From patchwork Wed Oct 7 05:48:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: auh@yoctoproject.org X-Patchwork-Id: 100112 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C20F0CA600A for ; Wed, 7 Oct 2026 05:48:44 +0000 (UTC) Received: from a27-30.smtp-out.us-west-2.amazonses.com (a27-30.smtp-out.us-west-2.amazonses.com [54.240.27.30]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1963.1791352117646477275 for ; Tue, 06 Oct 2026 22:48:37 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@yoctoproject.org header.s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky header.b=Mw6Nt/FR; dkim=pass header.i=@amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=myrwfQrX; spf=pass (domain: us-west-2.amazonses.com, ip: 54.240.27.30, mailfrom: 010101a114e815c4-560ef97e-2584-4203-9106-010ff21ad1eb-000000@us-west-2.amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky; d=yoctoproject.org; t=1791352116; h=Content-Type:MIME-Version:From:To:Subject:Message-Id:Date; bh=6UVsLyULZr25m/02G1hT9ziqrAOpYt7JBzlcGUvgv+M=; b=Mw6Nt/FRH7Oj3DPdGV1jAMOivLbyRXDtSMkf2u9G7X7CtG0ZEjjei2da9o2xyV9L uD1XRXTwOxAzAVAO2SkgmPXYjXacLjzcx9k0RDW92CdfbExfu3OI4y3AuVmT4Q7EYek YA4ukskQ1waoyw3xwdd2d+UZ8iNcXJQi4EFpHO2w= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=hsbnp7p3ensaochzwyq5wwmceodymuwv; d=amazonses.com; t=1791352116; h=Content-Type:MIME-Version:From:To:Subject:Message-Id:Date:Feedback-ID; bh=6UVsLyULZr25m/02G1hT9ziqrAOpYt7JBzlcGUvgv+M=; b=myrwfQrXQCw3yl/Myy6lfi1oE1CO2pyAUqhLvbKQ2wORacHIwqxMo2heFx76eLZu GH7Cq/XGGSyBiOFZRcCwnqK3e8/64gEgA/+KqWJnqZ1iC6hBUaUMsgkiaElUgTeldPz xVrMzs1O6L27qCeNynHopGju8aNPv7OwsR/+5bYo= MIME-Version: 1.0 From: auh@yoctoproject.org To: openembedded-core@lists.openembedded.org Subject: [AUH] openssh: upgrading to 10.6p1 SUCCEEDED Message-ID: <010101a114e815c4-560ef97e-2584-4203-9106-010ff21ad1eb-000000@us-west-2.amazonses.com> Date: Wed, 7 Oct 2026 05:48:36 +0000 Feedback-ID: ::1.us-west-2.9np3MYPs3fEaOBysGKSlUD4KtcmPijcmS9Az2Hwf7iQ=:AmazonSES X-SES-Outgoing: 2026.10.07-54.240.27.30 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 07 Oct 2026 05:48:44 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247360 Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe(s) *openssh* to *10.6p1* has Succeeded. Next steps: - apply the patch: git am 0001-openssh-upgrade-10.5p1-10.6p1.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From dae49ade37fafe4dd27d3aec3d3fc39fe4ef6ad2 Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Wed, 7 Oct 2026 05:22:35 +0000 Subject: [PATCH] openssh: upgrade 10.5p1 -> 10.6p1 .depend update RPM spec files upstream: openssh-10.6 upstream: Add test for proxycommand percent expansions. upstream: backout regress bits related to multiplexing change remove the --disable-fd-passing configure option disable features when post-auth sshd runs as root Don't automatically enable FORTIFY_SOURCE. upstream: Further restrict the characters allowed in a command-line Remove NetBSD 9.0 test target. Replace native ARM runner with remote runner. Pull older NetBSD sudo package from archive. upstream: make StreamLocalBindMask properly first-match-wins; upstream: make StreamLocalBindMask properly respect Host/Match upstream: start process of deprecating the -R flag. This was the upstream: mention default KDF rounds is now 32 upstream: Implement a maximum number of KDF rounds that will be upstream: fix the bit length of ML-DSA 44/Ed25519 keys that was upstream: sftp: be stricter in accepting paths returned by the upstream: handle max-pk-ok path identically when the incoming user upstream: Disallow nul byte in received scp -O filename. Not upstream: backout upstream: Check that compressed payloads don't inflate beyond the upstream: ssh-agent: no unlink(2) on empty filename upstream: ssh-agent: fix socket cleanup for -a option (no pathspec) upstream: Disable LZ77 dictionary coder to avoid a potential upstream: check ssh's handling of stale multiplexing sockets From Jens upstream: avoid race between multiple processes attempting to upstream: Include local and remote versions in ~I connection info. Remove the NetBSD BROKEN_READ_COMPARISON workaround. Ignore build/install status of netcat in tests. Add FreeBSD 15 test targets. upstream: Better wording. upstream: use Nm instead of Xr to self Don't deref NULL on STREAMS tty alloc failure. upstream: Plug leak. CID 913600. upstream: an abbreviation ending in a dot at EOL requires escaping upstream: tweak 1.406: minor wording and markup OK djm@ upstream: draft-ietf-sshm-ssh-agent became RFC 9987 ok dtucker@ Remove leftover from testing. Add fallback for mkdir_path() without openat(). upstream: Use >= instead of > for max comparison so that the upstream: Use equality not assignment in ternary. CID 913600. upstream: spelling; ok deraadt@ Also skip