ChangeLog 177 KB
Newer Older
Niels Möller's avatar
Niels Möller committed
1
2
3
4
5
6
7
2003-05-19  Niels Mller  <nisse@cuckoo.hack.org>

	* src/unix_user.c (do_read_file): Set the process gid, and reset
	the supplimentary groups list, before opening the file.

	* configure.ac: Check for seteuid and setresuid.

Niels Möller's avatar
Niels Möller committed
8
9
10
11
12
13
14
15
2003-05-16  Niels Mller  <niels@s3.kth.se>

	* configure.ac: Check for struct utmp.ut_exit.e_termination and
	struct utmpx.ut_exit.e_termination.

	* src/unix_process.c (do_utmp_cleanup): Fix for HPUX, which uses
	non-standard names for the fields of struct utmpx's ut_exit.

Niels Möller's avatar
Niels Möller committed
16
17
18
19
20
2003-05-14  Niels Mller  <niels@s3.kth.se>

	* src/io.c (io_resolv_address): More fixes for the non getaddrinfo
	code.

Niels Möller's avatar
Niels Möller committed
21
22
23
24
25
26
27
2003-05-14  Niels Mller  <nisse@cuckoo.hack.org>

	* src/unix_interact.c (unix_interact): New attribute password_fd.
	(unix_read_password): Read password from password_fd, unless it's
	-1. 
	(make_unix_interact): Initialize password_fd to -1.

Niels Möller's avatar
Niels Möller committed
28
29
30
31
32
2003-05-13  Niels Mller  <nisse@cuckoo.hack.org>

	* src/io.c (io_resolv_address): Fixes for the non getaddrinfo
	code. 

Niels Möller's avatar
Niels Möller committed
33
34
35
36
37
38
39
2003-05-13  Niels Mller  <niels@s3.kth.se>

	* acinclude.m4 (LSH_FUNC_STRSIGNAL): Use a dummy STRSIGNAL if none
	of strsignal, sys_siglist or _sys_siglist exists.

	* src/io.c (lsh_popen_read): Use STRSIGNAL macro.

40
41
2003-05-12  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
42
43
	* src/crypto.h (FOR_BLOCKS): Deleted unused macro.

Niels Möller's avatar
Niels Möller committed
44
45
46
47
48
49
	* src/lsh-execuv.c: Don't include lsh_types.h.
	* src/lsh-krb-checkpw.c: Likewise.

	* src/lsh.c (do_lsh_lookup): Fix syntax of generated ACL entries
	(bug 1030).

Niels Möller's avatar
Niels Möller committed
50
51
52
53
54
55
	* misc/make-am (environ_deps): Deleted code for generating
	.dist_deps. 

	* src/.dist_headers: Deleted memxor.h and lsh_types.h. 
	* src/.dist_headers, src/.dist_classes: Deleted proxy-related
	files. 
Niels Möller's avatar
Niels Möller committed
56

57
58
59
	* configure.ac: Updated AC_CONFIG_SRCDIR, as lsh_types.h no longer
	exists. 

Niels Möller's avatar
Niels Möller committed
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
2003-05-12  Niels Mller  <niels@s3.kth.se>

	* configure.ac: Don't AC_REPLACE_FUNCS(memxor), just use the
	memxor function in nettle.

	* doc/HACKING: Documented current include file ordering rules.

	* src/lsh.h (MAX, MIN, SQR, STRING_LINE): Moved miscellaneous
	macros here. Used to be in lsh_types.h.

	* Reordered includes in most or all .c-files. All should now
	include config.h.

	* src/lsh_types.h: Deleted file.
	* src/.dist_deps: Deleted file.
	* src/memxor.h, src/memxor.c: Deleted files.

	* src/Makefile.am (BUILT_SOURCES): Use BUILT_SOURCES to get
	environ.h built. .dist_deps no longer needed.

	* acinclude.m4 (LSH_GCC_FUNCTION_NAME, LSH_FUNC_ALLOCA) 
	(LSH_FUNC_STRERROR, LSH_FUNC_STRSIGNAL): New macros.
	* configure.ac: Use them.

84
85
86
87
88
2003-05-12  Pontus Skld  <pont@soua.net>

	* src/lsh-upgrade: Upgrade any authorized public keys and
	re-authorize them.

Niels Möller's avatar
Niels Möller committed
89
90
91
92
93
94
95
2003-04-23  Niels Mller  <niels@s3.kth.se>

	* src/Makefile.am (gcov-list): Don't include files with full code
	coverage in the list.

	* src/testsuite/Makefile.am (TS_SH): Added
	tcpip-local-in-use-test. 
Niels Möller's avatar
Niels Möller committed
96
97
	
2003-04-22  Niels Mller  <niels@s3.kth.se>
Niels Möller's avatar
Niels Möller committed
98

Niels Möller's avatar
Niels Möller committed
99
100
101
102
103
104
	* src/tcpforward_commands.c (forward_local_port): Use prog1 to
	delay bind call until the connection is established.

