Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package openssh for openSUSE:Factory checked in at 2026-10-02 23:02:38 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/openssh (Old) and /work/SRC/openSUSE:Factory/.openssh.new.1631729 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "openssh" Fri Oct 2 23:02:38 2026 rev:210 rq:1381978 version:10.5p1 Changes: -------- +++ only whitespace diff in changes, re-diffing --- /work/SRC/openSUSE:Factory/openssh/openssh.changes 2026-09-30 16:22:46.990675527 +0200 +++ /work/SRC/openSUSE:Factory/.openssh.new.1631729/openssh.changes 2026-10-02 23:03:15.397073962 +0200 @@ -1,0 +2,14 @@ +Wed Sep 30 21:45:12 UTC 2026 - Hans Petter Jansson <[email protected]> + +- Update openssh-8.4p1-ssh_config_d.patch with mentions of the + configuration drop-in directories (bsc#1259462). +- Add openssh-10.5p1-propagate-restrict-keyword.patch (bsc#1275079). + +------------------------------------------------------------------- +Tue Sep 29 07:23:16 UTC 2026 - Tomáš Chvátal <[email protected]> + +- Drop obsolete -fstack-protector from CFLAGS/CXXFLAGS (added 2006, + predates distro -fstack-protector-strong in optflags; the trailing + basic flag silently downgraded strong to basic). + +------------------------------------------------------------------- New: ---- openssh-10.5p1-propagate-restrict-keyword.patch ----------(New B)---------- New:/work/SRC/openSUSE:Factory/.openssh.new.1631729/openssh.changes- configuration drop-in directories (bsc#1259462). /work/SRC/openSUSE:Factory/.openssh.new.1631729/openssh.changes:- Add openssh-10.5p1-propagate-restrict-keyword.patch (bsc#1275079). /work/SRC/openSUSE:Factory/.openssh.new.1631729/openssh.changes- ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ openssh.spec ++++++ --- /var/tmp/diff_new_pack.YGro1b/_old 2026-10-02 23:03:17.940180402 +0200 +++ /var/tmp/diff_new_pack.YGro1b/_new 2026-10-02 23:03:17.942180486 +0200 @@ -178,6 +178,8 @@ Patch108: openssh-7.7p1-gssapi-new-unique.patch # PATCH-FIX-UPSTREAM openssh-10.5p1-sync-readpassphrase.patch mindrot#3995 [email protected] -- Sync readpassphrase(3) with OpenBSD libc: preserve SIG_IGN so ssh-add no longer spins without a controlling tty Patch109: openssh-10.5p1-sync-readpassphrase.patch +# PATCH-FIX-UPSTREAM openssh-10.5p1-propagate-restrict-keyword.patch bsc#1275079 -- Propagate the authorized_keys "restrict" flag +Patch110: openssh-10.5p1-propagate-restrict-keyword.patch # 200..300 -- Patches submitted to upstream # 1000..2000 -- Conditional patches %if %{with crypto_policies} @@ -389,8 +391,8 @@ %else PIEFLAGS="-fpie" %endif -CFLAGS="%{optflags} $PIEFLAGS -fstack-protector" -CXXFLAGS="%{optflags} $PIEFLAGS -fstack-protector" +CFLAGS="%{optflags} $PIEFLAGS" +CXXFLAGS="%{optflags} $PIEFLAGS" LDFLAGS="-pie -Wl,--as-needed" #CPPFLAGS="%%{optflags} -DUSE_INTERNAL_B64" export LDFLAGS CFLAGS CXXFLAGS CPPFLAGS ++++++ openssh-10.5p1-propagate-restrict-keyword.patch ++++++ >From 991f1f31dde2797416acaf4319dbebe764446c6f Mon Sep 17 00:00:00 2001 From: "[email protected]" <[email protected]> Date: Tue, 16 Sep 2026 00:33:44 +0000 Subject: [PATCH] upstream: Propagate authorized_keys "resrict" keyword The "restrict" keyword was not pervasively being applied to TunnelForwarding connections (which are administratively disabled by default). This is a separate problem to the one fixed in openssh-10.5 reported by several people; ok markus, deraadt OpenBSD-Commit-ID: 8c36c31dc2bdbc0c432d1056496b2f1ce93198d1 >From ded92bffa2e2f2db9b83245c5061812791bfa47f Mon Sep 17 00:00:00 2001 From: "[email protected]" <[email protected]> Date: Tue, 16 Sep 2026 04:51:28 +0000 Subject: [PATCH] upstream: correctly check sshauthopt->restricted merging OpenBSD-Regress-ID: e81e9267514338d6cf6bd2f83dcb722538af528e >From a30bafcbbd44dc4dc91916240c32ecabff899338 Mon Sep 17 00:00:00 2001 From: "[email protected]" <[email protected]> Date: Tue, 16 Sep 2026 04:56:12 +0000 Subject: [PATCH] upstream: simpler OpenBSD-Regress-ID: c7f30b865abd0b3e0e5514f861509c32e352a760 Index: openssh-10.5p1/auth-options.c =================================================================== --- openssh-10.5p1.orig/auth-options.c +++ openssh-10.5p1/auth-options.c @@ -604,6 +604,7 @@ sshauthopt_merge(const struct sshauthopt OPTFLAG_AND(no_require_user_presence); /* Restrictive flags are logical-OR (i.e. must be set in either) */ OPTFLAG_OR(require_verify); + OPTFLAG_OR(restricted); #undef OPTFLAG_AND /* Earliest expiry time should win */ Index: openssh-10.5p1/regress/unittests/authopt/tests.c =================================================================== --- openssh-10.5p1.orig/regress/unittests/authopt/tests.c +++ openssh-10.5p1/regress/unittests/authopt/tests.c @@ -418,13 +418,15 @@ test_merge(void) } while (0) /* Check a single case of merging of flag options */ -#define FLAG_CASE(keybase, label, keyname, keywords, mostly_off, var, val) \ +#define FLAG_CASE(keybase, label, keyname, keywords, mostly_off, \ + rflag, var, val) \ do { \ PREPARE(keybase " " label, keyname, keywords); \ expected = mostly_off ? \ sshauthopt_new() : default_authkey_opts(); \ - expected->var = val; \ ASSERT_PTR_NE(expected, NULL); \ + expected->restricted = rflag; \ + expected->var = val; \ CHECK_SUCCESS_AND_CLEANUP(); \ TEST_DONE(); \ } while (0) @@ -437,40 +439,40 @@ test_merge(void) #define FLAG_TEST(keybase, keyword, var) \ do { \ FLAG_CASE(keybase, "keys:default,yes cert:default,no", \ - "no_" keybase, keyword, 0, var, 0); \ + "no_" keybase, keyword, 0, 0, var, 0); \ FLAG_CASE(keybase,"keys:-*,yes cert:default,no", \ - "no_" keybase, "restrict," keyword, 1, var, 0); \ + "no_" keybase, "restrict," keyword, 1, 1, var, 0); \ FLAG_CASE(keybase, "keys:default,no cert:default,no", \ - "no_" keybase, "no-" keyword, 0, var, 0); \ + "no_" keybase, "no-" keyword, 0, 0, var, 0); \ FLAG_CASE(keybase, "keys:-*,no cert:default,no", \ - "no_" keybase, "restrict,no-" keyword, 1, var, 0); \ + "no_" keybase, "restrict,no-" keyword, 1, 1, var, 0); \ \ FLAG_CASE(keybase, "keys:default,yes cert:-*,yes", \ - "only_" keybase, keyword, 1, var, 1); \ + "only_" keybase, keyword, 1, 0, var, 1); \ FLAG_CASE(keybase,"keys:-*,yes cert:-*,yes", \ - "only_" keybase, "restrict," keyword, 1, var, 1); \ + "only_" keybase, "restrict," keyword, 1, 1, var, 1); \ FLAG_CASE(keybase, "keys:default,no cert:-*,yes", \ - "only_" keybase, "no-" keyword, 1, var, 0); \ + "only_" keybase, "no-" keyword, 1, 0, var, 0); \ FLAG_CASE(keybase, "keys:-*,no cert:-*,yes", \ - "only_" keybase, "restrict,no-" keyword, 1, var, 0); \ + "only_" keybase, "restrict,no-" keyword, 1, 1, var, 0); \ \ FLAG_CASE(keybase, "keys:default,yes cert:-*", \ - "no_permit", keyword, 1, var, 0); \ + "no_permit", keyword, 1, 0, var, 0); \ FLAG_CASE(keybase,"keys:-*,yes cert:-*", \ - "no_permit", "restrict," keyword, 1, var, 0); \ + "no_permit", "restrict," keyword, 1, 1, var, 0); \ FLAG_CASE(keybase, "keys:default,no cert:-*", \ - "no_permit", "no-" keyword, 1, var, 0); \ + "no_permit", "no-" keyword, 1, 0, var, 0); \ FLAG_CASE(keybase, "keys:-*,no cert:-*", \ - "no_permit", "restrict,no-" keyword, 1, var, 0); \ + "no_permit", "restrict,no-" keyword, 1, 1, var, 0); \ \ FLAG_CASE(keybase, "keys:default,yes cert:*", \ - "all_permit", keyword, 0, var, 