.depend update RPM spec files upstream: openssh-10.6 upstream: Add test for proxycommand percent expansions. upstream: backout regress bits related to multiplexing change remove the --disable-fd-passing configure option disable features when post-auth sshd runs as root Don't automatically enable FORTIFY_SOURCE. upstream: Further restrict the characters allowed in a command-line Remove NetBSD 9.0 test target. Replace native ARM runner with remote runner. Pull older NetBSD sudo package from archive. upstream: make StreamLocalBindMask properly first-match-wins; upstream: make StreamLocalBindMask properly respect Host/Match upstream: start process of deprecating the -R flag. This was the upstream: mention default KDF rounds is now 32 upstream: Implement a maximum number of KDF rounds that will be upstream: fix the bit length of ML-DSA 44/Ed25519 keys that was upstream: sftp: be stricter in accepting paths returned by the upstream: handle max-pk-ok path identically when the incoming user upstream: Disallow nul byte in received scp -O filename. Not upstream: backout upstream: Check that compressed payloads don't inflate beyond the upstream: ssh-agent: no unlink(2) on empty filename upstream: ssh-agent: fix socket cleanup for -a option (no pathspec) upstream: Disable LZ77 dictionary coder to avoid a potential upstream: check ssh's handling of stale multiplexing sockets From Jens upstream: avoid race between multiple processes attempting to upstream: Include local and remote versions in ~I connection info. Remove the NetBSD BROKEN_READ_COMPARISON workaround. Ignore build/install status of netcat in tests. Add FreeBSD 15 test targets. upstream: Better wording. upstream: use Nm instead of Xr to self Don't deref NULL on STREAMS tty alloc failure. upstream: Plug leak. CID 913600. upstream: an abbreviation ending in a dot at EOL requires escaping upstream: tweak 1.406: minor wording and markup OK djm@ upstream: draft-ietf-sshm-ssh-agent became RFC 9987 ok dtucker@ Remove leftover from testing. Add fallback for mkdir_path() without openat(). upstream: Use >= instead of > for max comparison so that the upstream: Use equality not assignment in ternary. CID 913600. upstream: spelling; ok deraadt@ Also skip scp3 test on Darwin 26 and 27. upstream: convert channel timeouts to use floating points, allows upstream: masking signals requried sigaddset, not sigdelset; bz3981 upstream: bz3635 - ssh-add -P to skip PIN entry upstream: simpler upstream: leaks on error paths; spotted by Coverity CID 913598 upstream: fix inverted logic that could cause a memleak; spotted en upstream: Add missing semicolon after return. CID 913599, ok upstream: correctly check sshauthopt->restricted merging unbreak readpassphrase.c sync sync readpassphrase(3) with OpenBSD libc upstream: whitespace upstream: adapt to libsodium ed25519 implementation upstream: missing part of previous commit: update script to upstream: switch from SUPERCOP ed25519 to libsodium upstream: Only store GSSAPI creds when authn succeeds upstream: Reset GSSAPI client state before authentication upstream: Correctly handle some options that accept "none" upstream: Propagate authorized_keys "resrict" keyword upstream: Check key and CA sig type during key parsing upstream: Add WarnWeakCrypto to sshd upstream: Allow specification of agent socket directories upstream: Account pubkey checks separately to auth attempts upstream: Extend TCPKeepAlive to support forwardings too upstream: Mask SIGTERM/SIGQUIT when processing a SIGHUP restart fix merge botch that put lines in wrong function upstream: Correct handling of DST when converting dates upstream: sk-usbhid: preserve UV requirement for resident keys upstream: Fix memory leak on an error path in mkdir_path upstream: sftp: don't crash when glob(3) results lack stat information openpty: mark inputs const upstream: replace testing of vendor PQ signature algorithm upstream: minor leak of fingerprint text when printing upstream: the default KDF rounds for keys generated by ssh-keygen Don't link sshd against libselinux upstream: warnings fixes (static vs missing prototype, sign conversion) sshd doesn't need sshpty.c any more upstream: wrap line upstream: g/c prototype upstream: disconnect_controlling_tty() is the only thing from sshpty.c upstream: Fix ChannelTimeout specificity allow madvise(..., MADV_DONTNEED_LOCKED) upstream: fix case for ssh -G option output; bz4005, reported by upstream: mux proxy sockets also share in and out fds, so using upstream: don't attempt to set TCP_NODELAY on non-AF_INET[6] upstream: add a "hexdump" export mode that dumps the key blob in upstream: Add '-p' to sftp mkdir/lmkdir to create directories as upstream: Use getexecpath(3); if it fails use argv[0] as before upstream: Change three paragraphs in different parts of the manual upstream: update fingerprint example from RSA to Ed25519 host key upstream: Remove scp '-s' flag from synopsis, the flag has been a set -Wno-error=discarded-qualifiers seccomp sandbox: restrict mremap flags upstream: reenable ssh-mldsa44-ed25519 at a low priority position upstream: IANA has allocated a non-vendor codepoint for upstream: grammar; a -> an upstream: Bump size of key comment buffers. Prevents warnings on allow PAMServiceName in Match (regressed in 10.4) Move le32toh and friends to after platform flags. Skip scp3 test on macosx 26 until debugged. Remove ubuntu-26.04-arm kitchensink test target. special treatment for a more Turkic languages Group command for Yubico PPA correctly. Make FIDO2 packages optional. Update dependencies for Debian derivatives. Install libcrypt-dev package. Fix quoting in failed log output step. Add newer OS X and Ubunty 26.04 test targets. Require kSBXProfilePureComputation for OS X sandbox. upstream: Refer to id_mldsa44_ed25519.pub in the pubkey list. bz#3989. Add instructions for pin_actions. Update NetBSD vmaction pin to pick up 11.0 release. Update x11-ssh-askpass upstream location. Add NetBSD 11.0 test targets. Add 10.5 branch to test status display. whitespace at eol