	* src/testsuite/tcpip-local-in-use-test: New test case, to check
	the error handling for "address already in use".

Niels Möller's avatar
Niels Möller committed
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
	* src/unix_user.c (exec_shell): Build the argument list for
	lsh-execuv only if we need to change uid. Include the name of the
	exec:ed program if exec fails.

	* src/lsh.c (main): Use addr_queue instead of sockaddr_list.
	* src/lshd.c: Likewise.

	* src/io_commands.c (connect_list_command): Take a
	connect_list_state as argument.

	* src/io.h (connect_list_state): Moved class definition to the
	header file.

	* src/io.c (sockaddr_cons): Deleted function.
	(io_resolv_address) Use addr_queue instead of sockaddr_list.
	(io_listen_list): Likewise.
	(connect_attempt): Likewise.
	(make_connect_list_state): Made non-static.
	(connect_list_callback): Moved c and e attributes here, from
	connect_list_state.
	(io_connect_list): Take a connect_list_state as argument.

	* src/queue.c (make_addr_queue_node): Initialize the size field. 

	* src/queue.h (struct lsh_queue): Added length field.

	* src/queue.c: New queue type addr_queue, for handling lists of
	sockaddr:esses. Let lsh_queue keep track of the length.

	* src/lsh.c (do_lsh_lookup): Deleted old code handling the
	ssh-rsa-pkcs1@lysator.liu.se algorithm id.

Niels Möller's avatar
Niels Möller committed
137
138
139
140
141
142
143
144
2003-04-22  Niels Mller  <nisse@cuckoo.hack.org>

	* src/lsh.c (lsh_verifier_command): Deleted command.
	(make_lsh_login): New function, replacing lsh_login_command.
	(make_lsh_userauth): Deleted GABA-expression.
	(make_lsh_connect): Take a login command as a parameter.
	(main): Updated calls to make_lsh_connect and make_lsh_login.

Niels Möller's avatar
Niels Möller committed
145
146
147
2003-04-21  Niels Mller  <nisse@cuckoo.hack.org>

	* src/lsh.c (make_lsh_connect): Take actions as a parameter.
Niels Möller's avatar
Niels Möller committed
148
149
150
151
152
153
154
155
156
	(options2service): Deleted command.
	(lsh_options): Deleted service attribute. Always ask for the
	userauth service.
	(make_lsh_userauth): Deleted expression.
	(make_lsh_connect): Take keys as parameter. Always ask for
	userauth service.
	(main): Deleted call of make_lsh_userauth. Pass keys to
	make_lsh_connect instead.

Niels Möller's avatar
Niels Möller committed
157
158
159
160
161
162
163
164
	* src/lshg.c (make_lshg_connect): Likewise.

	* src/gateway.c: Include string.h.

	* src/client.c (client_options2actions): Deleted command.

	* src/io.c (make_address_info_c): Deleted function.

Niels Möller's avatar
Niels Möller committed
165
166
2003-04-20  Niels Mller  <niels@s3.kth.se>

Niels Möller's avatar
Niels Möller committed
167
	* src/spki.c (make_ssh_hostkey_tag): Use a plain NUL-terminated
Niels Möller's avatar
Niels Möller committed
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
	string to identify the host.
	(spki_pkcs5_decrypt): Fixed string leak. The label string wasn't
	freed properly on failure.

	* src/lshd.c (do_exc_lshd_handler): It seems we need an exception
	handler after all, which catches and logs i/o errors.

	* src/lsh.c (options2identities): Deleted command.
	(lsh_host_db): Use a NUL-terminated string to identify the host.
	(do_lsh_lookup): Likewise.
	(make_lsh_host_db): Likewise.
	(make_lsh_userauth): Take keys as a parameter. Don't use
	options2identities. 
	(make_lsh_connect): Take options as a parameter, and the remote
	address list as argument. Use connect_list.
	(main): Call io_resolv_address, read_known_hosts, read_user_keys
	and make_lsh_userauth here.

	* src/io_commands.c (connect_list_command): New command.

	* src/io.c (do_connect_list_callback): Update fd->label.

	* src/handshake.c (handshake_command): Allow a NULL lv->peer.

	* src/gateway.c (make_gateway_address): Take a plain
	NUL-termianted string to identify the target.

	* src/client.c (client_options2remote): Deleted command.
	(client_argp_parser): Don't call make_address_info_c.

	* src/client.h (client_options): Replaced remote attribute with a
	plain NUL-termianted string, and renamed to target.
	* src/lshg.c: Updated for the struct client_options renaming
	remote->target. 

	* src/testsuite/functions.sh (spawn_lshd): Reduced sleep.

Niels Möller's avatar
Niels Möller committed
205
206
2003-04-16  Niels Mller  <niels@s3.kth.se>

Niels Möller's avatar
Niels Möller committed
207
208
209
	* src/lshd.c (main): No need to check for make_lshd_options
	returnning NULL.

