[openssh-commits] [openssh] 02/02: remove the --disable-fd-passing configure option

git+noreply at mindrot.org git+noreply at mindrot.org
Tue Oct 6 16:51:39 AEDT 2026


This is an automated email from the git hooks/post-receive script.

djm pushed a commit to branch master
in repository openssh.

commit ac6ad1afd1c3531fad2e96a00c84bd9867cf5561
Author: Damien Miller <djm at mindrot.org>
AuthorDate: Tue Oct 6 16:48:54 2026 +1100

    remove the --disable-fd-passing configure option
    
    Also add a deprecation warning when the lack FD passing support and also
    requires root for the post-auth sshd-session process
---
 configure.ac | 23 +++++++++++++----------
 1 file changed, 13 insertions(+), 10 deletions(-)

diff --git a/configure.ac b/configure.ac
index aa59ba3dd..bb4d065f1 100644
--- a/configure.ac
+++ b/configure.ac
@@ -777,6 +777,7 @@ case "$host" in
 	AC_DEFINE([DISABLE_WTMP], [1], [Define if you don't want to use wtmp])
 	;;
 *-*-cygwin*)
+	is_cygwin=1
 	LIBS="$LIBS /usr/lib/textreadmode.o"
 	AC_DEFINE([HAVE_CYGWIN], [1], [Define if you are on Cygwin])
 	AC_DEFINE([USE_PIPES], [1], [Use PIPES instead of a socketpair()])
@@ -786,6 +787,7 @@ case "$host" in
 		[Define if you want to disable shadow passwords])
 	AC_DEFINE([NO_X11_UNIX_SOCKETS], [1],
 		[Define if X11 doesn't support AF_UNIX sockets on that system])
+	no_fd_passing=1
 	AC_DEFINE([DISABLE_FD_PASSING], [1],
 		[Define if your platform needs to skip post auth
 		file descriptor passing])
@@ -1356,6 +1358,7 @@ if (setsockopt(s, IPPROTO_IP, IP_TOS, &one, sizeof(one)) == -1)
 	AC_DEFINE([USE_PIPES])
 	AC_DEFINE([HAVE_SECUREWARE])
 	AC_DEFINE([DISABLE_SHADOW])
+	no_fd_passing=1
 	AC_DEFINE([DISABLE_FD_PASSING])
 	AC_DEFINE([SETEUID_BREAKS_SETUID])
 	AC_DEFINE([BROKEN_GETADDRINFO])
@@ -1390,6 +1393,7 @@ if (setsockopt(s, IPPROTO_IP, IP_TOS, &one, sizeof(one)) == -1)
 			AC_DEFINE([DISABLE_LOGIN], [1],
 				[Define if you don't want to use your
 				system's login() call])
+			no_fd_passing=1
 			AC_DEFINE([DISABLE_FD_PASSING])
 			LIBS="$LIBS -lsecurity -ldb -lm -laud"
 			SIA_MSG="yes"
@@ -1415,6 +1419,7 @@ if (setsockopt(s, IPPROTO_IP, IP_TOS, &one, sizeof(one)) == -1)
 	enable_etc_default_login=no	# has incompatible /etc/default/login
 	case "$host" in
 	*-*-nto-qnx6*)
+		no_fd_passing=1
 		AC_DEFINE([DISABLE_FD_PASSING])
 		;;
 	esac
@@ -1427,6 +1432,7 @@ if (setsockopt(s, IPPROTO_IP, IP_TOS, &one, sizeof(one)) == -1)
 	AC_DEFINE([DISABLE_UTMPX], [1], [Disable utmpx])
 	# DISABLE_FD_PASSING so that we call setpgrp as root, otherwise we
 	# don't get a controlling tty.
+	no_fd_passing=1
 	AC_DEFINE([DISABLE_FD_PASSING], [1], [Need to call setpgrp as root])
 	# On Ultrix some headers are not protected against multiple includes,
 	# so we create wrappers and put it where the compiler will find it.
@@ -5514,16 +5520,6 @@ AC_DEFINE_UNQUOTED([_PATH_SSH_PIDDIR], ["$piddir"],
 	[Specify location of ssh.pid])
 AC_SUBST([piddir])
 
-
-AC_ARG_ENABLE([fd-passing],
-	[  --disable-fd-passing    disable file descriptor passsing [no]],
-	[
-		if test "x$enableval" = "xno" ; then
-			AC_DEFINE([DISABLE_FD_PASSING])
-		fi
-	]
-)
-
 dnl allow user to disable some login recording features
 AC_ARG_ENABLE([lastlog],
 	[  --disable-lastlog       disable use of lastlog even if detected [no]],
@@ -5938,3 +5934,10 @@ if test "$AUDIT_MODULE" = "bsm" ; then
 	echo "WARNING: BSM audit support is currently considered EXPERIMENTAL."
 	echo "See the Solaris section in README.platform for details."
 fi
+
+if test "x$no_fd_passing" = "x1" -a "x$is_cygwin" != "x1" ; then
+	echo "WARNING: support for platforms that lack file descriptor passing"
+	echo "and that also require root privileges for PTY allocation will be "
+	echo "deprecated in a future OpenSSH release."
+fi
+

-- 
To stop receiving notification emails like this one, please contact
djm at mindrot.org.


More information about the openssh-commits mailing list