Date: Fri, 1 Aug 2008 04:35:17 GMT From: Ed Schouten <ed@FreeBSD.org> To: Perforce Change Reviews <perforce@FreeBSD.org> Subject: PERFORCE change 146365 for review Message-ID: <200808010435.m714ZHGP014847@repoman.freebsd.org>
next in thread | raw e-mail | index | archive | help
http://perforce.freebsd.org/chv.cgi?CH=146365 Change 146365 by ed@ed_flippo on 2008/08/01 04:35:08 IFC. Affected files ... .. //depot/projects/mpsafetty/bin/sh/eval.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ChangeLog#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/FREEBSD-Xlist#2 delete .. //depot/projects/mpsafetty/crypto/openssh/FREEBSD-tricks#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/FREEBSD-upgrade#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/FREEBSD-vendor#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/INSTALL#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/LICENCE#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/PROTOCOL#1 branch .. //depot/projects/mpsafetty/crypto/openssh/PROTOCOL.agent#1 branch .. //depot/projects/mpsafetty/crypto/openssh/README#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/README.platform#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/RFC.nroff#2 delete .. //depot/projects/mpsafetty/crypto/openssh/addrmatch.c#1 branch .. //depot/projects/mpsafetty/crypto/openssh/atomicio.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/audit-bsm.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-bsdauth.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-chall.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-krb5.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-options.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-options.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-pam.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-pam.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-passwd.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-rhosts.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-rsa.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-shadow.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-sia.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth-skey.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth1.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth2-chall.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth2-gss.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth2-hostbased.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth2-kbdint.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth2-none.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth2-pubkey.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/auth2.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/bufaux.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/bufbn.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/buffer.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/canohost.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/channels.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/channels.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/cipher-3des1.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/cipher-bf1.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/cipher-ctr.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/clientloop.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/clientloop.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/compat.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/compat.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/config.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/config.h.in#1 branch .. //depot/projects/mpsafetty/crypto/openssh/defines.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/dh.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/dh.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/dns.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/entropy.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/groupaccess.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/groupaccess.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/gss-genr.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/gss-serv.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/includes.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/kex.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/kex.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/key.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/key.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/log.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/log.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/loginrec.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/mac.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/mac.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/match.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/match.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/misc.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/misc.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/moduli#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/moduli.5#1 branch .. //depot/projects/mpsafetty/crypto/openssh/moduli.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/monitor.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/monitor.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/monitor_fdpass.c#3 integrate .. //depot/projects/mpsafetty/crypto/openssh/monitor_fdpass.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/monitor_mm.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/monitor_wrap.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/monitor_wrap.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/mux.c#1 branch .. //depot/projects/mpsafetty/crypto/openssh/myproposal.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/nchan.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/base64.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/bindresvport.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/bsd-arc4random.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/bsd-asprintf.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/bsd-cray.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/bsd-cygwin_util.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/bsd-getpeereid.