Niels Möller's avatar
Niels Möller committed
210
211
212
213
214
	* src/.dist_classes (dist_classes): Deleted io_commands.h.x.
	* src/io_commands.h (io_write_file_info): Deleted class.
	* src/io_commands.c (io_write_file_command) 
	(make_io_write_file_info): Deleted unused functions.

Niels Möller's avatar
Niels Möller committed
215
216
217
218
219
220
221
222
	* src/lshd.c (do_exc_lshd_handler, make_lshd_exception_handler):
	Deleted functions.

	* src/exception.h (EXC_RANDOMNESS_LOW_ENTROPY, EXC_APP): Deleted
	unused exceptions.

	* src/io.c (io_read_file): Deleted unused function.

Niels Möller's avatar
Niels Möller committed
223
224
225
226
227
228
229
	* src/testsuite/functions.sh (spawn_lshd): Check exit code from
	lshd. Print out the lshd pid.
	(spawn_lsh): Print out the lsh pid.

	* src/Makefile.am (gcov-list): New target for running gcov.

	* src/io_commands.c (listen_list_command): Deleted command.
Niels Möller's avatar
Niels Möller committed
230
	Replaced by the io_listen_list function.
Niels Möller's avatar
Niels Möller committed
231

Niels Möller's avatar
Niels Möller committed
232
	* src/lshd.c (options2local, options2keys, options2tcp_wrapper)
Niels Möller's avatar
Niels Möller committed
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
	(close_on_sighup): Deleted commands.

	* src/keyexchange.c (kexinit_filter): Deleted command.

	* src/lshd.c (main): Reorganization, do more work before the work,
	including reading host keys and binding sockets directly in main.
	Moved the daemonization later, so that the forground process
	doesn't exit until after the ports are bound.

	Fixed an fd leak in the server tcpip-forwarding code.
	* src/tcpforward.c (do_tcpip_forward_request_continuation): Use
	remember_resource to associate the bound fd to the connection.
	(make_tcpip_forward_request_continuation): New argument,
	connection. 
	(do_tcpip_forward_request): Pass the connection to
	make_tcpip_forward_request_continuation.

	* src/io.c (io_listen_list): New function.

Niels Möller's avatar
Niels Möller committed
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
2003-04-15  Niels Mller  <niels@s3.kth.se>

	* src/testsuite/functions.sh (spawn_lshd): Use -HUP, not -9, for
	killing lshd.

	* src/werror.c (fatal) [WITH_GCOV]: Call fork, so that we can
	call exit() and also dump core.

	* src/server.c (read_host_key): Fixed string leak.

	* src/io.c (make_connect_callback): Made non-static.
	(io_connect): Changed interface, to take an io_callback instead of
	a continuation. The caller has to use make_connect_callback to get
	the old functionality.
	(io_connect_local): Adapted to new io_conenct interface, and call
	make_connect_list_callback. 
	* src/client_x11.c (channel_open_x11): Likewise.
	* src/io_commands.c (do_connect): Likewise.

	* src/io.c (connect_list_state): New class.
	(do_connect_list_kill): New function.
	(make_connect_list_state): New function.
	(connect_attempt): New function.
	(connect_list_callback): New class.
	(do_connect_list_callback): New function.
	(make_connect_list_callback): New function.
	(io_connect_list): New function. 

	* src/io.h (sockaddr_list): Renamed attribute, addr -> address.

	* configure.ac: New option --enable-profiling.

	* src/.gdbinit: New file.

Niels Möller's avatar
Niels Möller committed
286
287
288
289
290
291
292
293
294
295
2003-04-14  Niels Mller  <nisse@cuckoo.hack.org>

	* src/io.c (io_resolv_address): Changed interface, to avoid local
	conversion of service names to port numbers. This way, all that's
	needed for SRV-records is proper support in getaddrinfo.

	* src/lshd.c (parse_interface): Changed interface to use plain
	NUL-terminated strings.
	(main_argp_parser): Updated for new io_resolv_address interface.

Niels Möller's avatar
Niels Möller committed
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
2003-04-14  Niels Mller  <niels@s3.kth.se>

	* src/testsuite/functions.sh: Use INTERFACE=localhost, as we now
	support non-numerical interface names.
	(spawn_lshd): Must put -p option before --interface.

	* src/lshd.c (parse_interface): New function.
	(main_argp_parser): Implemented multiple --interface options.
	(make_lshd_listen): Use listen_list, to list on severala ddresses
	in parallel. Don't use the bind command.

	* src/io.c (io_resolv_address): Changed return type, now returns
	the number of resolved addresses.

	* doc/lsh.texinfo (Invoking lshd): Document the use of multiple
	--interface options.

Niels Möller's avatar
Niels Möller committed
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
2003-04-13  Niels Mller  <nisse@cuckoo.hack.org>

	* src/testsuite/Makefile.am (EXTRA_PROGRAMS): Added testutils, as
	a kludge to get automake to track dependencies for testutils.o.

	* src/io_commands.c (listen_list_command): New command.

	* src/io.h (sockaddr_list): New class.

