diff mbox series

[AUH] openssh: upgrading to 10.6p1 SUCCEEDED

Message ID 010101a114e815c4-560ef97e-2584-4203-9106-010ff21ad1eb-000000@us-west-2.amazonses.com
State New
Headers show
Series [AUH] openssh: upgrading to 10.6p1 SUCCEEDED | expand

Commit Message

auh@yoctoproject.org Oct. 7, 2026, 5:48 a.m. UTC
Hello,

this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe(s) *openssh* to *10.6p1* has Succeeded.

Next steps:
    - apply the patch: git am 0001-openssh-upgrade-10.5p1-10.6p1.patch
    - check the changes to upstream patches and summarize them in the commit message,
    - compile an image that contains the package
    - perform some basic sanity tests
    - amend the patch and sign it off: git commit -s --reset-author --amend
    - send it to the appropriate mailing list

Alternatively, if you believe the recipe should not be upgraded at this time,
you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that
automatic upgrades would no longer be attempted.

Please review the attached files for further information and build/update failures.
Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler

Regards,
The Upgrade Helper

-- >8 --
From dae49ade37fafe4dd27d3aec3d3fc39fe4ef6ad2 Mon Sep 17 00:00:00 2001
From: Upgrade Helper <auh@yoctoproject.org>
Date: Wed, 7 Oct 2026 05:22:35 +0000
Subject: [PATCH] openssh: upgrade 10.5p1 -> 10.6p1

.depend
update RPM spec files
upstream: openssh-10.6
upstream: Add test for proxycommand percent expansions.
upstream: backout regress bits related to multiplexing change
remove the --disable-fd-passing configure option
disable features when post-auth sshd runs as root
Don't automatically enable FORTIFY_SOURCE.
upstream: Further restrict the characters allowed in a command-line
Remove NetBSD 9.0 test target.
Replace native ARM runner with remote runner.
Pull older NetBSD sudo package from archive.
upstream: make StreamLocalBindMask properly first-match-wins;
upstream: make StreamLocalBindMask properly respect Host/Match
upstream: start process of deprecating the -R flag. This was the
upstream: mention default KDF rounds is now 32
upstream: Implement a maximum number of KDF rounds that will be
upstream: fix the bit length of ML-DSA 44/Ed25519 keys that was
upstream: sftp: be stricter in accepting paths returned by the
upstream: handle max-pk-ok path identically when the incoming user
upstream: Disallow nul byte in received scp -O filename. Not
upstream: backout
upstream: Check that compressed payloads don't inflate beyond the
upstream: ssh-agent: no unlink(2) on empty filename
upstream: ssh-agent: fix socket cleanup for -a option (no pathspec)
upstream: Disable LZ77 dictionary coder to avoid a potential
upstream: check ssh's handling of stale multiplexing sockets From Jens
upstream: avoid race between multiple processes attempting to
upstream: Include local and remote versions in ~I connection info.
Remove the NetBSD BROKEN_READ_COMPARISON workaround.
Ignore build/install status of netcat in tests.
Add FreeBSD 15 test targets.
upstream: Better wording.
upstream: use Nm instead of Xr to self
Don't deref NULL on STREAMS tty alloc failure.
upstream: Plug leak. CID 913600.
upstream: an abbreviation ending in a dot at EOL requires escaping
upstream: tweak 1.406: minor wording and markup OK djm@
upstream: draft-ietf-sshm-ssh-agent became RFC 9987 ok dtucker@
Remove leftover from testing.
Add fallback for mkdir_path() without openat().
upstream: Use >= instead of > for max comparison so that the
upstream: Use equality not assignment in ternary. CID 913600.
upstream: spelling; ok deraadt@
Also skip scp3 test on Darwin 26 and 27.
upstream: convert channel timeouts to use floating points, allows
upstream: masking signals requried sigaddset, not sigdelset; bz3981
upstream: bz3635 - ssh-add -P to skip PIN entry
upstream: simpler
upstream: leaks on error paths; spotted by Coverity CID 913598
upstream: fix inverted logic that could cause a memleak; spotted en
upstream: Add missing semicolon after return. CID 913599, ok
upstream: correctly check sshauthopt->restricted merging
unbreak readpassphrase.c sync
sync readpassphrase(3) with OpenBSD libc
upstream: whitespace
upstream: adapt to libsodium ed25519 implementation
upstream: missing part of previous commit: update script to
upstream: switch from SUPERCOP ed25519 to libsodium
upstream: Only store GSSAPI creds when authn succeeds
upstream: Reset GSSAPI client state before authentication
upstream: Correctly handle some options that accept "none"
upstream: Propagate authorized_keys "resrict" keyword
upstream: Check key and CA sig type during key parsing
upstream: Add WarnWeakCrypto to sshd
upstream: Allow specification of agent socket directories
upstream: Account pubkey checks separately to auth attempts
upstream: Extend TCPKeepAlive to support forwardings too
upstream: Mask SIGTERM/SIGQUIT when processing a SIGHUP restart
fix merge botch that put lines in wrong function
upstream: Correct handling of DST when converting dates
upstream: sk-usbhid: preserve UV requirement for resident keys
upstream: Fix memory leak on an error path in mkdir_path
upstream: sftp: don't crash when glob(3) results lack stat information
openpty: mark inputs const
upstream: replace testing of vendor PQ signature algorithm
upstream: minor leak of fingerprint text when printing
upstream: the default KDF rounds for keys generated by ssh-keygen
Don't link sshd against libselinux
upstream: warnings fixes (static vs missing prototype, sign conversion)
sshd doesn't need sshpty.c any more
upstream: wrap line
upstream: g/c prototype
upstream: disconnect_controlling_tty() is the only thing from sshpty.c
upstream: Fix ChannelTimeout specificity
allow madvise(..., MADV_DONTNEED_LOCKED)
upstream: fix case for ssh -G option output; bz4005, reported by
upstream: mux proxy sockets also share in and out fds, so using
upstream: don't attempt to set TCP_NODELAY on non-AF_INET[6]
upstream: add a "hexdump" export mode that dumps the key blob in
upstream: Add '-p' to sftp mkdir/lmkdir to create directories as
upstream: Use getexecpath(3); if it fails use argv[0] as before
upstream: Change three paragraphs in different parts of the manual
upstream: update fingerprint example from RSA to Ed25519 host key
upstream: Remove scp '-s' flag from synopsis, the flag has been a
set -Wno-error=discarded-qualifiers
seccomp sandbox:

