[openssh-commits] [openssh] 01/02: disable features when post-auth sshd runs as root
git+noreply at mindrot.org
git+noreply at mindrot.org
Tue Oct 6 16:51:38 AEDT 2026
This is an automated email from the git hooks/post-receive script.
djm pushed a commit to branch master
in repository openssh.
commit b37c095aa39bb2c01754673dec50a684a536db24
Author: Damien Miller <djm at mindrot.org>
AuthorDate: Tue Oct 6 16:43:39 2026 +1100
disable features when post-auth sshd runs as root
On platforms that require root privilege for the post-authentication
sshd-session process (e.g. OpenServer 5, QNX 6), disable and restrict
a number of features that assume user privilege.
This includes GatewayPorts, StreamLocalForwarding and -R forwardings
binding to ports <1024
---
channels.c | 8 ++++++++
defines.h | 16 ++++++++++++++++
servconf.c | 12 ++++++++++++
sshd-session.c | 20 +++-----------------
4 files changed, 39 insertions(+), 17 deletions(-)
diff --git a/channels.c b/channels.c
index ad380dbe4..abae44b92 100644
--- a/channels.c
+++ b/channels.c
@@ -4344,6 +4344,14 @@ check_rfwd_permission(struct ssh *ssh, struct Forward *fwd)
u_int i, permit, permit_adm = 1;
struct permission *perm;
+#ifdef SKIP_PRIVDROP
+ if (fwd->listen_path != NULL)
+ return 0;
+ if (allowed_open->listen_port != FWD_PERMIT_ANY_PORT &&
+ allowed_open->listen_port < 1024)
+ return 0;
+#endif
+
/* XXX apply GatewayPorts override before checking? */
permit = pset->all_permitted;
diff --git a/defines.h b/defines.h
index 634db453e..c0b9ad549 100644
--- a/defines.h
+++ b/defines.h
@@ -1007,4 +1007,20 @@ struct winsize {
# endif
#endif
+/*
+ * Hack for systems that don't support FD passing: retain privileges
+ * in the post-auth privsep process so it can allocate PTYs directly.
+ *
+ * Instead of doing what we did <= 9.7, which was to disable post-auth
+ * privsep entirely, we run with temporarily_use_uid, restoring root
+ * only to allocate ptys or in the child to permanently change UID.
+ *
+ * Cygwin doesn't need to drop privs here although it doesn't support
+ * fd passing, as AFAIK PTY allocation on this platform doesn't require
+ * special privileges to begin with.
+ */
+#if defined(DISABLE_FD_PASSING) && !defined(HAVE_CYGWIN)
+# define SKIP_PRIVDROP 1
+#endif
+
#endif /* _DEFINES_H */
diff --git a/servconf.c b/servconf.c
index b49e9e97c..044043b74 100644
--- a/servconf.c
+++ b/servconf.c
@@ -273,6 +273,18 @@ fill_default_server_options(ServerOptions *options)
{
u_int i;
+ /* Portable-specific overrides */
+#ifdef SKIP_PRIVDROP
+ if (options->allow_streamlocal_forwarding != -1 &&
+ options->allow_streamlocal_forwarding != FORWARD_DENY)
+ logit("StreamlocalForwarding is not supported on this system");
+ options->allow_streamlocal_forwarding = 0;
+ if (options->fwd_opts.gateway_ports != -1 &&
+ options->fwd_opts.gateway_ports == 0)
+ logit("GatewayPorts is not supported on this system");
+ options->fwd_opts.gateway_ports = 0;
+#endif
+
#define SSHCONF_INT(var, conf, flags, ms, def, cp) \
if (options->var == -1) \
options->var = def;
diff --git a/sshd-session.c b/sshd-session.c
index 7d7bbb40d..1af9bcf4c 100644
--- a/sshd-session.c
+++ b/sshd-session.c
@@ -371,21 +371,6 @@ privsep_preauth(struct ssh *ssh)
static void
privsep_postauth(struct ssh *ssh, Authctxt *authctxt)
{
- int skip_privdrop = 0;
-
- /*
- * Hack for systems that don't support FD passing: retain privileges
- * in the post-auth privsep process so it can allocate PTYs directly.
- * This is basically equivalent to what we did <= 9.7, which was to
- * disable post-auth privsep entirely.
- * Cygwin doesn't need to drop privs here although it doesn't support
- * fd passing, as AFAIK PTY allocation on this platform doesn't require
- * special privileges to begin with.
- */
-#if defined(DISABLE_FD_PASSING) && !defined(HAVE_CYGWIN)
- skip_privdrop = 1;
-#endif
-
/* New socket pair */
monitor_reinit(pmonitor);
@@ -412,9 +397,10 @@ privsep_postauth(struct ssh *ssh, Authctxt *authctxt)
reseed_prngs();
+#ifndef SKIP_PRIVDROP
/* Drop privileges */
- if (!skip_privdrop)
- do_setusercontext(authctxt->pw);
+ do_setusercontext(authctxt->pw);
+#endif
/* It is safe now to apply the key state */
monitor_apply_keystate(ssh, pmonitor);
--
To stop receiving notification emails like this one, please contact
djm at mindrot.org.
More information about the openssh-commits
mailing list