	* src/io.c (io_resolv_address): New function.
	(sockaddr_cons): New function. 

	* src/client_session.c (make_client_session_channel): Added place
	holder for send break escape handler (#if:ed out for now)

Niels Möller's avatar
Niels Möller committed
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
2003-04-11  Niels Mller  <niels@s3.kth.se>

	* src/client_pty.c (do_kill_client_tty_resource): Call
	set_error_raw. 
	(do_pty_continuation): Likewise.

	* src/client_escape.c (escape_help): New class.
	(do_escape_help): Escape function that lists all defined escapes. 
	(make_escape_help): New function.
	(make_escape_info): Install help.
	(escape_dispatch): Updated to use the escape_callback type.

	* src/client.c: Use DEFINE_ESCAPE.
	* src/suspend.c (suspend_callback): Likewise.

	* src/client.h (escape_callback): New class, which inherits
	lsh_callback and adds a help string.
	(class escape_info): Use it.
	(DEFINE_ESCAPE): New macro.

	* src/werror.c (set_error_raw): New function, for telling the
	werror functions when the tty is set to raw mode.
	(werror_putc): In raw mode, add a \r before each \n.
	(werror_write_raw): Renamed the old werror_write function.
	(werror_write): New function that inserts \r in the output when
	approrpriate.

	* src/Makefile.am (MAINTAINERCLEANFILES, class-map): Updated to
	use dist_classes, not dist_x_files.

Pontus Freyhult's avatar
Pontus Freyhult committed
358
359
360
361
362
363
364
365
366
2003-03-24  Pontus Skld  <pont@soua.net>

	* contrib/solpkg.sh.in: Added my script to create Solaris
	packages.

	* contrib/Makefile.am: Include script in EXTRA_DIST

	* configure.ac: Added hooks for Solaris package script. 

Niels Möller's avatar
Niels Möller committed
367
368
369
370
371
372
373
374
375
376
377
378
2003-03-14  Niels Mller  <nisse@cuckoo.hack.org>

	* src/io.c (handle_nonblock_error): New function, ignoring ENODEV
	errors. Needed for freebsd, where setting the non-block flag on
	/dev/null fails. 
	(io_set_nonblocking, io_set_blocking): Use handle_nonblock_error.

2003-03-13  Niels Mller  <nisse@cuckoo.hack.org>

	* src/io.c (io_set_nonblocking, io_set_blocking) 
	(io_set_close_on_exec): Fixed error messages.

379
380
381
382
383
384
385
386
387
2003-03-05  Niels Mller  <nisse@cuckoo.hack.org>

	* configure.ac: Bumped version to 1.5.2.

	* src/testsuite/Makefile.am (LDADD): Use DOTDOT_LIBARGP, instead
	of the GNU make specific addprefix function.

	* configure.ac (DOTDOT_LIBARGP): New substitution

Niels Möller's avatar
Niels Möller committed
388
389
390
391
392
393
394
395
2003-03-04  Niels Mller  <nisse@cuckoo.hack.org>

	* misc/xenofarm.sh (make): Don't use -k flag, it seems to mask
	errors. 

	* src/Makefile.am (environ.h): Avoid requiring GNU make for this
	rule. 

Niels Möller's avatar
Niels Möller committed
396
397
398
399
400
401
2003-03-02  Niels Mller  <nisse@cuckoo.hack.org>

	* src/unix_random.c: Include <sys/time.h> before <sys/resource.h>. 

	* src/io.c: Include <sys/wait.h>, not <wait.h>.

Niels Möller's avatar
Niels Möller committed
402
403
404
405
2003-03-01  Niels Mller  <nisse@cuckoo.hack.org>

	* src/lsh-upgrade: Note that we need to upgrade private keys too. 

Niels Möller's avatar
Niels Möller committed
406
407
2003-02-28  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
408
409
	* Released lsh-1.5.1.
	
Niels Möller's avatar
Niels Möller committed
410
411
412
	* src/spki.c (spki_pkcs5_decrypt): Typo fix, it's
	"password-encrypted", not "password_encrypted".

Niels Möller's avatar
Niels Möller committed
413
414
415
416
417
2003-02-27  Niels Mller  <nisse@cuckoo.hack.org>

	* src/testsuite/rapid7-lsh-test: ln -sf is not portable, so delete
	the symlink "current" explicitly using rm.

Niels Möller's avatar
Niels Möller committed
418
419
420
421
422
2003-02-27  Niels Mller  <niels@s3.kth.se>

	* src/testsuite/rapid7-lsh-test: Skip test if tcputils is missing.
	* src/testsuite/rapid7-lshd-test: Likewise.	

Niels Möller's avatar
Niels Möller committed
423
424
425
426
427
428
2003-02-27  Niels Mller  <nisse@cuckoo.hack.org>

	* src/testsuite/rapid7-lshd-test: Use $srdir for locating the test
	pdu:s. 
	* src/testsuite/rapid7-lsh-test: Likewise.

