From nobody Thu Jan 11 18:09:41 2024 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4T9t3p3qLSz56cVg; Thu, 11 Jan 2024 18:09:42 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4T9t3p1y7Hz58Jw; Thu, 11 Jan 2024 18:09:42 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1704996582; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=T3/lhUCMSPw/lhva0mSjn+PE/IwijkytTv3mBiZXZ60=; b=I/ut2+0eHZGFMajjK1jOMVlDwV0FjQfQD5xN5h+y/OohDh42nsqFbnvnrYSotaaAdB4Mov 0YGhqgH8q6Bkja7ZEJbvVBvcb+9CSnWFN0O1kgIjnjWOnKXDvz7pC3uGGE54AlmgoLGbv+ N6Zd0jkLa20MCu7pJff+0Z8TSsE0TWIRLSA8DPkyqn/kTtRBlVoS1t2PKE9uHqaiiXxTr2 EAuf1EsoIMcmilLdGvus8KCm5G6chh1wRihL/dYC96XanpjNUbkiOlR9i/Ov8D9vqWZ1il HbTMqPVnemh/0jgzrJ9DRCDegHjvDbzbXy0KMiejVuqYZJOT45qQ7vCxrSCQBw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1704996582; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=T3/lhUCMSPw/lhva0mSjn+PE/IwijkytTv3mBiZXZ60=; b=jZuEyU3u8YvZgA8xYJo+Q74Vubjdpc2eE5PU/a57JJTdtZ+lDDtfkdS1oX8IUBi1cJx/lc q0OyMnVzIs9DU1r8dFUGF6gz75TYFDtnbzpzxm+6DaESkwMHFIDPvgB4FNAcTO44tfyWoH RrocVGnCUEfyFSHHUulbBYJsy7p8QkiesSDvzU6YlO3kFEsC9arH3UKe7OE6dLIZpjSkeH QlPunrwZit3QhdKr/cHAynTz3ATJtiu3R/YM5Csagth87EyetJM3x0dQIFDUN9pRn4MR34 zv9agT/RaEl7uhJYEH5we4U/HXCBgEgl1l5jgM3YjNu998KJYUtIg8o3+6Ey9g== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1704996582; a=rsa-sha256; cv=none; b=oaU1KpZZGthve4nxYRwhI3KD7RKuVZUfer+fHVblCyIJAbTuGAQm/c9AFbjDzCf1j+b8JD QGdPZBPMkOJk8NBdWhGhnY9C9BdyFvGb+tc9p01zzaucXPbmeVt7qBWgd0KTRATH/w9CnB 36wHtLpcxZChs98lNy4CyKlcO3adYqivpmHBBuVQnwAo49iC/y6YKk/GClftwwyiG5beXG TulQD4O2Yb7YPzesr/Cf8XN5zA3LyEtDCJQcLEazjnxjGVUrm2a/zARkhJ6F1iPc0C+uJI 5vjR/CmHOkYV0Xup6mbs3KxI1Kd/0ExGwI4ZX+lpGcSh+RRf2lneQxsxyY9chw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4T9t3p0dwlzTDs; Thu, 11 Jan 2024 18:09:42 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 40BI9fIT085106; Thu, 11 Jan 2024 18:09:41 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 40BI9fkw085103; Thu, 11 Jan 2024 18:09:41 GMT (envelope-from git) Date: Thu, 11 Jan 2024 18:09:41 GMT Message-Id: <202401111809.40BI9fkw085103@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-branches@FreeBSD.org From: Bryan Drewery Subject: git: 41aa82664915 - 2024Q1 - security/openssh-portable: Fix blacklistd patch List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: bdrewery X-Git-Repository: ports X-Git-Refname: refs/heads/2024Q1 X-Git-Reftype: branch X-Git-Commit: 41aa82664915ea460861fba3f31932e45e107536 Auto-Submitted: auto-generated The branch 2024Q1 has been updated by bdrewery: URL: https://cgit.FreeBSD.org/ports/commit/?id=41aa82664915ea460861fba3f31932e45e107536 commit 41aa82664915ea460861fba3f31932e45e107536 Author: Bernard Spil AuthorDate: 2024-01-06 15:49:12 +0000 Commit: Bryan Drewery CommitDate: 2024-01-11 18:09:14 +0000 security/openssh-portable: Fix blacklistd patch (cherry picked from commit d820fcf123b40037884c06a94a42275934587a8f) --- security/openssh-portable/files/extra-patch-blacklistd | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/security/openssh-portable/files/extra-patch-blacklistd b/security/openssh-portable/files/extra-patch-blacklistd index 7bb88b2961fe..5d23bf869f7a 100644 --- a/security/openssh-portable/files/extra-patch-blacklistd +++ b/security/openssh-portable/files/extra-patch-blacklistd @@ -277,9 +277,9 @@ --- auth2.c.orig 2020-11-16 17:10:36.772062000 -0800 +++ auth2.c 2020-11-16 17:12:04.852943000 -0800 @@ -58,6 +58,7 @@ - #endif #include "monitor_wrap.h" #include "digest.h" + #include "kex.h" +#include "blacklist_client.h" /* import */ @@ -317,7 +317,7 @@ @@ -1882,6 +1883,7 @@ sshpkt_vfatal(struct ssh *ssh, int r, const char *fmt, case SSH_ERR_NO_KEX_ALG_MATCH: case SSH_ERR_NO_HOSTKEY_ALG_MATCH: - if (ssh && ssh->kex && ssh->kex->failed_choice) { + if (ssh->kex && ssh->kex->failed_choice) { + BLACKLIST_NOTIFY(BLACKLIST_AUTH_FAIL, ssh, "ssh"); ssh_packet_clear_keys(ssh); errno = oerrno; @@ -372,12 +372,12 @@ #Compression delayed #ClientAliveInterval 0 #ClientAliveCountMax 3 ---- sshd_config.5.orig 2020-11-16 16:57:58.533307000 -0800 -+++ sshd_config.5 2020-11-16 17:00:02.635070000 -0800 -@@ -1703,6 +1703,20 @@ for authentication using - .Cm TrustedUserCAKeys . - For more details on certificates, see the CERTIFICATES section in - .Xr ssh-keygen 1 . +--- sshd_config.5.orig 2023-12-18 15:59:50.000000000 +0100 ++++ sshd_config.5 2024-01-06 16:36:17.025742000 +0100 +@@ -1855,6 +1855,20 @@ This option may be useful in conjunction with + is to never expire connections for having no open channels. + This option may be useful in conjunction with + .Cm ChannelTimeout . +.It Cm UseBlacklist +Specifies whether +.Xr sshd 8