Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package openssh for openSUSE:Factory checked 
in at 2026-10-02 23:02:38
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/openssh (Old)
 and      /work/SRC/openSUSE:Factory/.openssh.new.1631729 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "openssh"

Fri Oct  2 23:02:38 2026 rev:210 rq:1381978 version:10.5p1

Changes:
--------
+++ only whitespace diff in changes, re-diffing
--- /work/SRC/openSUSE:Factory/openssh/openssh.changes  2026-09-30 
16:22:46.990675527 +0200
+++ /work/SRC/openSUSE:Factory/.openssh.new.1631729/openssh.changes     
2026-10-02 23:03:15.397073962 +0200
@@ -1,0 +2,14 @@
+Wed Sep 30 21:45:12 UTC 2026 - Hans Petter Jansson <[email protected]>
+
+- Update openssh-8.4p1-ssh_config_d.patch with mentions of the
+  configuration drop-in directories (bsc#1259462).
+- Add openssh-10.5p1-propagate-restrict-keyword.patch (bsc#1275079).
+
+-------------------------------------------------------------------
+Tue Sep 29 07:23:16 UTC 2026 - Tomáš Chvátal <[email protected]>
+
+- Drop obsolete -fstack-protector from CFLAGS/CXXFLAGS (added 2006,
+  predates distro -fstack-protector-strong in optflags; the trailing
+  basic flag silently downgraded strong to basic).
+
+-------------------------------------------------------------------

New:
----
  openssh-10.5p1-propagate-restrict-keyword.patch

----------(New B)----------
  New:/work/SRC/openSUSE:Factory/.openssh.new.1631729/openssh.changes-  
configuration drop-in directories (bsc#1259462).
/work/SRC/openSUSE:Factory/.openssh.new.1631729/openssh.changes:- Add 
openssh-10.5p1-propagate-restrict-keyword.patch (bsc#1275079).
/work/SRC/openSUSE:Factory/.openssh.new.1631729/openssh.changes-
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ openssh.spec ++++++
--- /var/tmp/diff_new_pack.YGro1b/_old  2026-10-02 23:03:17.940180402 +0200
+++ /var/tmp/diff_new_pack.YGro1b/_new  2026-10-02 23:03:17.942180486 +0200
@@ -178,6 +178,8 @@
 Patch108:       openssh-7.7p1-gssapi-new-unique.patch
 # PATCH-FIX-UPSTREAM openssh-10.5p1-sync-readpassphrase.patch mindrot#3995 
[email protected] -- Sync readpassphrase(3) with OpenBSD libc: preserve SIG_IGN 
so ssh-add no longer spins without a controlling tty
 Patch109:       openssh-10.5p1-sync-readpassphrase.patch
+# PATCH-FIX-UPSTREAM openssh-10.5p1-propagate-restrict-keyword.patch 
bsc#1275079 -- Propagate the authorized_keys "restrict" flag
+Patch110:       openssh-10.5p1-propagate-restrict-keyword.patch
 # 200..300 -- Patches submitted to upstream
 # 1000..2000 -- Conditional patches
 %if %{with crypto_policies}
@@ -389,8 +391,8 @@
 %else
 PIEFLAGS="-fpie"
 %endif
-CFLAGS="%{optflags} $PIEFLAGS -fstack-protector"
-CXXFLAGS="%{optflags} $PIEFLAGS -fstack-protector"
+CFLAGS="%{optflags} $PIEFLAGS"
+CXXFLAGS="%{optflags} $PIEFLAGS"
 LDFLAGS="-pie -Wl,--as-needed"
 #CPPFLAGS="%%{optflags} -DUSE_INTERNAL_B64"
 export LDFLAGS CFLAGS CXXFLAGS CPPFLAGS

++++++ openssh-10.5p1-propagate-restrict-keyword.patch ++++++
>From 991f1f31dde2797416acaf4319dbebe764446c6f Mon Sep 17 00:00:00 2001
From: "[email protected]" <[email protected]>
Date: Tue, 16 Sep 2026 00:33:44 +0000
Subject: [PATCH] upstream: Propagate authorized_keys "resrict" keyword

The "restrict" keyword was not pervasively being applied to TunnelForwarding
connections (which are administratively disabled by default). This is a
separate problem to the one fixed in openssh-10.5

reported by several people; ok markus, deraadt

OpenBSD-Commit-ID: 8c36c31dc2bdbc0c432d1056496b2f1ce93198d1

>From ded92bffa2e2f2db9b83245c5061812791bfa47f Mon Sep 17 00:00:00 2001
From: "[email protected]" <[email protected]>
Date: Tue, 16 Sep 2026 04:51:28 +0000
Subject: [PATCH] upstream: correctly check sshauthopt->restricted merging