Niels Möller's avatar
Niels Möller committed
429
430
431
432
433
434
435
436
2003-02-26  Niels Mller  <nisse@cuckoo.hack.org>

	* src/testsuite/rapid7-lsh-test: Bugfixes, and some adaption to
	the lsh testsuite framework.
	* src/testsuite/rapid7-lshd-test: Likewise.

	* src/testsuite/functions.sh (werror, die): New functions.

437
438
439
440
2003-02-26  Pontus Skld  <pont@soua.net>

	* src/lsh-krb-checkpw.c: Include config.h if available.

Niels Möller's avatar
Niels Möller committed
441
442
2003-02-25  Niels Mller  <niels@s3.kth.se>

Niels Möller's avatar
Niels Möller committed
443
444
	* src/testsuite/Makefile.am (AM_CPPFLAGS): Use $(srcdir)/..

Niels Möller's avatar
Niels Möller committed
445
446
	* src/testsuite/.dist_rapid7: Typo fix.

Niels Möller's avatar
Niels Möller committed
447
448
449
450
2003-02-25  Niels Mller  <nisse@cuckoo.hack.org>

	* src/rsync/Makefile.am (AM_CPPFLAGS): Use $(srcdir)/..

Niels Möller's avatar
Niels Möller committed
451
452
2003-02-24  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
453
454
455
456
457
458
459
460
461
	* src/testsuite/Makefile.am (TS_SH): Added rapid-7-lsh-test and
	rapid-7-lshd-test.
	(EXTRA_DIST): Use $(dist_rapid7), and include .dist_rapid7 which
	defines it. 

	* src/testsuite/.dist_rapid7: New file, listing rapid7 files.

	* rapid7-ssh-pdu: New directory, containing rapid7's testsuite.

462
463
	* configure.ac: Bumped version to 1.5.1.

Niels Möller's avatar
Niels Möller committed
464
465
466
467
468
469
470
	* src/rsync/Makefile.am: Use AM_CPPFLAGS = -I.. to get include
	files in the main src directory.
	* src/testsuite/Makefile.am: Likewise.

	* configure.ac: Use AC_GNU_SOURCE. Don't add -I$srcdir/src -DLSH
	to CPPFLAGS.

Niels Möller's avatar
Niels Möller committed
471
472
473
	* src/lsh.c (read_known_hosts): Fixed the message about old
	known_hosts files.

Niels Möller's avatar
Niels Möller committed
474
475
476
477
478
479
480
481
482
483
484
2003-02-23  Niels Moller  <nisse@carduelis>

	* src/scm/gaba.scm (main): Simplified. Explicitly use echo,
	otherwise scsh-0.6 seems to return a non-zero exit code.

	* acinclude.m4 (LSH_GCC_ATTRIBUTES): New macro, copied from lsh's
	configure.ac. 
	* configure.ac: Use it.

	* .bootstrap: Link acinclude.m4 to argp and sftp subdirectories.

485
486
2003-02-19  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
487
488
489
490
491
492
493
494
495
496
497
	* src/nettle/acinclude.m4, src/spki/acinclude.m4: Deleted files,
	let .bootstrap make links to the top-level acinclude.m4 instead.

	* acinclude.m4: Renamed macros to start with the LSH_-prfix.
	Deleted unused code. Updated configure.ac to match.
	(LSH_TYPE_SOCKLEN_T): Moved AH_TEMPLATE into the macro body.

	* .bootstrap: Link acinclude.m4 into the src/nettle and src/spki
	directories. Added command line option "links", that skips the
	autoconf and automake bootstrap.

498
499
500
501
502
	* misc/Makefile.am (EXTRA_DIST): Removed bootstrap.sh. Added
	make-am. 

	* Makefile.am (EXTRA_DIST): Added .bootstrap.

503
	* doc/Makefile.am (EXTRA_DIST): Don't distribute Makefile.am.in.
Niels Möller's avatar
Niels Möller committed
504
505
506
	(%.txt): Resurrected the rule for building txt from nroff. Needed
	for srp-spec.txt.

507
508
	* src/Makefile.am (EXTRA_DIST): Likewise.

509
510
	* .bootstrap: New link from src/nettle/examples and
	src/sftp/testsuite to run-tests.
511

Niels Möller's avatar
Niels Möller committed
512
513
2003-02-18  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
514
515
516
517
518
519
	* src/Makefile.am (bootstrap): Bootstrap the spki dirctory too.
	(EXTRA_DIST): dist_x_files and cvs_headers renamed to dist_classes
	and dist_headers.

	* doc/Makefile.am (EXTRA_DIST): Deleted man_MANS.

Niels Möller's avatar
Niels Möller committed
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
	* misc/bootstrap.sh: Deleted old bootstrap file.

	* src/.dist_classes, src/.dist_headers: Reformatted so that they
	can be included directly in the Makefile.

	* src/.dist_deps: Dependencies on environ.h.

	* misc/run-tests: Moved testsuite driver here, and symlink it from
	all directories that need it.