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/bsd-misc.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/bsd-poll.c#1 branch .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/bsd-poll.h#1 branch .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/bsd-snprintf.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/bsd-statvfs.c#1 branch .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/bsd-statvfs.h#1 branch .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/fake-rfc2553.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/fake-rfc2553.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/fmt_scaled.c#1 branch .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/getrrsetbyname.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/getrrsetbyname.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/glob.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/glob.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/openbsd-compat.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/openssl-compat.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/openssl-compat.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/port-aix.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/port-aix.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/port-linux.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/port-linux.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/port-tun.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/port-uw.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/port-uw.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/rresvport.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/setenv.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/setproctitle.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/sigact.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/sys-queue.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/sys-tree.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/xcrypt.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/openbsd-compat/xmmap.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/packet.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/packet.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/readconf.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/readconf.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/scard-opensc.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/scp.1#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/scp.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/servconf.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/servconf.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/serverloop.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/session.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/session.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sftp-client.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sftp-client.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sftp-server-main.c#1 branch .. //depot/projects/mpsafetty/crypto/openssh/sftp-server.8#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sftp-server.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sftp.1#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sftp.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sftp.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh-add.1#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh-add.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh-agent.1#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh-agent.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh-gss.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh-keygen.1#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh-keygen.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh-keyscan.1#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh-keyscan.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh-keysign.8#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh-rand-helper.8#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh-rand-helper.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh.1#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh_config#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh_config.5#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ssh_namespace.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sshconnect.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sshconnect.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sshconnect2.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sshd.8#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sshd.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sshd_config#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sshd_config.5#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sshlogin.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sshpty.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sshpty.h#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/sshtty.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/ttymodes.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/umac.c#1 branch .. //depot/projects/mpsafetty/crypto/openssh/umac.h#1 branch .. //depot/projects/mpsafetty/crypto/openssh/version.c#2 integrate .. //depot/projects/mpsafetty/crypto/openssh/version.h#2 integrate .. //depot/projects/mpsafetty/etc/rc.d/sysctl#2 integrate .. //depot/projects/mpsafetty/lib/libthr/thread/thr_condattr.c#2 integrate .. //depot/projects/mpsafetty/lib/libthread_db/Makefile#2 integrate .. //depot/projects/mpsafetty/lib/libthread_db/arch/amd64/libpthread_md.c#2 integrate .. //depot/projects/mpsafetty/lib/libthread_db/arch/arm/libpthread_md.c#2 integrate .. //depot/projects/mpsafetty/lib/libthread_db/arch/i386/libpthread_md.c#2 integrate .. //depot/projects/mpsafetty/lib/libthread_db/arch/ia64/libpthread_md.c#2 integrate .. //depot/projects/mpsafetty/lib/libthread_db/arch/powerpc/libpthread_md.c#2 integrate .. //depot/projects/mpsafetty/lib/libthread_db/arch/sparc64/libpthread_md.c#2 integrate .. //depot/projects/mpsafetty/lib/libthread_db/libpthread_db.c#3 integrate .. //depot/projects/mpsafetty/lib/libthread_db/libpthread_db.h#2 integrate .. //depot/projects/mpsafetty/lib/libthread_db/thread_db.c#3 integrate .. //depot/projects/mpsafetty/lib/libthread_db/thread_db_int.h#3 integrate .. //depot/projects/mpsafetty/lib/msun/Makefile#3 integrate .. //depot/projects/mpsafetty/lib/msun/Symbol.map#2 integrate .. //depot/projects/mpsafetty/lib/msun/ld128/invtrig.c#1 branch .. //depot/projects/mpsafetty/lib/msun/ld128/invtrig.h#1 branch .. //depot/projects/mpsafetty/lib/msun/ld80/invtrig.c#1 branch .. //depot/projects/mpsafetty/lib/msun/ld80/invtrig.h#1 branch .. //depot/projects/mpsafetty/lib/msun/man/acos.3#2 integrate .. //depot/projects/mpsafetty/lib/msun/man/asin.3#2 integrate .. //depot/projects/mpsafetty/lib/msun/man/atan.3#2 integrate .. //depot/projects/mpsafetty/lib/msun/man/atan2.3#2 integrate .. //depot/projects/mpsafetty/lib/msun/src/e_acos.c#2 integrate .. //depot/projects/mpsafetty/lib/msun/src/e_acosf.c#2 integrate .. //depot/projects/mpsafetty/lib/msun/src/e_acosl.c#1 branch .. //depot/projects/mpsafetty/lib/msun/src/e_asin.c#2 integrate .. //depot/projects/mpsafetty/lib/msun/src/e_asinf.c#2 integrate .. //depot/projects/mpsafetty/lib/msun/src/e_asinl.c#1 branch .. //depot/projects/mpsafetty/lib/msun/src/e_atan2.c#2 integrate .. //depot/projects/mpsafetty/lib/msun/src/e_atan2f.c#2 integrate .. //depot/projects/mpsafetty/lib/msun/src/e_atan2l.c#1 branch .. //depot/projects/mpsafetty/lib/msun/src/e_fmodl.c#2 integrate .. //depot/projects/mpsafetty/lib/msun/src/math.h#2 integrate .. //depot/projects/mpsafetty/lib/msun/src/s_atan.c#2 integrate .. //depot/projects/mpsafetty/lib/msun/src/s_atanf.c#2 integrate .. //depot/projects/mpsafetty/lib/msun/src/s_atanl.c#1 branch .. //depot/projects/mpsafetty/lib/msun/src/s_cargl.c#1 branch .. //depot/projects/mpsafetty/lib/msun/src/s_remquol.c#2 integrate .. //depot/projects/mpsafetty/sbin/fdisk/fdisk.8#2 integrate .. //depot/projects/mpsafetty/sbin/fdisk/fdisk.c#2 integrate .. //depot/projects/mpsafetty/sbin/ifconfig/ifieee80211.c#2 integrate .. //depot/projects/mpsafetty/secure/lib/libssh/Makefile#2 integrate .. //depot/projects/mpsafetty/secure/libexec/sftp-server/Makefile#2 integrate .. //depot/projects/mpsafetty/secure/usr.bin/ssh/Makefile#2 integrate .. //depot/projects/mpsafetty/secure/usr.sbin/sshd/Makefile#2 integrate .. //depot/projects/mpsafetty/sys/amd64/amd64/pmap.c#7 integrate .. //depot/projects/mpsafetty/sys/amd64/conf/GENERIC#4 integrate .. //depot/projects/mpsafetty/sys/amd64/include/pmap.h#3 integrate .. //depot/projects/mpsafetty/sys/bsm/audit.h#2 integrate .. //depot/projects/mpsafetty/sys/bsm/audit_internal.h#2 integrate .. //depot/projects/mpsafetty/sys/bsm/audit_kevents.h#2 integrate .. //depot/projects/mpsafetty/sys/bsm/audit_record.h#2 integrate .. //depot/projects/mpsafetty/sys/conf/files#7 integrate .. //depot/projects/mpsafetty/sys/dev/cxgb/ulp/tom/cxgb_cpl_io.c#4 integrate .. //depot/projects/mpsafetty/sys/dev/cxgb/ulp/tom/cxgb_cpl_socket.c#2 integrate .. //depot/projects/mpsafetty/sys/dev/cxgb/ulp/tom/cxgb_ddp.c#2 integrate .. //depot/projects/mpsafetty/sys/dev/cxgb/ulp/tom/cxgb_l2t.c#2 integrate .. //depot/projects/mpsafetty/sys/dev/cxgb/ulp/tom/cxgb_listen.c#2 integrate .. //depot/projects/mpsafetty/sys/dev/cxgb/ulp/tom/cxgb_tcp_offload.c#3 integrate .. //depot/projects/mpsafetty/sys/dev/cxgb/ulp/tom/cxgb_tcp_offload.h#3 integrate .. //depot/projects/mpsafetty/sys/dev/cxgb/ulp/tom/cxgb_tom.c#2 integrate .. //depot/projects/mpsafetty/sys/dev/cxgb/ulp/tom/cxgb_tom_sysctl.c#2 integrate .. //depot/projects/mpsafetty/sys/dev/e1000/LICENSE#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/README#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_80003es2lan.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_80003es2lan.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_82540.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_82541.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_82541.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_82542.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_82543.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_82543.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_82571.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_82571.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_82575.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_82575.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_api.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_api.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_defines.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_hw.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_ich8lan.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_ich8lan.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_mac.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_mac.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_manage.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_manage.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_nvm.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_nvm.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_osdep.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_osdep.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_phy.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_phy.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/e1000_regs.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/if_em.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/if_em.h#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/if_igb.c#1 branch .. //depot/projects/mpsafetty/sys/dev/e1000/if_igb.h#1 branch .. //depot/projects/mpsafetty/sys/dev/em/LICENSE#2 delete .. //depot/projects/mpsafetty/sys/dev/em/README#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_80003es2lan.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_80003es2lan.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_82540.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_82541.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_82541.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_82542.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_82543.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_82543.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_82571.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_82571.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_api.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_api.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_defines.