From owner-svn-ports-head@freebsd.org Thu Apr 12 17:29:00 2018 Return-Path: Delivered-To: svn-ports-head@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 803F3FA5D93; Thu, 12 Apr 2018 17:29:00 +0000 (UTC) (envelope-from bdrewery@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2610:1c1:1:6074::16:84]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "freefall.freebsd.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 24ADC7E8BC; Thu, 12 Apr 2018 17:29:00 +0000 (UTC) (envelope-from bdrewery@FreeBSD.org) Received: from mail.xzibition.com (unknown [127.0.1.132]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by freefall.freebsd.org (Postfix) with ESMTPS id EE37413CE6; Thu, 12 Apr 2018 17:28:59 +0000 (UTC) (envelope-from bdrewery@FreeBSD.org) Received: from mail.xzibition.com (localhost [172.31.3.2]) by mail.xzibition.com (Postfix) with ESMTP id 9BD0E7E5; Thu, 12 Apr 2018 17:28:58 +0000 (UTC) X-Virus-Scanned: amavisd-new at mail.xzibition.com Received: from mail.xzibition.com ([172.31.3.2]) by mail.xzibition.com (mail.xzibition.com [172.31.3.2]) (amavisd-new, port 10026) with LMTP id 0eYZyLr9jFUU; Thu, 12 Apr 2018 17:28:56 +0000 (UTC) Subject: Re: svn commit: r466577 - in head/security/openssh-portable: . files DKIM-Filter: OpenDKIM Filter v2.10.3 mail.xzibition.com 3FF3A7E0 To: Craig Leres , ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org References: <201804051820.w35IKpi2062956@repo.freebsd.org> <295c901e-d369-fe1b-4f6b-cff59098e166@freebsd.org> From: Bryan Drewery Openpgp: id=F9173CB2C3AAEA7A5C8A1F0935D771BB6E4697CF; url=http://www.shatow.net/bryan/bryan2.asc Organization: FreeBSD Message-ID: Date: Thu, 12 Apr 2018 10:28:48 -0700 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.7.0 MIME-Version: 1.0 In-Reply-To: Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="PHfFFIkNvZUT5EaYc9GEmt8jfyvwUFJt1" X-BeenThere: svn-ports-head@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: SVN commit messages for the ports tree for head List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 12 Apr 2018 17:29:00 -0000 This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --PHfFFIkNvZUT5EaYc9GEmt8jfyvwUFJt1 Content-Type: multipart/mixed; boundary="H3SRhFgXXPctmLtQuiQWGxcn2zsugBIE4"; protected-headers="v1" From: Bryan Drewery To: Craig Leres , ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Message-ID: Subject: Re: svn commit: r466577 - in head/security/openssh-portable: . files References: <201804051820.w35IKpi2062956@repo.freebsd.org> <295c901e-d369-fe1b-4f6b-cff59098e166@freebsd.org> In-Reply-To: --H3SRhFgXXPctmLtQuiQWGxcn2zsugBIE4 Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: quoted-printable Sorry I've been super busy. If this is right please commit it with a PORTREVISION bump. Other patches had similar problems where fuzz applied them incorrectly. On 4/11/2018 9:27 PM, Craig Leres wrote: > On 04/06/18 18:12, Craig Leres wrote: >> This version breaks sshfp support >=20 > I poked at this and the issue is that a block of code that canonicalize= s > the host supplied on the command teleported from main() to > ssh_session2(). What the VerifyHostKeyDNS yes path now encounters is > that the non-canonical version of the hostname is used for the SSHFP > lookup. The base problem is that files/patch-ssh.c has not been updated= > recently and somehow manages to be applied to the wrong part of ssh.c. >=20 > Attached is an updated patch.ssh.c >=20 > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 Craig --=20 Regards, Bryan Drewery --H3SRhFgXXPctmLtQuiQWGxcn2zsugBIE4-- --PHfFFIkNvZUT5EaYc9GEmt8jfyvwUFJt1 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQEcBAEBAgAGBQJaz5dWAAoJEDXXcbtuRpfPW0sH/3KBmbrF/x6dHWtAeF5Bov81 WOXXZtWZlax135Aa3KIPc43ApdsCP/H84SD+PEMT55Ky/xP5MQLAfQRZqMTGvJz7 LPCiDk++Ui33aWiT5r6Ah/Nz/+zQGf22MkdRhOdAN5BJvS9ehx8W9O4u5u9nv3s+ My3Mf5T9Y6jemEoVmm/uVAM1olKXkYFBUj37MnA2veR3bCoQ/xOKTJ9v03BZsb22 7sAxG1J74mCOZ3nQPQ/KbCglXK4TOGIcGn6hT/LYyY+Ju0B4IeDra+Bmey8TGMku 7nUNRmigBgWsT5I7/ZCWEKF/bUuWEjqxAMw4HbhMgi2qpe/OmnjxFrrNjF2cY8M= =rvOz -----END PGP SIGNATURE----- --PHfFFIkNvZUT5EaYc9GEmt8jfyvwUFJt1--