	* misc/make-am: New script, for generating the files
	src/.dist_headers, src/.dist_classes and src/.dist_deps. Replaces
	* make_am, src/used_headers, src/cvs_headers: Deleted files.

	* .bootstrap: Bugfixes.
	
	* Makefile.am.in: Removed all these files. Use plain Makefile.am
	instead. 

539
540
541
2003-02-18  Niels Mller  <niels@s3.kth.se>

	* configure.ac: Added check for inet_ntop in -lnsl.
542
543
	Check for -lnsl before checking for -lsocket, to avoid strange
	confusion with Solaris' library dependencies.
544

Niels Möller's avatar
Niels Möller committed
545
546
547
548
2003-02-17  Niels Mller  <nisse@cuckoo.hack.org>

	* misc/xenofarm.sh: Fixed make --version test.

Niels Möller's avatar
Niels Möller committed
549
550
551
2003-02-17  Niels Mller  <niels@s3.kth.se>

	* misc/xenofarm.sh: Make sure PATH is exported.
Niels Möller's avatar
Niels Möller committed
552
	Redirect stderr output from make --version.
Niels Möller's avatar
Niels Möller committed
553

Niels Möller's avatar
Niels Möller committed
554
555
2003-02-17  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
556
	* src/testsuite/testutils.c: Use uint32_t and friends, not UINT32.
Niels Möller's avatar
Niels Möller committed
557

Niels Möller's avatar
Niels Möller committed
558
559
	* misc/xenofarm.sh (cfgwarn): Fixed sed expression.

560
561
2003-02-16  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
562
563
564
	* src/.dist_classes: Deleted read_base64.c.x.
	* src/.dist_headers: Deleted digits.h

Niels Möller's avatar
Niels Möller committed
565
566
	* src/debug.c (send_debug, send_verbose): Deleted unused funtions.

567
568
569
570
571
572
573
574
575
576
577
578
579
580
	* .bootstrap: New file, to replace misc/bootstrap.sh.

	* General cleanup. Use types uint32_t and friends instead of
	UINT32. Include files in the order config.h, C headers, system
	headers, lsh headers. Deleted RCS id strings. Affects most files.

	* src/digits.h, src/read_base64.c: Deleted obsolete file.
	
	* src/Makefile.am.in (liblsh_a_SOURCES): Removed read_base64.c. 

	* configure.ac: Added missing LSH_RPATH_FIX between the checks for
	gmp and liboop.
	Use AH_BOTTOM to define NORETURN, PRINTF_STYLE and UNUSED.

Niels Möller's avatar
Niels Möller committed
581
582
2003-02-15  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
583
584
585
586
587
588
589
590
	* src/io.h (lsh_fd): Deleted old hanged_up attribute.
	* src/gateway_commands.c (gateway_setup_command): Deleted old
	#if:ed out command.
	* src/format.c (ssh_vformat_length): Deleted some old #if:ed out
	code. 
	* src/io.c (do_buffered_read): Likewise.
	* src/xalloc.c (lsh_object_free): Likewise.
	* src/proxy.c (do_proxy_offer_service): Likewise.
Niels Möller's avatar
Niels Möller committed
591
592
593
	* src/io_commands.h: Deleted old prototypes make_listen_local and
	make_connect_local. 

Niels Möller's avatar
Niels Möller committed
594
595
596
597
2003-02-14  Niels Mller  <niels@s3.kth.se>

	* src/Makefile.am.in (bin_SCRIPTS): Added lsh-upgrade.

598
599
2003-02-12  Niels Mller  <niels@s3.kth.se>

Niels Möller's avatar
Niels Möller committed
600
601
	* src/unix_user.c (do_spawn): Added FIXME on error reporting.

602
603
604
	* misc/xenofarm.sh (cfgwarn): Delete warning about using an
	absolute path for srcdir.

Niels Möller's avatar
Niels Möller committed
605
606
607
608
2003-02-11  Niels Mller  <niels@s3.kth.se>

	* misc/xenofarm.sh: Compile with make -k.

Niels Möller's avatar
Niels Möller committed
609
610
2003-02-10  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
611
612
	* src/.dist_classes: Deleted lsh_proxy.c.x and sexp-conv.c.x.

Niels Möller's avatar
Niels Möller committed
613
614
615
616
617
618
619
	* src/dsa.c (do_dsa_sign): Use tokens in format string to
	lsh_sexp_format. 
	* src/dsa_keygen.c (dsa_generate_key): Likewise.
	* src/lsh.c (do_lsh_lookup): Likewise.
	* src/srp_exchange.c (srp_make_verifier): Likewise.
	* src/rsa_keygen.c (rsa_generate_key): Likewise.
	* src/rsa.c (do_rsa_public_spki_key): Likewise.
Niels Möller's avatar
Niels Möller committed
620
621
	* src/spki.c (spki_pkcs5_encrypt, make_ssh_hostkey_tag) 
	(spki_hash_data): Likewise.
Niels Möller's avatar
Niels Möller committed
622
623
624
625

	* src/sexp-conv.c, src/sexp_test.c: Deleted file, not used
	anymore.