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_hw.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_ich8lan.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_ich8lan.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_mac.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_mac.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_manage.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_manage.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_nvm.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_nvm.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_osdep.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_osdep.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_phy.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_phy.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/e1000_regs.h#2 delete .. //depot/projects/mpsafetty/sys/dev/em/if_em.c#2 delete .. //depot/projects/mpsafetty/sys/dev/em/if_em.h#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_82575.c#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_82575.h#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_api.c#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_api.h#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_defines.h#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_hw.h#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_mac.c#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_mac.h#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_manage.c#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_manage.h#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_nvm.c#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_nvm.h#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_osdep.c#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_osdep.h#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_phy.c#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_phy.h#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/e1000_regs.h#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/if_igb.c#2 delete .. //depot/projects/mpsafetty/sys/dev/igb/if_igb.h#2 delete .. //depot/projects/mpsafetty/sys/dev/usb/ehci_pci.c#3 integrate .. //depot/projects/mpsafetty/sys/dev/usb/ehcireg.h#2 integrate .. //depot/projects/mpsafetty/sys/i386/conf/GENERIC#4 integrate .. //depot/projects/mpsafetty/sys/kern/vfs_cache.c#2 integrate .. //depot/projects/mpsafetty/sys/modules/em/Makefile#2 integrate .. //depot/projects/mpsafetty/sys/modules/igb/Makefile#2 integrate .. //depot/projects/mpsafetty/sys/modules/netgraph/bluetooth/socket/Makefile#2 integrate .. //depot/projects/mpsafetty/sys/modules/nfslockd/Makefile#2 integrate .. //depot/projects/mpsafetty/sys/net/if.h#2 integrate .. //depot/projects/mpsafetty/sys/netgraph/bluetooth/include/ng_btsocket_sco.h#1 branch .. //depot/projects/mpsafetty/sys/netgraph/bluetooth/socket/ng_btsocket.c#2 integrate .. //depot/projects/mpsafetty/sys/netgraph/bluetooth/socket/ng_btsocket_hci_raw.c#2 integrate .. //depot/projects/mpsafetty/sys/netgraph/bluetooth/socket/ng_btsocket_l2cap.c#2 integrate .. //depot/projects/mpsafetty/sys/netgraph/bluetooth/socket/ng_btsocket_l2cap_raw.c#2 integrate .. //depot/projects/mpsafetty/sys/netgraph/bluetooth/socket/ng_btsocket_rfcomm.c#2 integrate .. //depot/projects/mpsafetty/sys/netgraph/bluetooth/socket/ng_btsocket_sco.c#1 branch .. //depot/projects/mpsafetty/sys/netinet/sctp.h#2 integrate .. //depot/projects/mpsafetty/sys/netinet/sctp_output.c#3 integrate .. //depot/projects/mpsafetty/sys/netinet/sctp_pcb.c#3 integrate .. //depot/projects/mpsafetty/sys/netinet/sctp_pcb.h#3 integrate .. //depot/projects/mpsafetty/sys/netinet/sctp_usrreq.c#3 integrate .. //depot/projects/mpsafetty/sys/netinet/sctp_var.h#3 integrate .. //depot/projects/mpsafetty/sys/netinet/sctputil.c#4 integrate .. //depot/projects/mpsafetty/sys/netinet/tcp_input.c#2 integrate .. //depot/projects/mpsafetty/sys/netinet/tcp_output.c#3 integrate .. //depot/projects/mpsafetty/sys/netinet/tcp_syncache.c#3 integrate .. //depot/projects/mpsafetty/sys/netinet/tcp_usrreq.c#2 integrate .. //depot/projects/mpsafetty/sys/netinet/tcp_var.h#2 integrate .. //depot/projects/mpsafetty/sys/security/audit/audit.c#3 integrate .. //depot/projects/mpsafetty/sys/security/audit/audit.h#3 integrate .. //depot/projects/mpsafetty/sys/security/audit/audit_arg.c#3 integrate .. //depot/projects/mpsafetty/sys/security/audit/audit_bsm_klib.c#4 integrate .. //depot/projects/mpsafetty/sys/security/audit/audit_bsm_token.c#3 integrate .. //depot/projects/mpsafetty/sys/security/audit/audit_pipe.c#2 integrate .. //depot/projects/mpsafetty/sys/security/audit/audit_private.h#3 integrate .. //depot/projects/mpsafetty/sys/security/audit/audit_syscalls.c#3 integrate .. //depot/projects/mpsafetty/sys/security/audit/audit_worker.c#3 integrate .. //depot/projects/mpsafetty/sys/security/mac_bsdextended/mac_bsdextended.c#2 integrate .. //depot/projects/mpsafetty/sys/sys/sockbuf.h#2 integrate .. //depot/projects/mpsafetty/sys/sys/socketvar.h#3 integrate .. //depot/projects/mpsafetty/sys/sys/sockio.h#2 integrate .. //depot/projects/mpsafetty/sys/sys/vnode.h#2 integrate .. //depot/projects/mpsafetty/sys/ufs/ufs/ufs_lookup.c#2 integrate .. //depot/projects/mpsafetty/sys/vm/swap_pager.c#3 integrate .. //depot/projects/mpsafetty/sys/vm/vm_object.c#2 integrate .. //depot/projects/mpsafetty/sys/vm/vnode_pager.c#3 integrate .. //depot/projects/mpsafetty/tools/regression/bin/sh/errors/redirection-error2.2#1 branch .. //depot/projects/mpsafetty/tools/regression/lib/msun/Makefile#2 integrate .. //depot/projects/mpsafetty/tools/regression/lib/msun/test-invtrig.c#1 branch .. //depot/projects/mpsafetty/tools/regression/lib/msun/test-invtrig.t#1 branch .. //depot/projects/mpsafetty/tools/tools/nanobsd/nanobsd.sh#2 integrate .. //depot/projects/mpsafetty/usr.bin/make/main.c#2 integrate .. //depot/projects/mpsafetty/usr.bin/make/make.1#2 integrate .. //depot/projects/mpsafetty/usr.bin/truss/syscall.h#2 integrate .. //depot/projects/mpsafetty/usr.bin/truss/syscalls.c#2 integrate .. //depot/projects/mpsafetty/usr.sbin/adduser/rmuser.sh#2 integrate Differences ... ==== //depot/projects/mpsafetty/bin/sh/eval.c#2 (text+ko) ==== @@ -36,7 +36,7 @@ #endif #endif /* not lint */ #include <sys/cdefs.h> -__FBSDID("$FreeBSD: src/bin/sh/eval.c,v 1.54 2007/10/04 16:14:48 stefanf Exp $"); +__FBSDID("$FreeBSD: src/bin/sh/eval.c,v 1.55 2008/07/30 21:07:04 stefanf Exp $"); #include <paths.h> #include <signal.h> @@ -437,7 +437,7 @@ case NFROMFD: case NTOFD: if (redir->ndup.vname) { - expandarg(redir->ndup.vname, &fn, EXP_FULL | EXP_TILDE); + expandarg(redir->ndup.vname, &fn, EXP_TILDE | EXP_REDIR); fixredir(redir, fn.list->text, 1); } break; ==== //depot/projects/mpsafetty/crypto/openssh/ChangeLog#2 (text+ko) ==== @@ -1,3 +1,2108 @@ +20080721 + - (djm) OpenBSD CVS Sync + - jmc@cvs.openbsd.org 2008/07/18 22:51:01 + [sftp-server.8] + no need for .Pp before or after .Sh; + - djm@cvs.openbsd.org 2008/07/21 08:19:07 + [version.h] + openssh-5.1 + - (djm) [README contrib/caldera/openssh.spec contrib/redhat/openssh.spec] + [contrib/suse/openssh.spec] Update version number in README and RPM specs + - (djm) Release OpenSSH-5.1 + +20080717 + - (djm) OpenBSD CVS Sync + - djm@cvs.openbsd.org 2008/07/17 08:48:00 + [sshconnect2.c] + strnvis preauth banner; pointed out by mpf@ ok markus@ + - djm@cvs.openbsd.org 2008/07/17 08:51:07 + [auth2-hostbased.c] + strip trailing '.' from hostname when HostbasedUsesNameFromPacketOnly=yes + report and patch from res AT qoxp.net (bz#1200); ok markus@ + - (dtucker) [openbsd-compat/bsd-cygwin_util.c] Remove long-unneeded compat + code, replace with equivalent cygwin library call. Patch from vinschen + at redhat.com, ok djm@. + - (djm) [sshconnect2.c] vis.h isn't available everywhere + +20080716 + - OpenBSD CVS Sync + - djm@cvs.openbsd.org 2008/07/15 02:23:14 + [sftp.1] + number of pipelined requests is now 64; + prodded by Iain.Morgan AT nasa.gov + - djm@cvs.openbsd.org 2008/07/16 11:51:14 + [clientloop.c] + rename variable first_gc -> last_gc (since it is actually the last + in the list). + - djm@cvs.openbsd.org 2008/07/16 11:52:19 + [channels.c] + this loop index should be automatic, not static + +20080714 + - (djm) OpenBSD CVS Sync + - sthen@cvs.openbsd.org 2008/07/13 21:22:52 + [ssh-keygen.c] + Change "ssh-keygen -F [host] -l" to not display random art unless + -v is also specified, making it consistent with the manual and other + uses of -l. + ok grunk@ + - djm@cvs.openbsd.org 2008/07/13 22:13:07 + [channels.c] + use struct sockaddr_storage instead of struct sockaddr for accept(2) + address argument. from visibilis AT yahoo.com in bz#1485; ok markus@ + - djm@cvs.openbsd.org 2008/07/13 22:16:03 + [sftp.c] + increase number of piplelined requests so they properly fill the + (recently increased) channel window. prompted by rapier AT psc.edu; + ok markus@ + - djm@cvs.openbsd.org 2008/07/14 01:55:56 + [sftp-server.8] + mention requirement for /dev/log inside chroot when using sftp-server + with ChrootDirectory + - (djm) [openbsd-compat/bindresvport.c] Rename variables s/sin/in/ to + avoid clash with sin(3) function; reported by + cristian.ionescu-idbohrn AT axis.com + - (djm) [openbsd-compat/rresvport.c] Add unistd.h for missing close() + prototype; reported by cristian.ionescu-idbohrn AT axis.com + - (djm) [umac.c] Rename variable s/buffer_ptr/bufp/ to avoid clash; + reported by cristian.ionescu-idbohrn AT axis.com + - (djm) [contrib/cygwin/Makefile contrib/cygwin/ssh-host-config] + [contrib/cygwin/ssh-user-config contrib/cygwin/sshd-inetd] + Revamped and simplified Cygwin ssh-host-config script that uses + unified csih configuration tool. Requires recent Cygwin. + Patch from vinschen AT redhat.com + +20080712 + - (djm) OpenBSD CVS Sync + - djm@cvs.openbsd.org 2008/07/12 04:52:50 + [channels.c] + unbreak; move clearing of cctx struct to before first use + reported by dkrause@ + - djm@cvs.openbsd.org 2008/07/12 05:33:41 + [scp.1] + better description for -i flag: + s/RSA authentication/public key authentication/ + - (djm) [openbsd-compat/fake-rfc2553.c openbsd-compat/fake-rfc2553.h] + return EAI_FAMILY when trying to lookup unsupported address family; + from vinschen AT redhat.com + +20080711 + - (djm) OpenBSD CVS Sync + - stevesk@cvs.openbsd.org 2008/07/07 00:31:41 + [ttymodes.c] + we don't need arg after the debug3() was removed. from lint. + ok djm@ + - stevesk@cvs.openbsd.org 2008/07/07 23:32:51 + [key.c] + /*NOTREACHED*/ for lint warning: + warning: function key_equal falls off bottom without returning value + ok djm@ + - markus@cvs.openbsd.org 2008/07/10 18:05:58 + [channels.c] + missing bzero; from mickey; ok djm@ + - markus@cvs.openbsd.org 2008/07/10 18:08:11 + [clientloop.c monitor.c monitor_wrap.c packet.c packet.h sshd.c] + sync v1 and v2 traffic accounting; add it to sshd, too; + ok djm@, dtucker@ + +20080709 + - (djm) [Makefile.in] Print "all tests passed" when all regress tests pass + - (djm) [auth1.c] Fix format string vulnerability in protocol 1 PAM + account check failure path. The vulnerable format buffer is supplied + from PAM and should not contain attacker-supplied data. + - (djm) [auth.c] Missing unistd.h for close() + - (djm) [configure.ac] Add -Wformat-security to CFLAGS for gcc 3.x and 4.x + +20080705 + - (djm) [auth.c] Fixed test for locked account on HP/UX with shadowed + passwords disabled. bz#1083 report & patch from senthilkumar_sen AT + hotpop.com, w/ dtucker@ + - (djm) [atomicio.c configure.ac] Disable poll() fallback in atomiciov for + Tru64. readv doesn't seem to be a comparable object there. + bz#1386, patch from dtucker@ ok me + - (djm) [Makefile.in] Pass though pass to conch for interop tests + - (djm) [configure.ac] unbreak: remove extra closing brace + - (djm) OpenBSD CVS Sync + - djm@cvs.openbsd.org 2008/07/04 23:08:25 + [packet.c] + handle EINTR in packet_write_poll()l ok dtucker@ + - djm@cvs.openbsd.org 2008/07/04 23:30:16 + [auth1.c auth2.c] + Make protocol 1 MaxAuthTries logic match protocol 2's. + Do not treat the first protocol 2 authentication attempt as + a failure IFF it is for method "none". + Makes MaxAuthTries' user-visible behaviour identical for + protocol 1 vs 2. + ok dtucker@ + - djm@cvs.openbsd.org 2008/07/05 05:16:01 + [PROTOCOL] + grammar + +20080704 + - (dtucker) OpenBSD CVS Sync + - djm@cvs.openbsd.org 2008/07/02 13:30:34 + [auth2.c] + really really remove the freebie "none" auth try for protocol 2 + - djm@cvs.openbsd.org 2008/07/02 13:47:39 + [ssh.1 ssh.c] + When forking after authentication ("ssh -f") with ExitOnForwardFailure + enabled, delay the fork until after replies for any -R forwards have + been seen. Allows for robust detection of -R forward failure when + using -f (similar to bz#92); ok dtucker@ + - otto@cvs.openbsd.org 2008/07/03 21:46:58 + [auth2-pubkey.c] + avoid nasty double free; ok dtucker@ djm@ + - djm@cvs.openbsd.org 2008/07/04 03:44:59 + [servconf.c groupaccess.h groupaccess.c] + support negation of groups in "Match group" block (bz#1315); ok dtucker@ + - dtucker@cvs.openbsd.org 2008/07/04 03:47:02 + [monitor.c] + Make debug a little clearer. ok djm@ + - djm@cvs.openbsd.org 2008/06/30 08:07:34 + [regress/key-options.sh] + shell portability: use "=" instead of "==" in test(1) expressions, + double-quote string with backslash escaped / + - djm@cvs.openbsd.org 2008/06/30 10:31:11 + [regress/{putty-transfer,putty-kex,putty-ciphers}.sh] + remove "set -e" left over from debugging + - djm@cvs.openbsd.org 2008/06/30 10:43:03 + [regress/conch-ciphers.sh] + explicitly disable conch options that could interfere with the test + - (dtucker) [sftp-server.c] Bug #1447: fall back to racy rename if link + returns EXDEV. Patch from Mike Garrison, ok djm@ + - (djm) [atomicio.c channels.c clientloop.c defines.h includes.h] + [packet.c scp.c serverloop.c sftp-client.c ssh-agent.c ssh-keyscan.c] + [sshd.c] Explicitly handle EWOULDBLOCK wherever we handle EAGAIN, on + some platforms (HP nonstop) it is a distinct errno; + bz#1467 reported by sconeu AT yahoo.com; ok dtucker@ + +20080702 + - (dtucker) OpenBSD CVS Sync + - djm@cvs.openbsd.org 2008/06/30 08:05:59 + [PROTOCOL.agent] + typo: s/constraint_date/constraint_data/ + - djm@cvs.openbsd.org 2008/06/30 12:15:39 + [serverloop.c] + only pass channel requests on session channels through to the session + channel handler, avoiding spurious log messages; ok! markus@ + - djm@cvs.openbsd.org 2008/06/30 12:16:02 + [nchan.c] + only send eow@openssh.com notifications for session channels; ok! markus@ + - djm@cvs.openbsd.org 2008/06/30 12:18:34 + [PROTOCOL] + clarify that eow@openssh.com is only sent on session channels + - dtucker@cvs.openbsd.org 2008/07/01 07:20:52 + [sshconnect.c] + Check ExitOnForwardFailure if forwardings are disabled due to a failed + host key check. ok djm@ + - dtucker@cvs.openbsd.org 2008/07/01 07:24:22 + [sshconnect.c sshd.c] + Send CR LF during protocol banner exchanges, but only for Protocol 2 only, + in order to comply with RFC 4253. bz #1443, ok djm@ + - stevesk@cvs.openbsd.org 2008/07/01 23:12:47 + [PROTOCOL.agent] + fix some typos; ok djm@ + - djm@cvs.openbsd.org 2008/07/02 02:24:18 + [sshd_config sshd_config.5 sshd.8 servconf.c] + increase default size of ssh protocol 1 ephemeral key from 768 to 1024 + bits; prodded by & ok dtucker@ ok deraadt@ + - dtucker@cvs.openbsd.org 2008/07/02 12:03:51 + [auth-rsa.c auth.c auth2-pubkey.c auth.h] + Merge duplicate host key file checks, based in part on a patch from Rob + Holland via bz #1348 . Also checks for non-regular files during protocol + 1 RSA auth. ok djm@ + - djm@cvs.openbsd.org 2008/07/02 12:36:39 + [auth2-none.c auth2.c] + Make protocol 2 MaxAuthTries behaviour a little more sensible: + Check whether client has exceeded MaxAuthTries before running + an authentication method and skip it if they have, previously it + would always allow one try (for "none" auth). + Preincrement failure count before post-auth test - previously this + checked and postincremented, also to allow one "none" try. + Together, these two changes always count the "none" auth method + which could be skipped by a malicious client (e.g. an SSH worm) + to get an extra attempt at a real auth method. They also make + MaxAuthTries=0 a useful way to block users entirely (esp. in a + sshd_config Match block). + Also, move sending of any preauth banner from "none" auth method + to the first call to input_userauth_request(), so worms that skip + the "none" method get to see it too. + +20080630 + - (djm) OpenBSD CVS Sync + - dtucker@cvs.openbsd.org 2008/06/10 23:13:43 + [regress/Makefile regress/key-options.sh] + Add regress test for key options. ok djm@ + - dtucker@cvs.openbsd.org 2008/06/11 23:11:40 + [regress/Makefile] + Don't run cipher-speed test by default; mistakenly enabled by me + - djm@cvs.openbsd.org 2008/06/28 13:57:25 + [regress/Makefile regress/test-exec.sh regress/conch-ciphers.sh] + very basic regress test against Twisted Conch in "make interop" + target (conch is available in ports/devel/py-twisted/conch); + ok markus@ + - (djm) [regress/Makefile] search for conch by path, like we do putty + +20080629 + - (djm) OpenBSD CVS Sync + - martynas@cvs.openbsd.org 2008/06/21 07:46:46 + [sftp.c] + use optopt to get invalid flag, instead of return value of getopt, + which is always '?'; ok djm@ + - otto@cvs.openbsd.org 2008/06/25 11:13:43 + [key.c] + add key length to visual fingerprint; zap magical constants; + ok grunk@ djm@ + - djm@cvs.openbsd.org 2008/06/26 06:10:09 + [sftp-client.c sftp-server.c] + allow the sftp chmod(2)-equivalent operation to set set[ug]id/sticky + bits. Note that this only affects explicit setting of modes (e.g. via + sftp(1)'s chmod command) and not file transfers. (bz#1310) + ok deraadt@ at c2k8 + - djm@cvs.openbsd.org 2008/06/26 09:19:40 + [dh.c dh.h moduli.c] + when loading moduli from /etc/moduli in sshd(8), check that they + are of the expected "safe prime" structure and have had + appropriate primality tests performed; + feedback and ok dtucker@ + - grunk@cvs.openbsd.org 2008/06/26 11:46:31 + [readconf.c readconf.h ssh.1 ssh_config.5 sshconnect.c] + Move SSH Fingerprint Visualization away from sharing the config option + CheckHostIP to an own config option named VisualHostKey. + While there, fix the behaviour that ssh would draw a random art picture + on every newly seen host even when the option was not enabled. + prodded by deraadt@, discussions, + help and ok markus@ djm@ dtucker@ + - jmc@cvs.openbsd.org 2008/06/26 21:11:46 + [ssh.1] + add VisualHostKey to the list of options listed in -o; + - djm@cvs.openbsd.org 2008/06/28 07:25:07 + [PROTOCOL] + spelling fixes + - djm@cvs.openbsd.org 2008/06/28 13:58:23 + [ssh-agent.c] + refuse to add a key that has unknown constraints specified; + ok markus + - djm@cvs.openbsd.org 2008/06/28 14:05:15 + [ssh-agent.c] + reset global compat flag after processing a protocol 2 signature + request with the legacy DSA encoding flag set; ok markus + - djm@cvs.openbsd.org 2008/06/28 14:08:30 + [PROTOCOL PROTOCOL.agent] + document the