Package: openssh-server
Version: 1:9.9p2-2
Severity: important
Tags: patch
X-Debbugs-Cc: [email protected], [email protected]
User: [email protected]
Usertags: hurd-i386
Dear Maintainer,
I am running a Debian GNU/Hurd 2025 snapshot inside a virtual machine. After a
period of operation, attempting to SSH into the box resulted in connections
being immediately dropped with a "connection closed by port 22" error. Upon
checking the system state, I discovered that the /run/sshd directory had gone
missing.
I tried to execute '/etc/init.d/ssh reload' expecting the script to dynamically
verify and recreate the necessary runtime directories, just as it does during
the 'start' or 'restart' routines. Instead, the reload action failed to fix the
issue and left the openssh-server in a broken state with incoming connections
still dropping.
The root cause is a logic omission in the "reload|force-reload)" block of the
init script, which completely lacks a call to 'check_privsep_dir'. Because this
function is omitted, running 'reload' cannot self-heal a missing directory the
way 'start' or 'restart' can, leaving remote administrators locked out.
I have attached my modified script which successfully resolves this by ensuring
'check_privsep_dir' runs at the very beginning of the reload path.
-- System Information:
Debian Release: 13.0
APT prefers unreleased
APT policy: (500, 'unreleased'), (500, 'unstable')
Architecture: hurd-i386 (i686-AT386)
Kernel: GNU-Mach 1.8+git20250731-up-486/Hurd-0.9
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: sysvinit (via /sbin/init)
Versions of packages openssh-server depends on:
ii adduser 3.152
ii debconf [debconf-2.0] 1.5.91
ii init-system-helpers 1.68
ii libc0.3 2.41-12
ii libcom-err2 1.47.2-3+b3
ii libcrypt1 1:4.4.38-1
ii libgssapi-krb5-2 1.20.1-5.1
ii libkrb5-3 1.20.1-5.1
ii libpam-modules 1.7.0-2+hurd.1
ii libpam-runtime 1.7.0-5
ii libpam0g 1.7.0-2+hurd.1
ii libssl3t64 3.5.1-1
ii libwrap0 7.6.q-36
ii lsb-base 11.6
ii openssh-client 1:9.9p2-2
ii openssh-sftp-server 1:9.9p2-2
ii procps 2:3.3.17-7.1
ii runit-helper 2.16.4
ii sysvinit-utils [lsb-base] 3.14-4
ii ucf 3.0052
ii zlib1g 1:1.3.dfsg+really1.3.1-1+b1
Versions of packages openssh-server recommends:
pn default-logind | logind | libpam-systemd <none>
ii ncurses-term 6.5+20250216-2
ii xauth 1:1.1.2-1.1
Versions of packages openssh-server suggests:
pn molly-guard <none>
pn monkeysphere <none>
pn ssh-askpass <none>
pn ufw <none>
-- Configuration Files:
/etc/init.d/ssh changed:
set -e
test -x /usr/sbin/sshd || exit 0
( /usr/sbin/sshd -\? 2>&1 | grep -q OpenSSH ) 2>/dev/null || exit 0
umask 022
if test -f /etc/default/ssh; then
. /etc/default/ssh
fi
. /lib/lsb/init-functions
if [ -n "$2" ]; then
SSHD_OPTS="$SSHD_OPTS $2"
fi
run_by_init() {
([ "$previous" ] && [ "$runlevel" ]) || [ "$runlevel" = S ]
}
check_for_no_start() {
# forget it if we're trying to start, and /etc/ssh/sshd_not_to_be_run exists
if [ -e /etc/ssh/sshd_not_to_be_run ]; then
if [ "$1" = log_end_msg ]; then
log_end_msg 0 || true
fi
if ! run_by_init; then