Niels Möller's avatar
Niels Möller committed
626
627
	* misc/xenofarm.sh: Collect config.h files from subdirectories. 

Niels Möller's avatar
Niels Möller committed
628
629
630
631
632
633
634
635
636
637
638
2003-02-09  Niels Mller  <nisse@cuckoo.hack.org>

	* src/testsuite/Makefile.am (TS_PROGS): Added sockaddr2info-test.

	* src/testsuite/testutils.h: Include io.h.

	* src/testsuite/sockaddr2info-test.c: New test case.

	* src/io.c (sockaddr2info): Use inet_ntop for formatting AF_INET6
	addresses.

Niels Möller's avatar
Niels Möller committed
639
640
641
642
643
644
645
2003-02-07  Niels Mller  <nisse@cuckoo.hack.org>

	* src/lsh.c (do_lsh_lookup): The public key should be wrapped in a
	subject expression in the generated acl:s.

	* src/io.c (sockaddr2info): #ifed out broken IPv6 code.

Niels Möller's avatar
Niels Möller committed
646
647
2003-02-06  Niels Mller  <niels@s3.kth.se>

Niels Möller's avatar
Niels Möller committed
648
649
	* src/Makefile.am.in (DISTCLEANFILES): Delete environ.h.

Niels Möller's avatar
Niels Möller committed
650
651
652
653
654
	* src/testsuite/conv-3-test: Updated test for current sexp-conv. 

	* misc/xenofarm.sh: Try to add /usr/local/bin and /usr/ccs/bin to
	PATH, if needed.

Niels Möller's avatar
Niels Möller committed
655
656
657
658
659
660
661
662
663
664
665
2003-02-05  Niels Mller  <nisse@cuckoo.hack.org>

	* src/keyexchange.c (KEXINIT_MAX_ALGORITMS_SUN): New constant.
	(parse_kexinit): Added argument peer_flag. Use larger list limit
	than parsing the language lists from Sun's sshd.
	(do_handle_kexinit): Updated call to parse_kexinit.

	* src/handshake.c: Added workaround for "Sun_SSH_1.0".

	* src/connection.h: New constant PEER_KEXINIT_LANGUAGE_KLUDGE.

Niels Möller's avatar
Niels Möller committed
666
667
668
669
2003-02-04  Niels Mller  <nisse@cuckoo.hack.org>

	* Moved argp-related entries from this file to src/argp/ChangeLog. 

Niels Möller's avatar
Niels Möller committed
670
671
672
673
674
675
676
2003-01-27  Niels Mller  <nisse@cuckoo.hack.org>

	* src/rsa_keygen.c, src/rsa.c: Updated for nettle rsa renaming.

	* configure.ac: Fixed syntax error when testing $x_includes and
	$x_libraries.

Niels Möller's avatar
Niels Möller committed
677
678
2003-01-24  Niels Mller  <nisse@cuckoo.hack.org>

679
680
681
	* configure.ac: --with-lib-path should add to LDFLAGS, not replace
	it. 

Niels Möller's avatar
Niels Möller committed
682
683
684
685
	* misc/xenofarm.sh (dotask cfg): Pass --with-include-path and
	--with-lib-path to configure. On some systems /usr/local/lib and
	/usr/local/include are not searched by default.

Niels Möller's avatar
Niels Möller committed
686
687
688
689
690
691
2003-01-22  Niels Mller  <nisse@cuckoo.hack.org>

	* src/spki.c (spki_add_acl): Use spki_acl_process.
	(spki_authorize): Adapted to changed spki_acl_by_subject_first and
	spki_acl_by_subject_next. 

Niels Möller's avatar
Niels Möller committed
692
693
694
695
696
2003-01-21  Niels Mller  <niels@s3.kth.se>

	* misc/xenofarm.sh: Don't run make distcheck, as it leaves some
	write-protected directories in the tree. 

Niels Möller's avatar
Niels Möller committed
697
698
2003-01-20  Niels Mller  <niels@s3.kth.se>

Niels Möller's avatar
Niels Möller committed
699
700
701
	* misc/xenofarm.sh: Dont cd into src before running make check and
	make distcheck.

Niels Möller's avatar
Niels Möller committed
702
703
	* src/testsuite/functions.sh (need_tcputils): Use test_skip.

Niels Möller's avatar
Niels Möller committed
704
705
	* misc/xenofarm.sh (timeecho): Fixed typo.

Niels Möller's avatar
Niels Möller committed
706
707
708
709
710
711
712
713
2003-01-19  Niels Mller  <nisse@cuckoo.hack.org>

	* misc/xenofarm.sh (timeecho): Set LC_ALL=C before calling date.

	* src/testsuite/functions.sh (need_tcputils): New function. Use it
	in the testcases that depend on tcputils: tcpip-local-test,
	tcpip-remote-test, lshg-tcpip-test and ssh1-fallback-test.