protocol used by ssh-agent; "looks ok" markus@ + +20080628 + - (djm) [RFC.nroff contrib/cygwin/Makefile contrib/suse/openssh.spec] + RFC.nroff lacks a license, remove it (it is long gone in OpenBSD). + +20080626 + - (djm) [Makefile.in moduli.5] Include moduli(5) manpage from OpenBSD. + (bz#1372) + - (djm) [ contrib/caldera/openssh.spec contrib/redhat/openssh.spec] + [contrib/suse/openssh.spec] Include moduli.5 in RPM spec files. + +20080616 + - (dtucker) OpenBSD CVS Sync + - dtucker@cvs.openbsd.org 2008/06/16 13:22:53 + [session.c channels.c] + Rename the isatty argument to is_tty so we don't shadow + isatty(3). ok markus@ + - (dtucker) [channels.c] isatty -> is_tty here too. + +20080615 + - (dtucker) [configure.ac] Enable -fno-builtin-memset when using gcc. + - OpenBSD CVS Sync + - dtucker@cvs.openbsd.org 2008/06/14 15:49:48 + [sshd.c] + wrap long line at 80 chars + - dtucker@cvs.openbsd.org 2008/06/14 17:07:11 + [sshd.c] + ensure default umask disallows at least group and world write; ok djm@ + - djm@cvs.openbsd.org 2008/06/14 18:33:43 + [session.c] + suppress the warning message from chdir(homedir) failures + when chrooted (bz#1461); ok dtucker + - dtucker@cvs.openbsd.org 2008/06/14 19:42:10 + [scp.1] + Mention that scp follows symlinks during -r. bz #1466, + from nectar at apple + - dtucker@cvs.openbsd.org 2008/06/15 16:55:38 + [sshd_config.5] + MaxSessions is allowed in a Match block too + - dtucker@cvs.openbsd.org 2008/06/15 16:58:40 + [servconf.c sshd_config.5] + Allow MaxAuthTries within a Match block. ok djm@ + - djm@cvs.openbsd.org 2008/06/15 20:06:26 + [channels.c channels.h session.c] + don't call isatty() on a pty master, instead pass a flag down to + channel_set_fds() indicating that te fds refer to a tty. Fixes a + hang on exit on Solaris (bz#1463) in portable but is actually + a generic bug; ok dtucker deraadt markus + +20080614 + - (djm) [openbsd-compat/sigact.c] Avoid NULL derefs in ancient sigaction + replacement code; patch from ighighi AT gmail.com in bz#1240; + ok dtucker + +20080613 + - (dtucker) OpenBSD CVS Sync + - deraadt@cvs.openbsd.org 2008/06/13 09:44:36 + [packet.c] + compile on older gcc; no decl after code + - dtucker@cvs.openbsd.org 2008/06/13 13:56:59 + [monitor.c] + Clear key options in the monitor on failed authentication, prevents + applying additional restrictions to non-pubkey authentications in + the case where pubkey fails but another method subsequently succeeds. + bz #1472, found by Colin Watson, ok markus@ djm@ + - dtucker@cvs.openbsd.org 2008/06/13 14:18:51 + [auth2-pubkey.c auth-rhosts.c] + Include unistd.h for close(), prevents warnings in -portable + - dtucker@cvs.openbsd.org 2008/06/13 17:21:20 + [mux.c] + Friendlier error messages for mux fallback. ok djm@ + - dtucker@cvs.openbsd.org 2008/06/13 18:55:22 + [scp.c] + Prevent -Wsign-compare warnings on LP64 systems. bz #1192, ok deraadt@ + - grunk@cvs.openbsd.org 2008/06/13 20:13:26 + [ssh.1] + Explain the use of SSH fpr visualization using random art, and cite the + original scientific paper inspiring that technique. + Much help with English and nroff by jmc@, thanks. + - (dtucker) [configure.ac] Bug #1276: avoid linking against libgssapi, which + despite its name doesn't seem to implement all of GSSAPI. Patch from + Jan Engelhardt, sanity checked by Simon Wilkinson. + +20080612 + - (dtucker) OpenBSD CVS Sync + - jmc@cvs.openbsd.org 2008/06/11 07:30:37 + [sshd.8] + kill trailing whitespace; + - grunk@cvs.openbsd.org 2008/06/11 21:01:35 + [ssh_config.5 key.h readconf.c readconf.h ssh-keygen.1 ssh-keygen.c key.c + sshconnect.c] + Introduce SSH Fingerprint ASCII Visualization, a technique inspired by the + graphical hash visualization schemes known as "random art", and by + Dan Kaminsky's musings on the subject during a BlackOp talk at the + 23C3 in Berlin. + Scientific publication (original paper): + "Hash Visualization: a New Technique to improve Real-World Security", + Perrig A. and Song D., 1999, International Workshop on Cryptographic + Techniques and E-Commerce (CrypTEC '99) + http://sparrow.ece.cmu.edu/~adrian/projects/validation/validation.pdf + The algorithm used here is a worm crawling over a discrete plane, + leaving a trace (augmenting the field) everywhere it goes. + Movement is taken from dgst_raw 2bit-wise. Bumping into walls + makes the respective movement vector be ignored for this turn, + thus switching to the other color of the chessboard. + Graphs are not unambiguous for now, because circles in graphs can be + walked in either direction. + discussions with several people, + help, corrections and ok markus@ djm@ + - grunk@cvs.openbsd.org 2008/06/11 21:38:25 + [ssh-keygen.c] + ssh-keygen -lv -f /etc/ssh/ssh_host_rsa_key.pub + would not display you the random art as intended, spotted by canacar@ + - grunk@cvs.openbsd.org 2008/06/11 22:20:46 + [ssh-keygen.c ssh-keygen.1] + ssh-keygen would write fingerprints to STDOUT, and random art to STDERR, + that is not how it was envisioned. + Also correct manpage saying that -v is needed along with -l for it to work. + spotted by naddy@ + - otto@cvs.openbsd.org 2008/06/11 23:02:22 + [key.c] + simpler way of computing the augmentations; ok grunk@ + - grunk@cvs.openbsd.org 2008/06/11 23:03:56 + [ssh_config.5] + CheckHostIP set to ``fingerprint'' will display both hex and random art + spotted by naddy@ + - grunk@cvs.openbsd.org 2008/06/11 23:51:57 + [key.c] + #define statements that are not atoms need braces around them, else they + will cause trouble in some cases. + Also do a computation of -1 once, and not in a loop several times. + spotted by otto@ + - dtucker@cvs.openbsd.org 2008/06/12 00:03:49 + [dns.c canohost.c sshconnect.c] + Do not pass "0" strings as ports to getaddrinfo because the lookups + can slow things down and we never use the service info anyway. bz + #859, patch from YOSHIFUJI Hideaki and John Devitofranceschi. ok + deraadt@ djm@ + djm belives that the reason for the "0" strings is to ensure that + it's not possible to call getaddrinfo with both host and port being + NULL. In the case of canohost.c host is a local array. In the + case of sshconnect.c, it's checked for null immediately before use. + In dns.c it ultimately comes from ssh.c:main() and is guaranteed to + be non-null but it's not obvious, so I added a warning message in + case it is ever passed a null. + - grunk@cvs.openbsd.org 2008/06/12 00:13:55 + [sshconnect.c] + Make ssh print the random art also when ssh'ing to a host using IP only. + spotted by naddy@, ok and help djm@ dtucker@ + - otto@cvs.openbsd.org 2008/06/12 00:13:13 + [key.c] + use an odd number of rows and columns and a separate start marker, looks + better; ok grunk@ + - djm@cvs.openbsd.org 2008/06/12 03:40:52 + [clientloop.h mux.c channels.c clientloop.c channels.h] + Enable ~ escapes for multiplex slave sessions; give each channel + its own escape state and hook the escape filters up to muxed + channels. bz #1331 + Mux slaves do not currently support the ~^Z and ~& escapes. + NB. this change cranks the mux protocol version, so a new ssh + mux client will not be able to connect to a running old ssh + mux master. + ok dtucker@ + - djm@cvs.openbsd.org 2008/06/12 04:06:00 + [clientloop.h ssh.c clientloop.c] + maintain an ordered queue of outstanding global requests that we + expect replies to, similar to the per-channel confirmation queue. + Use this queue to verify success or failure for remote forward + establishment in a race free way. + ok dtucker@ + - djm@cvs.openbsd.org 2008/06/12 04:17:47 + [clientloop.c] + thall shalt not code past the eightieth column + - djm@cvs.openbsd.org 2008/06/12 04:24:06 + [ssh.c] + thal shalt not code past the eightieth column + - djm@cvs.openbsd.org 2008/06/12 05:15:41 + [PROTOCOL] + document tun@openssh.com forwarding method + - djm@cvs.openbsd.org 2008/06/12 05:32:30 + [mux.c] + some more TODO for me + - grunk@cvs.openbsd.org 2008/06/12 05:42:46 + [key.c] + supply the key type (rsa1, rsa, dsa) as a caption in the frame of the + random art. while there, stress the fact that the field base should at + least be 8 characters for the pictures to make sense. + comment and ok djm@ + - grunk@cvs.openbsd.org 2008/06/12 06:32:59 + [key.c] + We already mark the start of the worm, now also mark the end of the worm + in our random art drawings. + ok djm@ + - djm@cvs.openbsd.org 2008/06/12 15:19:17 + [clientloop.h channels.h clientloop.c channels.c mux.c] + The multiplexing escape char handler commit last night introduced a + small memory leak per session; plug it. + - dtucker@cvs.openbsd.org 2008/06/12 16:35:31 + [ssh_config.5 ssh.c] + keyword expansion for localcommand. ok djm@ + - jmc@cvs.openbsd.org 2008/06/12 19:10:09 + [ssh_config.5 ssh-keygen.1] + tweak the ascii art text; ok grunk + - dtucker@cvs.openbsd.org 2008/06/12 20:38:28 + [sshd.c sshconnect.c packet.h misc.c misc.h packet.c] + Make keepalive timeouts apply while waiting for a packet, particularly + during key renegotiation (bz #1363). With djm and Matt Day, ok djm@ + - djm@cvs.openbsd.org 2008/06/12 20:47:04 + [sftp-client.c] + print extension revisions for extensions that we understand + - djm@cvs.openbsd.org 2008/06/12 21:06:25 + [clientloop.c] + I was coalescing expected global request confirmation replies at + the wrong end of the queue - fix; prompted by markus@ + - grunk@cvs.openbsd.org 2008/06/12 21:14:46 + [ssh-keygen.c] + make ssh-keygen -lf show the key type just as ssh-add -l would do it + ok djm@ markus@ + - grunk@cvs.openbsd.org 2008/06/12 22:03:36 + [key.c] + add my copyright, ok djm@ + - ian@cvs.openbsd.org 2008/06/12 23:24:58 + [sshconnect.c] + tweak wording in message, ok deraadt@ jmc@ + - dtucker@cvs.openbsd.org 2008/06/13 00:12:02 + [sftp.h log.h] + replace __dead with __attribute__((noreturn)), makes things + a little easier to port. Also, add it to sigdie(). ok djm@ + - djm@cvs.openbsd.org 2008/06/13 00:16:49 + [mux.c] + fall back to creating a new TCP connection on most multiplexing errors + (socket connect fail, invalid version, refused permittion, corrupted + messages, etc.); bz #1329 ok dtucker@ + - dtucker@cvs.openbsd.org 2008/06/13 00:47:53 + [mux.c] + upcast size_t to u_long to match format arg; ok djm@ + - dtucker@cvs.openbsd.org 2008/06/13 00:51:47 + [mac.c] + upcast another size_t to u_long to match format + - dtucker@cvs.openbsd.org 2008/06/13 01:38:23 + [misc.c] + upcast uid to long with matching %ld, prevents warnings in portable + - djm@cvs.openbsd.org 2008/06/13 04:40:22 + [auth2-pubkey.c auth-rhosts.c] + refuse to read ~/.shosts or ~/.ssh/authorized_keys that are not + regular files; report from Solar Designer via Colin Watson in bz#1471 + ok dtucker@ deraadt + - (dtucker) [clientloop.c serverloop.c] channel_register_filter now + takes 2 more args. with djm@ + - (dtucker) [defines.h] Bug #1112: __dead is, well dead. Based on a patch + from Todd Vierling. + - (dtucker) [auth-sia.c] Bug #1241: support password expiry on Tru64 SIA + systems. Patch from R. Scott Bailey. + - (dtucker) [umac.c] STORE_UINT32_REVERSED and endian_convert are never used + on big endian machines, so ifdef them for little-endian only to prevent + unused function warnings on big-endians. + - (dtucker) [openbsd-compat/setenv.c] Make offsets size_t to prevent + compiler warnings on some platforms. Based on a discussion with otto@ + +20080611 + - (djm) [channels.c configure.ac] + Do not set SO_REUSEADDR on wildcard X11 listeners (X11UseLocalhost=no) + bz#1464; ok dtucker + +20080610 + - (dtucker) OpenBSD CVS Sync + - djm@cvs.openbsd.org 2008/06/10 03:57:27 + [servconf.c match.h sshd_config.5] + support CIDR address matching in sshd_config "Match address" blocks, with + full support for negation and fall-back to classic wildcard matching. + For example: + Match address 192.0.2.0/24,3ffe:ffff::/32,!10.* + PasswordAuthentication yes + addrmatch.c code mostly lifted from flowd's addr.c + feedback and ok dtucker@ + - djm@cvs.openbsd.org 2008/06/10 04:17:46 + [sshd_config.5] + better reference for pattern-list + - dtucker@cvs.openbsd.org 2008/06/10 04:50:25 + [sshd.c channels.h channels.c log.c servconf.c log.h servconf.h sshd.8] + Add extended test mode (-T) and connection parameters for test mode (-C). + -T causes sshd to write its effective configuration to stdout and exit. + -C causes any relevant Match rules to be applied before output. The + combination allows tesing of the parser and config files. ok deraadt djm + - jmc@cvs.openbsd.org 2008/06/10 07:12:00 + [sshd_config.5] + tweak previous; + - jmc@cvs.openbsd.org 2008/06/10 08:17:40 + [sshd.8 sshd.c] + - update usage() >>> TRUNCATED FOR MAIL (1000 lines) <<<
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200808010435.m714ZHGP014847>