diff --git a/openssh.changes b/openssh.changes index 8a37f61..ae740c5 100644 --- a/openssh.changes +++ b/openssh.changes @@ -1,3 +1,9 @@ +------------------------------------------------------------------- +Fri Oct 19 13:22:10 UTC 2018 - Tomáš Chvátal + +- Mention upstream bugs on multiple local patches +- Adjust service to not spam restart and reload only on fails + ------------------------------------------------------------------- Fri Oct 19 13:11:34 UTC 2018 - Tomáš Chvátal diff --git a/openssh.spec b/openssh.spec index 9a5a614..f2106df 100644 --- a/openssh.spec +++ b/openssh.spec @@ -64,25 +64,32 @@ Patch8: openssh-7.7p1-remove_xauth_cookies_on_exit.patch Patch9: openssh-7.7p1-pts_names_formatting.patch Patch10: openssh-7.7p1-pam_check_locks.patch Patch11: openssh-7.7p1-disable_short_DH_parameters.patch +# https://bugzilla.mindrot.org/show_bug.cgi?id=2752 Patch14: openssh-7.7p1-seccomp_stat.patch +# https://bugzilla.mindrot.org/show_bug.cgi?id=2752 Patch15: openssh-7.7p1-seccomp_ipc_flock.patch +# https://bugzilla.mindrot.org/show_bug.cgi?id=2752 Patch16: openssh-7.7p1-seccomp_ioctl_s390_EP11.patch Patch17: openssh-7.7p1-fips.patch Patch18: openssh-7.7p1-cavstest-ctr.patch Patch19: openssh-7.7p1-cavstest-kdf.patch Patch20: openssh-7.7p1-fips_checks.patch Patch21: openssh-7.7p1-seed-prng.patch +# https://bugzilla.mindrot.org/show_bug.cgi?id=2641 Patch22: openssh-7.7p1-systemd-notify.patch Patch23: openssh-7.7p1-gssapi_key_exchange.patch Patch24: openssh-7.7p1-audit.patch Patch25: openssh-7.7p1-openssl_1.1.0.patch Patch26: openssh-7.7p1-disable_openssl_abi_check.patch +# https://bugzilla.mindrot.org/show_bug.cgi?id=2641 Patch27: openssh-7.7p1-no_fork-no_pid_file.patch Patch28: openssh-7.7p1-host_ident.patch # https://bugzilla.mindrot.org/show_bug.cgi?id=1844 Patch29: openssh-7.7p1-sftp_force_permissions.patch +# https://bugzilla.mindrot.org/show_bug.cgi?id=2143 Patch30: openssh-7.7p1-X_forward_with_disabled_ipv6.patch Patch31: openssh-7.7p1-ldap.patch +# https://bugzilla.mindrot.org/show_bug.cgi?id=2213 Patch32: openssh-7.7p1-IPv6_X_forwarding.patch Patch33: openssh-7.7p1-sftp_print_diagnostic_messages.patch BuildRequires: audit-devel diff --git a/sshd.service b/sshd.service index 1a5cfbd..783df8c 100644 --- a/sshd.service +++ b/sshd.service @@ -10,7 +10,8 @@ ExecStartPre=/usr/sbin/sshd -t $SSHD_OPTS ExecStart=/usr/sbin/sshd -D $SSHD_OPTS ExecReload=/bin/kill -HUP $MAINPID KillMode=process -Restart=always +Restart=on-failure +RestartPreventExitStatus=255 TasksMax=infinity [Install]