Package: openssh-server
Version: 1:9.9p2-2
Severity: important
Tags: patch
X-Debbugs-Cc: [email protected], [email protected]
User: [email protected]
Usertags: hurd-i386

Dear Maintainer,

I am running a Debian GNU/Hurd 2025 snapshot inside a virtual machine. After a 
period of operation, attempting to SSH into the box resulted in connections 
being immediately dropped with a "connection closed by port 22" error. Upon 
checking the system state, I discovered that the /run/sshd directory had gone 
missing.

I tried to execute '/etc/init.d/ssh reload' expecting the script to dynamically 
verify and recreate the necessary runtime directories, just as it does during 
the 'start' or 'restart' routines. Instead, the reload action failed to fix the 
issue and left the openssh-server in a broken state with incoming connections 
still dropping.

The root cause is a logic omission in the "reload|force-reload)" block of the 
init script, which completely lacks a call to 'check_privsep_dir'. Because this 
function is omitted, running 'reload' cannot self-heal a missing directory the 
way 'start' or 'restart' can, leaving remote administrators locked out.

I have attached my modified script which successfully resolves this by ensuring 
'check_privsep_dir' runs at the very beginning of the reload path.



-- System Information:
Debian Release: 13.0
  APT prefers unreleased
  APT policy: (500, 'unreleased'), (500, 'unstable')
Architecture: hurd-i386 (i686-AT386)

Kernel: GNU-Mach 1.8+git20250731-up-486/Hurd-0.9
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: sysvinit (via /sbin/init)

Versions of packages openssh-server depends on:
ii  adduser                    3.152
ii  debconf [debconf-2.0]      1.5.91
ii  init-system-helpers        1.68
ii  libc0.3                    2.41-12
ii  libcom-err2                1.47.2-3+b3
ii  libcrypt1                  1:4.4.38-1
ii  libgssapi-krb5-2           1.20.1-5.1
ii  libkrb5-3                  1.20.1-5.1
ii  libpam-modules             1.7.0-2+hurd.1
ii  libpam-runtime             1.7.0-5
ii  libpam0g                   1.7.0-2+hurd.1
ii  libssl3t64                 3.5.1-1
ii  libwrap0                   7.6.q-36
ii  lsb-base                   11.6
ii  openssh-client             1:9.9p2-2
ii  openssh-sftp-server        1:9.9p2-2
ii  procps                     2:3.3.17-7.1
ii  runit-helper               2.16.4
ii  sysvinit-utils [lsb-base]  3.14-4
ii  ucf                        3.0052
ii  zlib1g                     1:1.3.dfsg+really1.3.1-1+b1

Versions of packages openssh-server recommends:
pn  default-logind | logind | libpam-systemd  <none>
ii  ncurses-term                              6.5+20250216-2
ii  xauth                                     1:1.1.2-1.1

Versions of packages openssh-server suggests:
pn  molly-guard   <none>
pn  monkeysphere  <none>
pn  ssh-askpass   <none>
pn  ufw           <none>

-- Configuration Files:
/etc/init.d/ssh changed:
set -e
test -x /usr/sbin/sshd || exit 0
( /usr/sbin/sshd -\? 2>&1 | grep -q OpenSSH ) 2>/dev/null || exit 0
umask 022
if test -f /etc/default/ssh; then
    . /etc/default/ssh
fi
. /lib/lsb/init-functions
if [ -n "$2" ]; then
    SSHD_OPTS="$SSHD_OPTS $2"
fi
run_by_init() {
    ([ "$previous" ] && [ "$runlevel" ]) || [ "$runlevel" = S ]
}
check_for_no_start() {
    # forget it if we're trying to start, and /etc/ssh/sshd_not_to_be_run exists
    if [ -e /etc/ssh/sshd_not_to_be_run ]; then 
        if [ "$1" = log_end_msg ]; then
            log_end_msg 0 || true
        fi
        if ! run_by_init; then
            log_action_msg "OpenBSD Secure Shell server not in use 
(/etc/ssh/sshd_not_to_be_run)" || true
        fi
        exit 0
    fi
}
check_dev_null() {
    if [ ! -c /dev/null ]; then
        if [ "$1" = log_end_msg ]; then
            log_end_msg 1 || true
        fi
        if ! run_by_init; then
            log_action_msg "/dev/null is not a character device!" || true
        fi
        exit 1
    fi
}
check_privsep_dir() {
    # Create the PrivSep empty dir if necessary
    if [ ! -d /run/sshd ]; then
        mkdir /run/sshd
        chmod 0755 /run/sshd
    fi
}
check_config() {
    if [ ! -e /etc/ssh/sshd_not_to_be_run ]; then
        # shellcheck disable=SC2086
        /usr/sbin/sshd $SSHD_OPTS -t || exit 1
    fi
}
export PATH="${PATH:+$PATH:}/usr/sbin:/sbin"
case "$1" in
  start)
        check_privsep_dir
        check_for_no_start
        check_dev_null
        log_daemon_msg "Starting OpenBSD Secure Shell server" "sshd" || true
        # shellcheck disable=SC2086
        if start-stop-daemon --start --quiet --oknodo --chuid 0:0 --pidfile 
/run/sshd.pid --exec /usr/sbin/sshd -- $SSHD_OPTS; then
            log_end_msg 0 || true
        else
            log_end_msg 1 || true
        fi
        ;;
  stop)
        log_daemon_msg "Stopping OpenBSD Secure Shell server" "sshd" || true
        if start-stop-daemon --stop --quiet --oknodo --pidfile /run/sshd.pid 
--exec /usr/sbin/sshd; then
            log_end_msg 0 || true
        else
            log_end_msg 1 || true
        fi
        ;;
  reload|force-reload)
        check_privsep_dir
        check_for_no_start
        check_config
        log_daemon_msg "Reloading OpenBSD Secure Shell server's configuration" 
"sshd" || true
        if start-stop-daemon --stop --signal 1 --quiet --oknodo --pidfile 
/run/sshd.pid --exec /usr/sbin/sshd; then
            log_end_msg 0 || true
        else
            log_end_msg 1 || true
        fi
        ;;
  restart)
        check_privsep_dir
        check_config
        log_daemon_msg "Restarting OpenBSD Secure Shell server" "sshd" || true
        start-stop-daemon --stop --quiet --oknodo --retry 30 --pidfile 
/run/sshd.pid --exec /usr/sbin/sshd
        check_for_no_start log_end_msg
        check_dev_null log_end_msg
        # shellcheck disable=SC2086
        if start-stop-daemon --start --quiet --oknodo --chuid 0:0 --pidfile 
/run/sshd.pid --exec /usr/sbin/sshd -- $SSHD_OPTS; then
            log_end_msg 0 || true
        else
            log_end_msg 1 || true
        fi
        ;;
  try-restart)
        check_privsep_dir
        check_config
        log_daemon_msg "Restarting OpenBSD Secure Shell server" "sshd" || true
        RET=0
        start-stop-daemon --stop --quiet --retry 30 --pidfile /run/sshd.pid 
--exec /usr/sbin/sshd || RET="$?"
        case $RET in
            0)
                # old daemon stopped
                check_for_no_start log_end_msg
                check_dev_null log_end_msg
                # shellcheck disable=SC2086
                if start-stop-daemon --start --quiet --oknodo --chuid 0:0 
--pidfile /run/sshd.pid --exec /usr/sbin/sshd -- $SSHD_OPTS; then
                    log_end_msg 0 || true
                else
                    log_end_msg 1 || true
                fi
                ;;
            1)
                # daemon not running
                log_progress_msg "(not running)" || true
                log_end_msg 0 || true
                ;;
            *)
                # failed to stop
                log_progress_msg "(failed to stop)" || true
                log_end_msg 1 || true
                ;;
        esac
        ;;
  status)
        status_of_proc -p /run/sshd.pid /usr/sbin/sshd sshd && exit 0 || exit $?
        ;;
  *)
        log_action_msg "Usage: /etc/init.d/ssh 
{start|stop|reload|force-reload|restart|try-restart|status}" || true
        exit 1
esac
exit 0


-- debconf information:
  openssh-server/permit-root-login: true
  openssh-server/password-authentication: true

Reply via email to