2016-05-30 03:36:18 +02:00
|
|
|
# HG changeset patch
|
2017-11-06 15:50:53 +01:00
|
|
|
# Parent e4a7e5799420a3d4b8047c5984c75c4bd4331951
|
2016-07-07 09:07:23 +02:00
|
|
|
# -- uset do be called '-xauthlocalhostname'
|
2016-05-30 03:36:18 +02:00
|
|
|
handle hostname changes when forwarding X
|
2013-09-19 06:09:33 +02:00
|
|
|
|
2016-05-30 03:36:18 +02:00
|
|
|
bnc#98627
|
|
|
|
|
2017-11-06 15:50:53 +01:00
|
|
|
diff --git a/openssh-7.6p1/session.c b/openssh-7.6p1/session.c
|
|
|
|
--- a/openssh-7.6p1/session.c
|
|
|
|
+++ b/openssh-7.6p1/session.c
|
|
|
|
@@ -953,17 +953,17 @@ copy_environment_blacklist(char **source
|
2013-09-19 06:09:33 +02:00
|
|
|
|
2017-11-06 15:50:53 +01:00
|
|
|
void
|
|
|
|
copy_environment(char **source, char ***env, u_int *envsize)
|
|
|
|
{
|
|
|
|
copy_environment_blacklist(source, env, envsize, NULL);
|
2013-09-19 06:09:33 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
static char **
|
2017-11-06 15:50:53 +01:00
|
|
|
-do_setup_env(struct ssh *ssh, Session *s, const char *shell)
|
|
|
|
+do_setup_env(struct ssh *ssh, Session *s, const char *shell, int *env_size)
|
2013-09-19 06:09:33 +02:00
|
|
|
{
|
|
|
|
char buf[256];
|
|
|
|
u_int i, envsize;
|
|
|
|
char **env, *laddr;
|
|
|
|
struct passwd *pw = s->pw;
|
|
|
|
#if !defined (HAVE_LOGIN_CAP) && !defined (HAVE_CYGWIN)
|
|
|
|
char *path = NULL;
|
|
|
|
#endif
|
2017-11-06 15:50:53 +01:00
|
|
|
@@ -1142,25 +1142,27 @@ do_setup_env(struct ssh *ssh, Session *s
|
2013-09-19 06:09:33 +02:00
|
|
|
read_environment_file(&env, &envsize, buf);
|
|
|
|
}
|
|
|
|
if (debug_flag) {
|
|
|
|
/* dump the environment */
|
|
|
|
fprintf(stderr, "Environment:\n");
|
|
|
|
for (i = 0; env[i]; i++)
|
|
|
|
fprintf(stderr, " %.200s\n", env[i]);
|
|
|
|
}
|
|
|
|
+
|
|
|
|
+ *env_size = envsize;
|
|
|
|
return env;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Run $HOME/.ssh/rc, /etc/ssh/sshrc, or xauth (whichever is found
|
|
|
|
* first in this order).
|
|
|
|
*/
|
|
|
|
static void
|
|
|
|
-do_rc_files(Session *s, const char *shell)
|
|
|
|
+do_rc_files(Session *s, const char *shell, char **env, int *env_size)
|
|
|
|
{
|
|
|
|
FILE *f = NULL;
|
|
|
|
char cmd[1024];
|
|
|
|
int do_xauth;
|
|
|
|
struct stat st;
|
|
|
|
|
|
|
|
do_xauth =
|
|
|
|
s->display != NULL && s->auth_proto != NULL && s->auth_data != NULL;
|
2017-11-06 15:50:53 +01:00
|
|
|
@@ -1205,22 +1207,30 @@ do_rc_files(Session *s, const char *shel
|
2013-09-19 06:09:33 +02:00
|
|
|
"%.500s add %.100s %.100s %.100s\n",
|
|
|
|
options.xauth_location, s->auth_display,
|
|
|
|
s->auth_proto, s->auth_data);
|
|
|
|
}
|
|
|
|
snprintf(cmd, sizeof cmd, "%s -q -",
|
|
|
|
options.xauth_location);
|
|
|
|
f = popen(cmd, "w");
|
|
|
|
if (f) {
|
|
|
|
+ char hostname[MAXHOSTNAMELEN];
|
2017-11-06 15:50:53 +01:00
|
|
|
+
|
2013-09-19 06:09:33 +02:00
|
|
|
fprintf(f, "remove %s\n",
|
|
|
|
s->auth_display);
|
|
|
|
fprintf(f, "add %s %s %s\n",
|
|
|
|
s->auth_display, s->auth_proto,
|
|
|
|
s->auth_data);
|
|
|
|
pclose(f);
|
|
|
|
+ if (gethostname(hostname,sizeof(hostname)) >= 0)
|
|
|
|
+ child_set_env(&env,env_size,"XAUTHLOCALHOSTNAME",
|
|
|
|
+ hostname);
|
|
|
|
+ else
|
|
|
|
+ debug("Cannot set up XAUTHLOCALHOSTNAME %s\n",
|
|
|
|
+ strerror(errno));
|
|
|
|
} else {
|
|
|
|
fprintf(stderr, "Could not run %s\n",
|
|
|
|
cmd);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
static void
|
2017-11-06 15:50:53 +01:00
|
|
|
@@ -1461,16 +1471,17 @@ child_close_fds(struct ssh *ssh)
|
2013-09-19 06:09:33 +02:00
|
|
|
* ids, and executing the command or shell.
|
|
|
|
*/
|
|
|
|
#define ARGV_MAX 10
|
|
|
|
void
|
2017-11-06 15:50:53 +01:00
|
|
|
do_child(struct ssh *ssh, Session *s, const char *command)
|
2013-09-19 06:09:33 +02:00
|
|
|
{
|
|
|
|
extern char **environ;
|
|
|
|
char **env;
|
|
|
|
+ int env_size;
|
|
|
|
char *argv[ARGV_MAX];
|
2017-11-06 15:50:53 +01:00
|
|
|
const char *shell, *shell0;
|
2013-09-19 06:09:33 +02:00
|
|
|
struct passwd *pw = s->pw;
|
|
|
|
int r = 0;
|
|
|
|
|
|
|
|
/* remove hostkey from the child's memory */
|
|
|
|
destroy_sensitive_data();
|
2017-11-06 15:50:53 +01:00
|
|
|
packet_clear_keys();
|
|
|
|
@@ -1522,17 +1533,17 @@ do_child(struct ssh *ssh, Session *s, co
|
2013-09-19 06:09:33 +02:00
|
|
|
* legal, and means /bin/sh.
|
|
|
|
*/
|
|
|
|
shell = (pw->pw_shell[0] == '\0') ? _PATH_BSHELL : pw->pw_shell;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Make sure $SHELL points to the shell from the password file,
|
|
|
|
* even if shell is overridden from login.conf
|
|
|
|
*/
|
2017-11-06 15:50:53 +01:00
|
|
|
- env = do_setup_env(ssh, s, shell);
|
|
|
|
+ env = do_setup_env(ssh, s, shell, &env_size);
|
2013-09-19 06:09:33 +02:00
|
|
|
|
|
|
|
#ifdef HAVE_LOGIN_CAP
|
|
|
|
shell = login_getcapstr(lc, "shell", (char *)shell, (char *)shell);
|
|
|
|
#endif
|
|
|
|
|
2017-11-06 15:50:53 +01:00
|
|
|
/*
|
|
|
|
* Close the connection descriptors; note that this is the child, and
|
|
|
|
* the server will still have the socket open, and it is important
|
|
|
|
@@ -1586,17 +1597,17 @@ do_child(struct ssh *ssh, Session *s, co
|
|
|
|
strerror(errno));
|
2016-05-30 03:36:18 +02:00
|
|
|
}
|
2013-09-19 06:09:33 +02:00
|
|
|
if (r)
|
|
|
|
exit(1);
|
|
|
|
}
|
|
|
|
|
|
|
|
closefrom(STDERR_FILENO + 1);
|
|
|
|
|
2017-11-06 15:50:53 +01:00
|
|
|
- do_rc_files(s, shell);
|
|
|
|
+ do_rc_files(s, shell, env, &env_size);
|
2013-09-19 06:09:33 +02:00
|
|
|
|
|
|
|
/* restore SIGPIPE for child */
|
|
|
|
signal(SIGPIPE, SIG_DFL);
|
|
|
|
|
|
|
|
if (s->is_subsystem == SUBSYSTEM_INT_SFTP_ERROR) {
|
|
|
|
printf("This service allows sftp connections only.\n");
|
|
|
|
fflush(NULL);
|
|
|
|
exit(1);
|