OpenBSD-Regress-ID: e81e9267514338d6cf6bd2f83dcb722538af528e

>From a30bafcbbd44dc4dc91916240c32ecabff899338 Mon Sep 17 00:00:00 2001
From: "[email protected]" <[email protected]>
Date: Tue, 16 Sep 2026 04:56:12 +0000
Subject: [PATCH] upstream: simpler

OpenBSD-Regress-ID: c7f30b865abd0b3e0e5514f861509c32e352a760

Index: openssh-10.5p1/auth-options.c
===================================================================
--- openssh-10.5p1.orig/auth-options.c
+++ openssh-10.5p1/auth-options.c
@@ -604,6 +604,7 @@ sshauthopt_merge(const struct sshauthopt
        OPTFLAG_AND(no_require_user_presence);
        /* Restrictive flags are logical-OR (i.e. must be set in either) */
        OPTFLAG_OR(require_verify);
+       OPTFLAG_OR(restricted);
 #undef OPTFLAG_AND
 
        /* Earliest expiry time should win */
Index: openssh-10.5p1/regress/unittests/authopt/tests.c
===================================================================
--- openssh-10.5p1.orig/regress/unittests/authopt/tests.c
+++ openssh-10.5p1/regress/unittests/authopt/tests.c
@@ -418,13 +418,15 @@ test_merge(void)
        } while (0)
 
        /* Check a single case of merging of flag options */
-#define FLAG_CASE(keybase, label, keyname, keywords, mostly_off, var, val) \
+#define FLAG_CASE(keybase, label, keyname, keywords, mostly_off, \
+           rflag, var, val) \
        do { \
                PREPARE(keybase " " label, keyname, keywords); \
                expected = mostly_off ? \
                    sshauthopt_new() : default_authkey_opts(); \
-               expected->var = val; \
                ASSERT_PTR_NE(expected, NULL); \
+               expected->restricted = rflag; \
+               expected->var = val; \
                CHECK_SUCCESS_AND_CLEANUP(); \
                TEST_DONE(); \
        } while (0)
@@ -437,40 +439,40 @@ test_merge(void)
 #define FLAG_TEST(keybase, keyword, var) \
        do { \
                FLAG_CASE(keybase, "keys:default,yes cert:default,no", \
-                   "no_" keybase, keyword, 0, var, 0); \
+                   "no_" keybase, keyword, 0, 0, var, 0); \
                FLAG_CASE(keybase,"keys:-*,yes cert:default,no", \
-                   "no_" keybase, "restrict," keyword, 1, var, 0); \
+                   "no_" keybase, "restrict," keyword, 1, 1, var, 0); \
                FLAG_CASE(keybase, "keys:default,no cert:default,no", \
-                   "no_" keybase, "no-" keyword, 0, var, 0); \
+                   "no_" keybase, "no-" keyword, 0, 0, var, 0); \
                FLAG_CASE(keybase, "keys:-*,no cert:default,no", \
-                   "no_" keybase, "restrict,no-" keyword, 1, var, 0); \
+                   "no_" keybase, "restrict,no-" keyword, 1, 1, var, 0); \
                \
                FLAG_CASE(keybase, "keys:default,yes cert:-*,yes", \
-                   "only_" keybase, keyword, 1, var, 1); \
+                   "only_" keybase, keyword, 1, 0, var, 1); \
                FLAG_CASE(keybase,"keys:-*,yes cert:-*,yes", \
-                   "only_" keybase, "restrict," keyword, 1, var, 1); \
+                   "only_" keybase, "restrict," keyword, 1, 1, var, 1); \
                FLAG_CASE(keybase, "keys:default,no cert:-*,yes", \
-                   "only_" keybase, "no-" keyword, 1, var, 0); \
+                   "only_" keybase, "no-" keyword, 1, 0, var, 0); \
                FLAG_CASE(keybase, "keys:-*,no cert:-*,yes", \
-                   "only_" keybase, "restrict,no-" keyword, 1, var, 0); \
+                   "only_" keybase, "restrict,no-" keyword, 1, 1, var, 0); \
                \
                FLAG_CASE(keybase, "keys:default,yes cert:-*", \
-                   "no_permit", keyword, 1, var, 0); \
+                   "no_permit", keyword, 1, 0, var, 0); \
                FLAG_CASE(keybase,"keys:-*,yes cert:-*", \
-                   "no_permit", "restrict," keyword, 1, var, 0); \
+                   "no_permit", "restrict," keyword, 1, 1, var, 0); \
                FLAG_CASE(keybase, "keys:default,no cert:-*", \
-                   "no_permit", "no-" keyword, 1, var, 0); \
+                   "no_permit", "no-" keyword, 1, 0, var, 0); \
                FLAG_CASE(keybase, "keys:-*,no cert:-*", \
-                   "no_permit", "restrict,no-" keyword, 1, var, 0); \
+                   "no_permit", "restrict,no-" keyword, 1, 1, var, 0); \
                \
                FLAG_CASE(keybase, "keys:default,yes cert:*", \
-                   "all_permit", keyword, 0, var, 1); \
+                   "all_permit", keyword, 0, 0, var, 1); \
                FLAG_CASE(keybase,"keys:-*,yes cert:*", \
-                   "all_permit", "restrict," keyword, 1, var, 1); \
+                   "all_permit", "restrict," keyword, 1, 1, var, 1); \
                FLAG_CASE(keybase, "keys:default,no cert:*", \
-                   "all_permit", "no-" keyword, 0, var, 0); \
+                   "all_permit", "no-" keyword, 0, 0, var, 0); \
                FLAG_CASE(keybase, "keys:-*,no cert:*", \
-                   "all_permit", "restrict,no-" keyword, 1, var, 0); \
+                   "all_permit", "restrict,no-" keyword, 1, 1, var, 0); \
                \
        } while (0)
        FLAG_TEST("portfwd", "port-forwarding", permit_port_forwarding_flag);


++++++ openssh-8.4p1-ssh_config_d.patch ++++++
--- /var/tmp/diff_new_pack.YGro1b/_old  2026-10-02 23:03:18.362198066 +0200
+++ /var/tmp/diff_new_pack.YGro1b/_new  2026-10-02 23:03:18.372198484 +0200
@@ -38,4 +38,76 @@
  
  #Port 22
  #AddressFamily any
+Index: openssh-8.9p1/sshd_config.5
+===================================================================
+--- openssh-8.9p1.orig/sshd_config.5
++++ openssh-8.9p1/sshd_config.5
+@@ -56,6 +56,19 @@ Arguments may optionally be enclosed in
+ .Pq \&"
+ in order to represent arguments containing spaces.
+ .Pp
++Note that the default configuration file shipped with SUSE distributions
++begins by including the drop-in files
++.Pa /etc/ssh/sshd_config.d/*.conf .
++Because these files are included at the start of the configuration file,
++options set there will override those in
++.Pa /etc/ssh/sshd_config .
++The files are processed in lexical order.
++To change the system-wide configuration, add a
++.Pa *.conf
++file to
++.Pa /etc/ssh/sshd_config.d
++instead of editing the configuration file itself.
++.Pp
+ The possible
+ keywords and their meanings are as follows (note that
+ keywords are case-insensitive and arguments are case-sensitive):
+@@ -2117,6 +2130,11 @@ Contains configuration data for
+ .Xr sshd 8 .
+ This file should be writable by root only, but it is recommended
+ (though not necessary) that it be world-readable.
++.It Pa /etc/ssh/sshd_config.d/*.conf
++Drop-in configuration files, included at the start of the default
++configuration file.
++Options set in these files override those in
++.Pa /etc/ssh/sshd_config .
+ .El
+ .Sh SEE ALSO
+ .Xr sftp-server 8 ,
+Index: openssh-8.9p1/ssh_config.5
+===================================================================
+--- openssh-8.9p1.orig/ssh_config.5
++++ openssh-8.9p1/ssh_config.5
+@@ -90,6 +90,19 @@ and
+ .Fl o
+ option.
+ .Pp
++Note that the default system-wide configuration file shipped with SUSE
++distributions begins by including the drop-in files
++.Pa /etc/ssh/ssh_config.d/*.conf .
++Because these files are included at the start of the configuration file,
++options set there will override those in
++.Pa /etc/ssh/ssh_config .
++The files are processed in lexical order.
++To change the system-wide configuration, add a
++.Pa *.conf
++file to
++.Pa /etc/ssh/ssh_config.d
++instead of editing the configuration file itself.
++.Pp
+ The possible
+ keywords and their meanings are as follows (note that
+ keywords are case-insensitive and arguments are case-sensitive):
+@@ -2379,6 +2392,11 @@ The format of this file is described abo
+ This file is used by the SSH client.
+ Because of the potential for abuse, this file must have strict permissions:
+ read/write for the user, and not writable by others.
++.It Pa /etc/ssh/ssh_config.d/*.conf
++Drop-in configuration files, included at the start of the default
++system-wide configuration file.
++Options set in these files override those in
++.Pa /etc/ssh/ssh_config .
+ .It Pa /etc/ssh/ssh_config
+ Systemwide configuration file.
+ This file provides defaults for those
 

Reply via email to