_secs = penalty_cfg.penalty_crash;
penalty_secs = penalty_cfg.penalty_grace;
reason = "penalty: exceeded LoginGraceTime";
break;
default:
-13
View File
@@ -2708,14 +2708,6 @@ sshkey_ec_validate_public(const EC_GROUP *group, const EC_POINT *public)
* EC_POINT_oct2point then the caller will need to explicitly check.
*/
/*
* We shouldn't ever hit this case because bignum_get_ecpoint()
* refuses to load GF2m points.
*/
if (EC_METHOD_get_field_type(EC_GROUP_method_of(group)) !=
NID_X9_62_prime_field)
goto out;
/* Q != infinity */
if (EC_POINT_is_at_infinity(group, public))
goto out;
@@ -2815,11 +2807,6 @@ sshkey_dump_ec_point(const EC_GROUP *group, const EC_POINT *point)
fprintf(stderr, "%s: BN_new failed\n", __func__);
goto out;
}
if (EC_METHOD_get_field_type(EC_GROUP_method_of(group)) !=
NID_X9_62_prime_field) {
fprintf(stderr, "%s: group is not a prime field\n", __func__);
goto out;
}
if (EC_POINT_get_affine_coordinates_GFp(group, point,
x, y, NULL) != 1) {
fprintf(stderr, "%s: EC_POINT_get_affine_coordinates_GFp\n",