Niels Möller's avatar
Niels Möller committed
714
715
716
717
718
719
2003-01-17  Niels Mller  <niels@s3.kth.se>

	* src/Makefile.am.in: Added explicit dependencies for objects
	depending on environ.h. Must figure out some better way to do
	that. 

Niels Möller's avatar
Niels Möller committed
720
721
2003-01-16  Niels Mller  <niels@s3.kth.se>

Niels Möller's avatar
Niels Möller committed
722
	* src/Makefile.am.in (EXTRA_DIST): Added environ.h.in.
Niels Möller's avatar
Niels Möller committed
723
724
	(generated_sources): Don't list environ.h here, as it's system
	dependent. 
Niels Möller's avatar
Niels Möller committed
725

Niels Möller's avatar
Niels Möller committed
726
727
	* misc/xenofarm.sh: Fixed invocation of dotask, which should take
	four arguments. 
Niels Möller's avatar
Niels Möller committed
728
	(dotask): Don't create $task.pass, they're not used anymore.
Niels Möller's avatar
Niels Möller committed
729

Niels Möller's avatar
Niels Möller committed
730
731
732
733
734
2003-01-15  Niels Mller  <nisse@cuckoo.hack.org>

	* misc/xenofarm.sh: Updated to use new format for reporting the
	result. 

Niels Möller's avatar
Niels Möller committed
735
736
737
738
739
740
741
2003-01-14  Niels Mller  <nisse@lysator.liu.se>

	* src/.dist_classes: sexp.h.x has disappeared.

	* misc/bootstrap.sh: Bootstrap spki subdir. Removed redundant
	automake calls. 

Niels Möller's avatar
Niels Möller committed
742
743
2003-01-14  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
744
745
746
	* misc/xenofarm.sh: New file.
	Added build instructions, following the lyskom-server example. 
	
Niels Möller's avatar
Niels Möller committed
747
748
749
	* src/.dist_classes: hmac.c.x, md5.c.x and sha.c.x have
	disappeared. 

Niels Möller's avatar
Niels Möller committed
750
751
752
753
754
755
756
757
758
759
760
761
762
2003-01-14  Niels Mller  <nisse@lysator.liu.se>

	* configure.ac (AC_PATH_X): Check not only $no_x, also check if
	$x_includes and $x_libraries are empty before adding new flags.

	* src/scm/gaba.scm (nth): New function. The elisp/Common
	Lisp/MACLisp style function, which takes the index as the first
	argument. 
	(make-output): Updated call of nth.

	* src/scm/guile-compat.scm (nth): Deleted function. Needed for
	scsh, not just guile.

Niels Möller's avatar
Niels Möller committed
763
764
765
766
767
2003-01-14  Niels Mller  <nisse@cuckoo.hack.org>

	* src/.dist_classes: sexp.c.x and spki.c.x have disappeared.
	* src/.dist_headers: dsa.h has disappeared.

Niels Möller's avatar
Niels Möller committed
768
769
770
771
772
2003-01-13  Niels Mller  <nisse@cuckoo.hack.org>

	* src/.dist_headers, src/.dist_classes: Check into cvs, to make it
	easier for xenofarm to build a distribution directly from cvs.

Niels Möller's avatar
Niels Möller committed
773
774
2003-01-13  Niels Mller  <nisse@lysator.liu.se>

Niels Möller's avatar
Niels Möller committed
775
776
777
	* src/scm/compiler.scm (let-and): Fixed syntax error in
	syntax-rules.  

Niels Möller's avatar
Niels Möller committed
778
779
	* misc/bootstrap.sh: Use plain automake -a, no extra arguments.

Niels Möller's avatar
Niels Möller committed
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
2003-01-12  Niels Mller  <nisse@cuckoo.hack.org>

	* src/unix_user.c: Use macros in environ.h, when defining
	environment veriables. 


	* src/lshd.c: Use PATH_KERBEROS_HELPER, defined in environ.h.

	* src/environ.h.in: Define a bunch of PATH_* and ENV_* constants. 

	* src/client.c: Include environ.h, and use those macros for all
	getenv calls.
	* src/client_pty.c: Likewise.
	* src/gateway.c: Likewise.
	* src/lsh-keygen.c: Likewise.
	* src/lsh-make-seed.c: Likewise.
	* src/lsh-writekey.c: Likewise.
	* src/lsh.c: Likewise.
	* src/server_session.c: Likewise.
	* src/server_x11.c: Likewise.
	* src/srp-gen.c: Likewise.
	* src/unix_random.c: Likewise.
	* src/xauth.c: Likewise.

	* src/Makefile.am.in (environ.h): Fixed commands.
	(generated_sources): Added environ.h.

	* doc/lsh.texinfo (Files and environment variables): Document
	POSIXLY_CORRECT. 

	* configure.ac: Don't try AC_DEFINE:ing PREFIX and SBINDIR. Those
	substitutions are now performed at make-time.

Niels Möller's avatar
Niels Möller committed
813
814
815
816
817
818
2003-01-10  Niels Mller  <nisse@cuckoo.hack.org>

	* src/lsh.c (read_known_hosts): