[openssh-commits] [openssh] 01/02: upstream: make StreamLocalBindMask properly respect Host/Match

git+noreply at mindrot.org git+noreply at mindrot.org
Sat Oct 3 11:02:18 AEST 2026


This is an automated email from the git hooks/post-receive script.

djm pushed a commit to branch master
in repository openssh.

commit bc00e06e0cda509c06b47ee4d1551efc904894a1
Author: djm at openbsd.org <djm at openbsd.org>
AuthorDate: Sat Oct 3 00:46:29 2026 +0000

    upstream: make StreamLocalBindMask properly respect Host/Match
    
    blocks and make it first-match-wins as documented. bz4013
    
    OpenBSD-Commit-ID: e2efc85b42bbf7067ece4f1ab12d7d02ec6c3e12
---
 readconf.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/readconf.c b/readconf.c
index b61755c18..4def155f6 100644
--- a/readconf.c
+++ b/readconf.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: readconf.c,v 1.417 2026/09/16 00:13:58 djm Exp $ */
+/* $OpenBSD: readconf.c,v 1.418 2026/10/03 00:46:29 djm Exp $ */
 /*
  * Author: Tatu Ylonen <ylo at cs.hut.fi>
  * Copyright (c) 1995 Tatu Ylonen <ylo at cs.hut.fi>, Espoo, Finland
@@ -2322,7 +2322,9 @@ parse_pubkey_algos:
 			error("%.200s line %d: Bad mask.", filename, linenum);
 			goto out;
 		}
-		options->fwd_opts.streamlocal_bind_mask = (mode_t)value;
+		if (*activep &&
+		    options->fwd_opts.streamlocal_bind_mask == (mode_t)-1)
+			options->fwd_opts.streamlocal_bind_mask = (mode_t)value;
 		break;
 
 	case oStreamLocalBindUnlink:

-- 
To stop receiving notification emails like this one, please contact
djm at mindrot.org.


More information about the openssh-commits mailing list