scp3 test on Darwin 26 and 27. upstream: convert channel timeouts to use floating points, allows upstream: masking signals requried sigaddset, not sigdelset; bz3981 upstream: bz3635 - ssh-add -P to skip PIN entry upstream: simpler upstream: leaks on error paths; spotted by Coverity CID 913598 upstream: fix inverted logic that could cause a memleak; spotted en upstream: Add missing semicolon after return. CID 913599, ok upstream: correctly check sshauthopt->restricted merging unbreak readpassphrase.c sync sync readpassphrase(3) with OpenBSD libc upstream: whitespace upstream: adapt to libsodium ed25519 implementation upstream: missing part of previous commit: update script to upstream: switch from SUPERCOP ed25519 to libsodium upstream: Only store GSSAPI creds when authn succeeds upstream: Reset GSSAPI client state before authentication upstream: Correctly handle some options that accept "none" upstream: Propagate authorized_keys "resrict" keyword upstream: Check key and CA sig type during key parsing upstream: Add WarnWeakCrypto to sshd upstream: Allow specification of agent socket directories upstream: Account pubkey checks separately to auth attempts upstream: Extend TCPKeepAlive to support forwardings too upstream: Mask SIGTERM/SIGQUIT when processing a SIGHUP restart fix merge botch that put lines in wrong function upstream: Correct handling of DST when converting dates upstream: sk-usbhid: preserve UV requirement for resident keys upstream: Fix memory leak on an error path in mkdir_path upstream: sftp: don't crash when glob(3) results lack stat information openpty: mark inputs const upstream: replace testing of vendor PQ signature algorithm upstream: minor leak of fingerprint text when printing upstream: the default KDF rounds for keys generated by ssh-keygen Don't link sshd against libselinux upstream: warnings fixes (static vs missing prototype, sign conversion) sshd doesn't need sshpty.c any more upstream: wrap line upstream: g/c prototype upstream: disconnect_controlling_tty() is the only thing from sshpty.c upstream: Fix ChannelTimeout specificity allow madvise(..., MADV_DONTNEED_LOCKED) upstream: fix case for ssh -G option output; bz4005, reported by upstream: mux proxy sockets also share in and out fds, so using upstream: don't attempt to set TCP_NODELAY on non-AF_INET[6] upstream: add a "hexdump" export mode that dumps the key blob in upstream: Add '-p' to sftp mkdir/lmkdir to create directories as upstream: Use getexecpath(3); if it fails use argv[0] as before upstream: Change three paragraphs in different parts of the manual upstream: update fingerprint example from RSA to Ed25519 host key upstream: Remove scp '-s' flag from synopsis, the flag has been a set -Wno-error=discarded-qualifiers seccomp sandbox: [Changelog truncated as it exceeds 5000 characters; the full changelog can be found in an attachment to the AUH email] --- ...1-regress-banner.sh-log-input-and-output-files-on-erro.patch | 2 +- .../openssh/{openssh_10.5p1.bb => openssh_10.6p1.bb} | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) rename meta/recipes-connectivity/openssh/{openssh_10.5p1.bb => openssh_10.6p1.bb} (99%) diff --git a/meta/recipes-connectivity/openssh/openssh/0001-regress-banner.sh-log-input-and-output-files-on-erro.patch b/meta/recipes-connectivity/openssh/openssh/0001-regress-banner.sh-log-input-and-output-files-on-erro.patch index f424288e37..aa25f09537 100644 --- a/meta/recipes-connectivity/openssh/openssh/0001-regress-banner.sh-log-input-and-output-files-on-erro.patch +++ b/meta/recipes-connectivity/openssh/openssh/0001-regress-banner.sh-log-input-and-output-files-on-erro.patch @@ -1,4 +1,4 @@ -From 5cc897fe2effe549e1e280c2f606bce8b532b61e Mon Sep 17 00:00:00 2001 +From af460c6fc73213c41a498dc15f72e6e64f2342f1 Mon Sep 17 00:00:00 2001 From: Mikko Rapeli Date: Mon, 11 Sep 2023 09:55:21 +0100 Subject: [PATCH] regress/banner.sh: log input and output files on error diff --git a/meta/recipes-connectivity/openssh/openssh_10.5p1.bb b/meta/recipes-connectivity/openssh/openssh_10.6p1.bb similarity index 99% rename from meta/recipes-connectivity/openssh/openssh_10.5p1.bb rename to meta/recipes-connectivity/openssh/openssh_10.6p1.bb index 052686f289..6043f140b3 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.5p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.6p1.bb @@ -25,7 +25,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://sshd_check_keys \ file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \ " -SRC_URI[sha256sum] = "d44d28a839ea9daf969cc69150fde59910b2b39361dad81a3bd6cbd19218db11" +SRC_URI[sha256sum] = "a9dc9565dffe8640f64d863cd29a32bc4a3dbdec0566a7fc44c5d6ee767d5f39" CVE_STATUS[CVE-2007-2768] = "not-applicable-config: This CVE is specific to OpenSSH with the pam opie which we don't build/use here."