[openssh-commits] [openssh] 02/02: remove the --disable-fd-passing configure option
git+noreply at mindrot.org
git+noreply at mindrot.org
Tue Oct 6 16:51:39 AEDT 2026
This is an automated email from the git hooks/post-receive script.
djm pushed a commit to branch master
in repository openssh.
commit ac6ad1afd1c3531fad2e96a00c84bd9867cf5561
Author: Damien Miller <djm at mindrot.org>
AuthorDate: Tue Oct 6 16:48:54 2026 +1100
remove the --disable-fd-passing configure option
Also add a deprecation warning when the lack FD passing support and also
requires root for the post-auth sshd-session process
---
configure.ac | 23 +++++++++++++----------
1 file changed, 13 insertions(+), 10 deletions(-)
diff --git a/configure.ac b/configure.ac
index aa59ba3dd..bb4d065f1 100644
--- a/configure.ac
+++ b/configure.ac
@@ -777,6 +777,7 @@ case "$host" in
AC_DEFINE([DISABLE_WTMP], [1], [Define if you don't want to use wtmp])
;;
*-*-cygwin*)
+ is_cygwin=1
LIBS="$LIBS /usr/lib/textreadmode.o"
AC_DEFINE([HAVE_CYGWIN], [1], [Define if you are on Cygwin])
AC_DEFINE([USE_PIPES], [1], [Use PIPES instead of a socketpair()])
@@ -786,6 +787,7 @@ case "$host" in
[Define if you want to disable shadow passwords])
AC_DEFINE([NO_X11_UNIX_SOCKETS], [1],
[Define if X11 doesn't support AF_UNIX sockets on that system])
+ no_fd_passing=1
AC_DEFINE([DISABLE_FD_PASSING], [1],
[Define if your platform needs to skip post auth
file descriptor passing])
@@ -1356,6 +1358,7 @@ if (setsockopt(s, IPPROTO_IP, IP_TOS, &one, sizeof(one)) == -1)
AC_DEFINE([USE_PIPES])
AC_DEFINE([HAVE_SECUREWARE])
AC_DEFINE([DISABLE_SHADOW])
+ no_fd_passing=1
AC_DEFINE([DISABLE_FD_PASSING])
AC_DEFINE([SETEUID_BREAKS_SETUID])
AC_DEFINE([BROKEN_GETADDRINFO])
@@ -1390,6 +1393,7 @@ if (setsockopt(s, IPPROTO_IP, IP_TOS, &one, sizeof(one)) == -1)
AC_DEFINE([DISABLE_LOGIN], [1],
[Define if you don't want to use your
system's login() call])
+ no_fd_passing=1
AC_DEFINE([DISABLE_FD_PASSING])
LIBS="$LIBS -lsecurity -ldb -lm -laud"
SIA_MSG="yes"
@@ -1415,6 +1419,7 @@ if (setsockopt(s, IPPROTO_IP, IP_TOS, &one, sizeof(one)) == -1)
enable_etc_default_login=no # has incompatible /etc/default/login
case "$host" in
*-*-nto-qnx6*)
+ no_fd_passing=1
AC_DEFINE([DISABLE_FD_PASSING])
;;
esac
@@ -1427,6 +1432,7 @@ if (setsockopt(s, IPPROTO_IP, IP_TOS, &one, sizeof(one)) == -1)
AC_DEFINE([DISABLE_UTMPX], [1], [Disable utmpx])
# DISABLE_FD_PASSING so that we call setpgrp as root, otherwise we
# don't get a controlling tty.
+ no_fd_passing=1
AC_DEFINE([DISABLE_FD_PASSING], [1], [Need to call setpgrp as root])
# On Ultrix some headers are not protected against multiple includes,
# so we create wrappers and put it where the compiler will find it.
@@ -5514,16 +5520,6 @@ AC_DEFINE_UNQUOTED([_PATH_SSH_PIDDIR], ["$piddir"],
[Specify location of ssh.pid])
AC_SUBST([piddir])
-
-AC_ARG_ENABLE([fd-passing],
- [ --disable-fd-passing disable file descriptor passsing [no]],
- [
- if test "x$enableval" = "xno" ; then
- AC_DEFINE([DISABLE_FD_PASSING])
- fi
- ]
-)
-
dnl allow user to disable some login recording features
AC_ARG_ENABLE([lastlog],
[ --disable-lastlog disable use of lastlog even if detected [no]],
@@ -5938,3 +5934,10 @@ if test "$AUDIT_MODULE" = "bsm" ; then
echo "WARNING: BSM audit support is currently considered EXPERIMENTAL."
echo "See the Solaris section in README.platform for details."
fi
+
+if test "x$no_fd_passing" = "x1" -a "x$is_cygwin" != "x1" ; then
+ echo "WARNING: support for platforms that lack file descriptor passing"
+ echo "and that also require root privileges for PTY allocation will be "
+ echo "deprecated in a future OpenSSH release."
+fi
+
--
To stop receiving notification emails like this one, please contact
djm at mindrot.org.
More information about the openssh-commits
mailing list