[Bug 1815741] Re: Probable regression after rssh security update

2019-04-12 Thread Iyyappa Murugandi
Thanks, will test it in our end. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1815741 Title: Probable regression after rssh security update To manage notifications about this bug go to: https://bu

[Bug 1815935] Re: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing

2019-04-11 Thread Iyyappa Murugandi
That's great news. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1815935 Title: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing To manage notifications about this bug go t

[Bug 1815935] Re: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing

2019-03-05 Thread Iyyappa Murugandi
Thanks! Do you know when will the new package be released? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1815935 Title: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing To manage n

[Bug 1815935] Re: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing

2019-02-27 Thread Iyyappa Murugandi
Thanks for fixing it in Debian. I'll request someone from Ubuntu to import the fix. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1815935 Title: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp com

[Bug 1815935] Re: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing

2019-02-26 Thread Iyyappa Murugandi
Russ, Please let us know if there is an update on this bug. This regression is having a huge impact on our business, so it would be good if you could provide us with an update (https://blogs.msdn.microsoft.com/azureservicefabric/2019/02/07/known-issue-for-service-fabric-linux-clusters/ ). It w

[Bug 1815935] Re: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing

2019-02-18 Thread Iyyappa Murugandi
Sounds good. We will keep that as an option for the long term solution. It would be great if you could provide a fix for the regression. Thanks again! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1815

[Bug 1815935] Re: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing

2019-02-18 Thread Iyyappa Murugandi
Thanks for looking into it. Do you have any suggestion for the alternative solutions? If we decide to not use rssh tomorrow, the user we created that was meant only for file transfer would be a regular user, that would solve current issue and remove dependency on rssh. But that will be step down

[Bug 1815935] Re: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing

2019-02-14 Thread Iyyappa Murugandi
Also libssh2 scp_send() uses "-pt" option. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1815935 Title: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing To manage notifications abo

[Bug 1815935] [NEW] Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing

2019-02-14 Thread Iyyappa Murugandi
Public bug reported: Package: rssh Version: 2.3.4-4+deb8u1build0.16.04.1 We are using libssh2(v1.5) client to download files in our product. After rssh got auto patched, our download scenario is broken. This happens only for users that are created with default rssh shell login. Steps to repro:

[Bug 1815741] Re: Probable regression after rssh security update

2019-02-13 Thread Iyyappa Murugandi
Sorry ignore the previous comment. It was meant for the rssh mailing list. Anyways, libssh2 send scp request as "scp -pf ". But rssh has added new validation function which expects the commands to be specified as "-p -f" instead of "-pf". Since it is a regression, I have requested rssh maintainer

[Bug 1815741] Re: Probable regression after rssh security update

2019-02-13 Thread Iyyappa Murugandi
No, 2.3.4-4+deb8u2ubuntu0.16.04.1 release didn't fix the issue. 2.3.4-4+deb8u2ubuntu0.16.04.1 is mainly targeted for downloading multiple files using '*' based on the issue raised by https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=921655. In our case, we don't use scp commands directly but use

[Bug 1815741] [NEW] Probable regression after rssh security update

2019-02-13 Thread Iyyappa Murugandi
Public bug reported: version: v1.5 (or above) Last week rssh package got updated to include security patch (2.3.4-4+deb8u1build0.16.04.1) after which download scenario is broken. This happens only for users that are created with default rssh shell login. Specifically libssh2_scp_recv()/libssh2_s