[Changelog truncated as it exceeds 5000 characters;
the full changelog can be found in an attachment to the AUH email]
---
 ...1-regress-banner.sh-log-input-and-output-files-on-erro.patch | 2 +-
 .../openssh/{openssh_10.5p1.bb => openssh_10.6p1.bb}            | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)
 rename meta/recipes-connectivity/openssh/{openssh_10.5p1.bb => openssh_10.6p1.bb} (99%)
diff mbox series

Patch

diff --git a/meta/recipes-connectivity/openssh/openssh/0001-regress-banner.sh-log-input-and-output-files-on-erro.patch b/meta/recipes-connectivity/openssh/openssh/0001-regress-banner.sh-log-input-and-output-files-on-erro.patch
index f424288e37..aa25f09537 100644
--- a/meta/recipes-connectivity/openssh/openssh/0001-regress-banner.sh-log-input-and-output-files-on-erro.patch
+++ b/meta/recipes-connectivity/openssh/openssh/0001-regress-banner.sh-log-input-and-output-files-on-erro.patch
@@ -1,4 +1,4 @@ 
-From 5cc897fe2effe549e1e280c2f606bce8b532b61e Mon Sep 17 00:00:00 2001
+From af460c6fc73213c41a498dc15f72e6e64f2342f1 Mon Sep 17 00:00:00 2001
 From: Mikko Rapeli <mikko.rapeli@linaro.org>
 Date: Mon, 11 Sep 2023 09:55:21 +0100
 Subject: [PATCH] regress/banner.sh: log input and output files on error
diff --git a/meta/recipes-connectivity/openssh/openssh_10.5p1.bb b/meta/recipes-connectivity/openssh/openssh_10.6p1.bb
similarity index 99%
rename from meta/recipes-connectivity/openssh/openssh_10.5p1.bb
rename to meta/recipes-connectivity/openssh/openssh_10.6p1.bb
index 052686f289..6043f140b3 100644
--- a/meta/recipes-connectivity/openssh/openssh_10.5p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_10.6p1.bb
@@ -25,7 +25,7 @@  SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta
            file://sshd_check_keys \
            file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \
            "
-SRC_URI[sha256sum] = "d44d28a839ea9daf969cc69150fde59910b2b39361dad81a3bd6cbd19218db11"
+SRC_URI[sha256sum] = "a9dc9565dffe8640f64d863cd29a32bc4a3dbdec0566a7fc44c5d6ee767d5f39"
 
 CVE_STATUS[CVE-2007-2768] = "not-applicable-config: This CVE is specific to OpenSSH with the pam opie which we don't build/use here."