NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: bin/60512: sshd: hosts.deny and hosts.allow for NetBSD 10 not working for 11



> Date: Tue, 28 Jul 2026 12:20:15 +0200
> From: Martin Husemann <martin%duskware.de@localhost>
> 
> If that change is not acceptable, this needs to be checked by
> postinstall(8). "postinstall check" could just fail with a message
> pointing the admin at what manual fix would work.

That's absurd; the introduction of an internal privilege separation
measure in the implementation of sshd should not reinterpret the
operator's intent!

This was previously discussed at:

https://mail-index.netbsd.org/current-users/2025/01/06/msg045945.html

As a result of that discussion, we updated our local patch for libwrap
support to check _both_ `sshd-session' and `sshd':

https://mail-index.netbsd.org/source-changes/2025/01/08/msg155130.html

    106 #ifdef LIBWRAP
...
    112 static void
    113 check_connection(const char *argv0, int sock_in)
    114 {
    115 	struct request_info req;
    116 
    117 	request_init(&req, RQ_DAEMON, argv0, RQ_FILE, sock_in, 0);
    118 	fromhost(&req);
    119 
    120 	if (hosts_access(&req))
    121 		return;
    122 	debug("Connection refused by tcp wrapper");
    123 	/* n.b. hosts_access(3) has logged and notified blocklistd */
    124 	refuse(&req);
    125 	/* NOTREACHED */
    126 	fatal("libwrap refuse returns");
    127 }
    128 #endif /* LIBWRAP */
...
   1171 #ifdef LIBWRAP
   1172 	/* Check whether logins are denied from this host. */
   1173 	if (ssh_packet_connection_is_on_socket(ssh)) {
   1174 		/* First, try with the value stored in __progname */
   1175 		check_connection(__progname, sock_in);
   1176 		/*
   1177 		 * Test with "sshd" as well, since that is what most people
   1178 		 * will have in their hosts.allow and hosts.deny files.
   1179 		 */
   1180 		check_connection("sshd", sock_in);
   1181 	}
   1182 #endif /* LIBWRAP */

https://nxr.netbsd.org/xref/src/crypto/external/bsd/openssh/dist/sshd-session.c?r=1.13#106

However, I suspect that logic only works for hosts.deny, not for
hosts.allow.

Frankly, I don't think we should use the name sshd-session at all;
it's an internal implementation detail, not the name of the service
users are configuring.  We should just fix openssh to use the name
"sshd" again.



Home | Main Index | Thread Index | Old Index