From dae49ade37fafe4dd27d3aec3d3fc39fe4ef6ad2 Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Wed, 7 Oct 2026 05:22:35 +0000 Subject: [PATCH] openssh: upgrade 10.5p1 -> 10.6p1 .depend update RPM spec files upstream: openssh-10.6 upstream: Add test for proxycommand percent expansions. upstream: backout regress bits related to multiplexing change remove the --disable-fd-passing configure option disable features when post-auth sshd runs as root Don't automatically enable FORTIFY_SOURCE. upstream: Further restrict the characters allowed in a command-line Remove NetBSD 9.0 test target. Replace native ARM runner with remote runner. Pull older NetBSD sudo package from archive. upstream: make StreamLocalBindMask properly first-match-wins; upstream: make StreamLocalBindMask properly respect Host/Match upstream: start process of deprecating the -R flag. This was the upstream: mention default KDF rounds is now 32 upstream: Implement a maximum number of KDF rounds that will be upstream: fix the bit length of ML-DSA 44/Ed25519 keys that was upstream: sftp: be stricter in accepting paths returned by the upstream: handle max-pk-ok path identically when the incoming user upstream: Disallow nul byte in received scp -O filename. Not upstream: backout upstream: Check that compressed payloads don't inflate beyond the upstream: ssh-agent: no unlink(2) on empty filename upstream: ssh-agent: fix socket cleanup for -a option (no pathspec) upstream: Disable LZ77 dictionary coder to avoid a potential upstream: check ssh's handling of stale multiplexing sockets From Jens upstream: avoid race between multiple processes attempting to upstream: Include local and remote versions in ~I connection info. Remove the NetBSD BROKEN_READ_COMPARISON workaround. Ignore build/install status of netcat in tests. Add FreeBSD 15 test targets. upstream: Better wording. upstream: use Nm instead of Xr to self Don't deref NULL on STREAMS tty alloc failure. upstream: Plug leak. CID 913600. upstream: an abbreviation ending in a dot at EOL requires escaping upstream: tweak 1.406: minor wording and markup OK djm@ upstream: draft-ietf-sshm-ssh-agent became RFC 9987 ok dtucker@ Remove leftover from testing. Add fallback for mkdir_path() without openat(). upstream: Use >= instead of > for max comparison so that the upstream: Use equality not assignment in ternary. CID 913600. upstream: spelling; ok deraadt@ Also skip scp3 test on Darwin 26 and 27. upstream: convert channel timeouts to use floating points, allows upstream: masking signals requried sigaddset, not sigdelset; bz3981 upstream: bz3635 - ssh-add -P to skip PIN entry upstream: simpler upstream: leaks on error paths; spotted by Coverity CID 913598 upstream: fix inverted logic that could cause a memleak; spotted en upstream: Add missing semicolon after return. CID 913599, ok upstream: correctly check sshauthopt->restricted merging unbreak readpassphrase.c sync sync readpassphrase(3) with OpenBSD libc upstream: whitespace upstream: adapt to libsodium ed25519 implementation upstream: missing part of previous commit: update script to upstream: switch from SUPERCOP ed25519 to libsodium upstream: Only store GSSAPI creds when authn succeeds upstream: Reset GSSAPI client state before authentication upstream: Correctly handle some options that accept "none" upstream: Propagate authorized_keys "resrict" keyword upstream: Check key and CA sig type during key parsing upstream: Add WarnWeakCrypto to sshd upstream: Allow specification of agent socket directories upstream: Account pubkey checks separately to auth attempts upstream: Extend TCPKeepAlive to support forwardings too upstream: Mask SIGTERM/SIGQUIT when processing a SIGHUP restart fix merge botch that put lines in wrong function upstream: Correct handling of DST when converting dates upstream: sk-usbhid: preserve UV requirement for resident keys upstream: Fix memory leak on an error path in mkdir_path upstream: sftp: don't crash when glob(3) results lack stat information openpty: mark inputs const upstream: replace testing of vendor PQ signature algorithm upstream: minor leak of fingerprint text when printing upstream: the default KDF rounds for keys generated by ssh-keygen Don't link sshd against libselinux upstream: warnings fixes (static vs missing prototype, sign conversion) sshd doesn't need sshpty.c any more upstream: wrap line upstream: g/c prototype upstream: disconnect_controlling_tty() is the only thing from sshpty.c upstream: Fix ChannelTimeout specificity allow madvise(..., MADV_DONTNEED_LOCKED) upstream: fix case for ssh -G option output; bz4005, reported by upstream: mux proxy sockets also share in and out fds, so using upstream: don't attempt to set TCP_NODELAY on non-AF_INET[6] upstream: add a "hexdump" export mode that dumps the key blob in upstream: Add '-p' to sftp mkdir/lmkdir to create directories as upstream: Use getexecpath(3); if it fails use argv[0] as before upstream: Change three paragraphs in different parts of the manual upstream: update fingerprint example from RSA to Ed25519 host key upstream: Remove scp '-s' flag from synopsis, the flag has been a set -Wno-error=discarded-qualifiers seccomp sandbox: [Changelog truncated as it exceeds 5000 characters; the full changelog can be found in an attachment to the AUH email] --- ...1-regress-banner.sh-log-input-and-output-files-on-erro.patch | 2 +- .../openssh/{openssh_10.5p1.bb => openssh_10.6p1.bb} | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) rename meta/recipes-connectivity/openssh/{openssh_10.5p1.bb => openssh_10.6p1.bb} (99%) diff --git a/meta/recipes-connectivity/openssh/openssh/0001-regress-banner.sh-log-input-and-output-files-on-erro.patch b/meta/recipes-connectivity/openssh/openssh/0001-regress-banner.sh-log-input-and-output-files-on-erro.patch index f424288e37..aa25f09537 100644 --- a/meta/recipes-connectivity/openssh/openssh/0001-regress-banner.sh-log-input-and-output-files-on-erro.patch +++ b/meta/recipes-connectivity/openssh/openssh/0001-regress-banner.sh-log-input-and-output-files-on-erro.patch @@ -1,4 +1,4 @@ -From 5cc897fe2effe549e1e280c2f606bce8b532b61e Mon Sep 17 00:00:00 2001 +From af460c6fc73213c41a498dc15f72e6e64f2342f1 Mon Sep 17 00:00:00 2001 From: Mikko Rapeli Date: Mon, 11 Sep 2023 09:55:21 +0100 Subject: [PATCH] regress/banner.sh: log input and output files on error diff --git a/meta/recipes-connectivity/openssh/openssh_10.5p1.bb b/meta/recipes-connectivity/openssh/openssh_10.6p1.bb similarity index 99% rename from meta/recipes-connectivity/openssh/openssh_10.5p1.bb rename to meta/recipes-connectivity/openssh/openssh_10.6p1.bb index 052686f289..6043f140b3 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.5p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.6p1.bb @@ -25,7 +25,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://sshd_check_keys \ file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \ " -SRC_URI[sha256sum] = "d44d28a839ea9daf969cc69150fde59910b2b39361dad81a3bd6cbd19218db11" +SRC_URI[sha256sum] = "a9dc9565dffe8640f64d863cd29a32bc4a3dbdec0566a7fc44c5d6ee767d5f39" CVE_STATUS[CVE-2007-2768] = "not-applicable-config: This CVE is specific to OpenSSH with the pam opie which we don't build/use here." -- 2.47.1