The branch main has been updated by bapt:

URL: 
https://cgit.FreeBSD.org/src/commit/?id=8d4d5f2e8e56e7b24b50706acbdc0c8c750c6fed

commit 8d4d5f2e8e56e7b24b50706acbdc0c8c750c6fed
Author:     Baptiste Daroussin <[email protected]>
AuthorDate: 2026-08-11 09:07:37 +0000
Commit:     Baptiste Daroussin <[email protected]>
CommitDate: 2026-08-11 11:16:02 +0000

    nuageinit: fix ssh_pwauth string handling
    
    Treat "no"/"unchanged" correctly instead of any non-nil value as yes.
---
 libexec/nuageinit/nuageinit          | 22 +++++++++++++++++++---
 libexec/nuageinit/tests/nuageinit.sh | 18 ++++++++++++++++++
 2 files changed, 37 insertions(+), 3 deletions(-)

diff --git a/libexec/nuageinit/nuageinit b/libexec/nuageinit/nuageinit
index d67ac6ce4229..536739c8a0bf 100755
--- a/libexec/nuageinit/nuageinit
+++ b/libexec/nuageinit/nuageinit
@@ -478,9 +478,25 @@ end
 local function ssh_pwauth(obj)
        if obj.ssh_pwauth == nil then return end
 
-       local value = "no"
-       if obj.ssh_pwauth then
-               value = "yes"
+       local value
+       if type(obj.ssh_pwauth) == "boolean" then
+               value = obj.ssh_pwauth and "yes" or "no"
+       elseif type(obj.ssh_pwauth) == "string" then
+               local s = obj.ssh_pwauth:lower()
+               if s == "yes" or s == "true" or s == "1" or s == "on" then
+                       value = "yes"
+               elseif s == "no" or s == "false" or s == "0" or s == "off" then
+                       value = "no"
+               elseif s == "unchanged" then
+                       return
+               else
+                       nuage.warn("ssh_pwauth: unrecognized value '" ..
+                           obj.ssh_pwauth .. "', leaving unchanged")
+                       return
+               end
+       else
+               nuage.warn("ssh_pwauth: invalid type " .. type(obj.ssh_pwauth))
+               return
        end
        nuage.update_sshd_config("PasswordAuthentication", value)
 end
diff --git a/libexec/nuageinit/tests/nuageinit.sh 
b/libexec/nuageinit/tests/nuageinit.sh
index 1fb5f7b4c967..a4b0def48a86 100644
--- a/libexec/nuageinit/tests/nuageinit.sh
+++ b/libexec/nuageinit/tests/nuageinit.sh
@@ -632,6 +632,24 @@ EOF
        printf "   PasswordAuthentication yes # Should change\n" > 
etc/ssh/sshd_config
        atf_check -o empty -e empty /usr/libexec/nuageinit 
"${PWD}"/media/nuageinit nocloud
        atf_check -o inline:"PasswordAuthentication no\n" cat 
etc/ssh/sshd_config
+
+       cat > media/nuageinit/user-data << 'EOF'
+#cloud-config
+ssh_pwauth: "no"
+EOF
+
+       printf "   PasswordAuthentication yes # Should change\n" > 
etc/ssh/sshd_config
+       atf_check -o empty -e empty /usr/libexec/nuageinit 
"${PWD}"/media/nuageinit nocloud
+       atf_check -o inline:"PasswordAuthentication no\n" cat 
etc/ssh/sshd_config
+
+       cat > media/nuageinit/user-data << 'EOF'
+#cloud-config
+ssh_pwauth: "unchanged"
+EOF
+
+       printf "   PasswordAuthentication yes # keep\n" > etc/ssh/sshd_config
+       atf_check -o empty -e empty /usr/libexec/nuageinit 
"${PWD}"/media/nuageinit nocloud
+       atf_check -o inline:"   PasswordAuthentication yes # keep\n" cat 
etc/ssh/sshd_config
 }
 
 nocloud_userdata_cloudconfig_chpasswd_head()

Reply via email to