log_action_msg "OpenBSD Secure Shell server not in use
(/etc/ssh/sshd_not_to_be_run)" || true
fi
exit 0
fi
}
check_dev_null() {
if [ ! -c /dev/null ]; then
if [ "$1" = log_end_msg ]; then
log_end_msg 1 || true
fi
if ! run_by_init; then
log_action_msg "/dev/null is not a character device!" || true
fi
exit 1
fi
}
check_privsep_dir() {
# Create the PrivSep empty dir if necessary
if [ ! -d /run/sshd ]; then
mkdir /run/sshd
chmod 0755 /run/sshd
fi
}
check_config() {
if [ ! -e /etc/ssh/sshd_not_to_be_run ]; then
# shellcheck disable=SC2086
/usr/sbin/sshd $SSHD_OPTS -t || exit 1
fi
}
export PATH="${PATH:+$PATH:}/usr/sbin:/sbin"
case "$1" in
start)
check_privsep_dir
check_for_no_start
check_dev_null
log_daemon_msg "Starting OpenBSD Secure Shell server" "sshd" || true
# shellcheck disable=SC2086
if start-stop-daemon --start --quiet --oknodo --chuid 0:0 --pidfile
/run/sshd.pid --exec /usr/sbin/sshd -- $SSHD_OPTS; then
log_end_msg 0 || true
else
log_end_msg 1 || true
fi
;;
stop)
log_daemon_msg "Stopping OpenBSD Secure Shell server" "sshd" || true
if start-stop-daemon --stop --quiet --oknodo --pidfile /run/sshd.pid
--exec /usr/sbin/sshd; then
log_end_msg 0 || true
else
log_end_msg 1 || true
fi
;;
reload|force-reload)
check_privsep_dir
check_for_no_start
check_config
log_daemon_msg "Reloading OpenBSD Secure Shell server's configuration"
"sshd" || true
if start-stop-daemon --stop --signal 1 --quiet --oknodo --pidfile
/run/sshd.pid --exec /usr/sbin/sshd; then
log_end_msg 0 || true
else
log_end_msg 1 || true
fi
;;
restart)
check_privsep_dir
check_config
log_daemon_msg "Restarting OpenBSD Secure Shell server" "sshd" || true
start-stop-daemon --stop --quiet --oknodo --retry 30 --pidfile
/run/sshd.pid --exec /usr/sbin/sshd
check_for_no_start log_end_msg
check_dev_null log_end_msg
# shellcheck disable=SC2086
if start-stop-daemon --start --quiet --oknodo --chuid 0:0 --pidfile
/run/sshd.pid --exec /usr/sbin/sshd -- $SSHD_OPTS; then
log_end_msg 0 || true
else
log_end_msg 1 || true
fi
;;
try-restart)
check_privsep_dir
check_config
log_daemon_msg "Restarting OpenBSD Secure Shell server" "sshd" || true
RET=0
start-stop-daemon --stop --quiet --retry 30 --pidfile /run/sshd.pid
--exec /usr/sbin/sshd || RET="$?"
case $RET in
0)
# old daemon stopped
check_for_no_start log_end_msg
check_dev_null log_end_msg
# shellcheck disable=SC2086
if start-stop-daemon --start --quiet --oknodo --chuid 0:0
--pidfile /run/sshd.pid --exec /usr/sbin/sshd -- $SSHD_OPTS; then
log_end_msg 0 || true
else
log_end_msg 1 || true
fi
;;
1)
# daemon not running
log_progress_msg "(not running)" || true
log_end_msg 0 || true
;;
*)
# failed to stop
log_progress_msg "(failed to stop)" || true
log_end_msg 1 || true
;;
esac
;;
status)
status_of_proc -p /run/sshd.pid /usr/sbin/sshd sshd && exit 0 || exit $?
;;
*)
log_action_msg "Usage: /etc/init.d/ssh
{start|stop|reload|force-reload|restart|try-restart|status}" || true
exit 1
esac
exit 0
-- debconf information:
openssh-server/permit-root-login: true
openssh-server/password-authentication: true