[openssh-commits] [openssh] 02/03: upstream: When using a combination of a Yubikey+GnuPG+remote

git+noreply at mindrot.org git+noreply at mindrot.org
Tue Jul 30 15:06:34 AEST 2019


This is an automated email from the git hooks/post-receive script.

djm pushed a commit to branch master
in repository openssh.

commit 7adf6c430d6fc17901e167bc0789d31638f5c2f8
Author: mestre at openbsd.org <mestre at openbsd.org>
Date:   Wed Jul 24 08:57:00 2019 +0000

    upstream: When using a combination of a Yubikey+GnuPG+remote
    
    forwarding the gpg-agent (and options ControlMaster+RemoteForward in
    ssh_config(5)) then the codepath taken will call mux_client_request_session
    -> mm_send_fd -> sendmsg(2). Since sendmsg(2) is not allowed in that codepath
    then pledge(2) kills the process.
    
    The solution is to add "sendfd" to pledge(2), which is not too bad considering
    a little bit later we reduce pledge(2) to only "stdio proc tty" in that
    codepath.
    
    Problem reported and diff provided by Timothy Brown <tbrown at freeshell.org>
    
    OK deraadt@
    
    OpenBSD-Commit-ID: 7ce38b6542bbec00e441595d0a178e970a9472ac
---
 clientloop.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/clientloop.c b/clientloop.c
index 7f32871f..b5a1f703 100644
--- a/clientloop.c
+++ b/clientloop.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: clientloop.c,v 1.326 2019/06/28 13:35:04 deraadt Exp $ */
+/* $OpenBSD: clientloop.c,v 1.327 2019/07/24 08:57:00 mestre Exp $ */
 /*
  * Author: Tatu Ylonen <ylo at cs.hut.fi>
  * Copyright (c) 1995 Tatu Ylonen <ylo at cs.hut.fi>, Espoo, Finland
@@ -1251,7 +1251,7 @@ client_loop(struct ssh *ssh, int have_pty, int escape_char_arg,
 	if (options.control_master &&
 	    !option_clear_or_none(options.control_path)) {
 		debug("pledge: id");
-		if (pledge("stdio rpath wpath cpath unix inet dns recvfd proc exec id tty",
+		if (pledge("stdio rpath wpath cpath unix inet dns recvfd sendfd proc exec id tty",
 		    NULL) == -1)
 			fatal("%s pledge(): %s", __func__, strerror(errno));
 

-- 
To stop receiving notification emails like this one, please contact
djm at mindrot.org.


More information about the openssh-commits mailing list