1); \ + "all_permit", keyword, 0, 0, var, 1); \ FLAG_CASE(keybase,"keys:-*,yes cert:*", \ - "all_permit", "restrict," keyword, 1, var, 1); \ + "all_permit", "restrict," keyword, 1, 1, var, 1); \ FLAG_CASE(keybase, "keys:default,no cert:*", \ - "all_permit", "no-" keyword, 0, var, 0); \ + "all_permit", "no-" keyword, 0, 0, var, 0); \ FLAG_CASE(keybase, "keys:-*,no cert:*", \ - "all_permit", "restrict,no-" keyword, 1, var, 0); \ + "all_permit", "restrict,no-" keyword, 1, 1, var, 0); \ \ } while (0) FLAG_TEST("portfwd", "port-forwarding", permit_port_forwarding_flag); ++++++ openssh-8.4p1-ssh_config_d.patch ++++++ --- /var/tmp/diff_new_pack.YGro1b/_old 2026-10-02 23:03:18.362198066 +0200 +++ /var/tmp/diff_new_pack.YGro1b/_new 2026-10-02 23:03:18.372198484 +0200 @@ -38,4 +38,76 @@ #Port 22 #AddressFamily any +Index: openssh-8.9p1/sshd_config.5 +=================================================================== +--- openssh-8.9p1.orig/sshd_config.5 ++++ openssh-8.9p1/sshd_config.5 +@@ -56,6 +56,19 @@ Arguments may optionally be enclosed in + .Pq \&" + in order to represent arguments containing spaces. + .Pp ++Note that the default configuration file shipped with SUSE distributions ++begins by including the drop-in files ++.Pa /etc/ssh/sshd_config.d/*.conf . ++Because these files are included at the start of the configuration file, ++options set there will override those in ++.Pa /etc/ssh/sshd_config . ++The files are processed in lexical order. ++To change the system-wide configuration, add a ++.Pa *.conf ++file to ++.Pa /etc/ssh/sshd_config.d ++instead of editing the configuration file itself. ++.Pp + The possible + keywords and their meanings are as follows (note that + keywords are case-insensitive and arguments are case-sensitive): +@@ -2117,6 +2130,11 @@ Contains configuration data for + .Xr sshd 8 . + This file should be writable by root only, but it is recommended + (though not necessary) that it be world-readable. ++.It Pa /etc/ssh/sshd_config.d/*.conf ++Drop-in configuration files, included at the start of the default ++configuration file. ++Options set in these files override those in ++.Pa /etc/ssh/sshd_config . + .El + .Sh SEE ALSO + .Xr sftp-server 8 , +Index: openssh-8.9p1/ssh_config.5 +=================================================================== +--- openssh-8.9p1.orig/ssh_config.5 ++++ openssh-8.9p1/ssh_config.5 +@@ -90,6 +90,19 @@ and + .Fl o + option. + .Pp ++Note that the default system-wide configuration file shipped with SUSE ++distributions begins by including the drop-in files ++.Pa /etc/ssh/ssh_config.d/*.conf . ++Because these files are included at the start of the configuration file, ++options set there will override those in ++.Pa /etc/ssh/ssh_config . ++The files are processed in lexical order. ++To change the system-wide configuration, add a ++.Pa *.conf ++file to ++.Pa /etc/ssh/ssh_config.d ++instead of editing the configuration file itself. ++.Pp + The possible + keywords and their meanings are as follows (note that + keywords are case-insensitive and arguments are case-sensitive): +@@ -2379,6 +2392,11 @@ The format of this file is described abo + This file is used by the SSH client. + Because of the potential for abuse, this file must have strict permissions: + read/write for the user, and not writable by others. ++.It Pa /etc/ssh/ssh_config.d/*.conf ++Drop-in configuration files, included at the start of the default ++system-wide configuration file. ++Options set in these files override those in ++.Pa /etc/ssh/ssh_config . + .It Pa /etc/ssh/ssh_config + Systemwide configuration file. + This file provides defaults for those
