From nobody Sat Jan 6 15:49:35 2024 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4T6lBS2M8Pz56b3s; Sat, 6 Jan 2024 15:49:36 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4T6lBS1Tt2z4V1q; Sat, 6 Jan 2024 15:49:36 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1704556176; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=IsFRveCgvVHwwuwGjNstjUf07bFv3U3vqAfaMEe+nCk=; b=NoLsu/NSrZqzoNXv9YXqjkGVvxRzBdl9cY7dbaxw6Uu8+JE5fjtmw5V6uZ0OkIi38MtiLB VtKxrCff8+J+6lt7z+Ti9dq7rBLAasMzfGaFCRsTIAZGs0a1+S/othAvLHr9VIuyutxkaW /DVvRQcAXY/p1g1YRbJmpizSanIFhNLVVt+x86tTO+d3vTA4KAsGWMlzcHJiXNL9dbc8yF /kmXQe7FnP5pTqED1VtCATHNPTMbpz8d8ytGkc7riYp66h8qePcqKW+L1tRAY0FWehf7di ZBs1QlfGAmOnjEBWE6yKlpOmFnnQloYqIkydGB2LOZx1Ha2KDnU0f7fsQArhrA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1704556176; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=IsFRveCgvVHwwuwGjNstjUf07bFv3U3vqAfaMEe+nCk=; b=fl4AgAC2CBdJrPmbWtPxnvCTLA7NRQJhPCh8/cTNdRXq57VT9HIuuLrz/ticAXsiwaiqyW 1/jlZ7EMqIKSjVLcKKOeayMMJDyMpA/syAXZJBEJ/BphYCtb5C6qYcWlQlNAJkW4Qrv+Lr zrUWVV+T38I+2HKrhvHp1GMgFMmcbnDNHbUzt6T2cQrTXCU6svQk3nHTz+A8gx40ENq/u3 AzVT2JTmxsNJKxRQKEo2+pwcxaMsDdmldBn8HLl0BUkb+yGcfbPaAXh0H7AnHx0cyOm0QR cxSPfFbcamIGC9elk22zP7a4PMj8nRMDuiG4MAH4tXgYtErwKLmYApZ1TR3bVg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1704556176; a=rsa-sha256; cv=none; b=U9ESxnhIWV0dpIbLvGzfh/5t+tQkm/FazEDl7ahONtigv956TPg0itIPIH/FxAdAvTJpnv wBk38B9djBFbocPQCV7Ft72yKH9Z5Smb3Sp6aFU69B2yHVDDNexhB5o0o/DBwQlJK9yDR2 +nuE4oz+j7EuUHszGJFykCciSm1mlZiyC4CvZNYZbF80iRkrMq5jD8BGmgH2w+bZNnuzRH v3oaQkXzBREckgU0JP0O0FyWH3ZTtqG6jGfJkgap09OxXPxZdE0VkMxMMrVS32ckjTbUrd LT3s9C5hUquzRhmpQViuluC1AaEvftsmm7+uBNwS4qvPVp6SHpNhJpO98e8fJQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4T6lBS0JCBzn7q; Sat, 6 Jan 2024 15:49:36 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 406FnZAk094176; Sat, 6 Jan 2024 15:49:35 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 406FnZcu094173; Sat, 6 Jan 2024 15:49:35 GMT (envelope-from git) Date: Sat, 6 Jan 2024 15:49:35 GMT Message-Id: <202401061549.406FnZcu094173@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Bernard Spil Subject: git: d820fcf123b4 - main - security/openssh-portable: Fix blacklistd patch List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: brnrd X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: d820fcf123b40037884c06a94a42275934587a8f Auto-Submitted: auto-generated The branch main has been updated by brnrd: URL: https://cgit.FreeBSD.org/ports/commit/?id=d820fcf123b40037884c06a94a42275934587a8f commit d820fcf123b40037884c06a94a42275934587a8f Author: Bernard Spil AuthorDate: 2024-01-06 15:49:12 +0000 Commit: Bernard Spil CommitDate: 2024-01-06 15:49:12 +0000 security/openssh-portable: Fix blacklistd patch --- security/openssh-portable/files/extra-patch-blacklistd | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/security/openssh-portable/files/extra-patch-blacklistd b/security/openssh-portable/files/extra-patch-blacklistd index 7bb88b2961fe..5d23bf869f7a 100644 --- a/security/openssh-portable/files/extra-patch-blacklistd +++ b/security/openssh-portable/files/extra-patch-blacklistd @@ -277,9 +277,9 @@ --- auth2.c.orig 2020-11-16 17:10:36.772062000 -0800 +++ auth2.c 2020-11-16 17:12:04.852943000 -0800 @@ -58,6 +58,7 @@ - #endif #include "monitor_wrap.h" #include "digest.h" + #include "kex.h" +#include "blacklist_client.h" /* import */ @@ -317,7 +317,7 @@ @@ -1882,6 +1883,7 @@ sshpkt_vfatal(struct ssh *ssh, int r, const char *fmt, case SSH_ERR_NO_KEX_ALG_MATCH: case SSH_ERR_NO_HOSTKEY_ALG_MATCH: - if (ssh && ssh->kex && ssh->kex->failed_choice) { + if (ssh->kex && ssh->kex->failed_choice) { + BLACKLIST_NOTIFY(BLACKLIST_AUTH_FAIL, ssh, "ssh"); ssh_packet_clear_keys(ssh); errno = oerrno; @@ -372,12 +372,12 @@ #Compression delayed #ClientAliveInterval 0 #ClientAliveCountMax 3 ---- sshd_config.5.orig 2020-11-16 16:57:58.533307000 -0800 -+++ sshd_config.5 2020-11-16 17:00:02.635070000 -0800 -@@ -1703,6 +1703,20 @@ for authentication using - .Cm TrustedUserCAKeys . - For more details on certificates, see the CERTIFICATES section in - .Xr ssh-keygen 1 . +--- sshd_config.5.orig 2023-12-18 15:59:50.000000000 +0100 ++++ sshd_config.5 2024-01-06 16:36:17.025742000 +0100 +@@ -1855,6 +1855,20 @@ This option may be useful in conjunction with + is to never expire connections for having no open channels. + This option may be useful in conjunction with + .Cm ChannelTimeout . +.It Cm UseBlacklist +Specifies whether +.Xr sshd 8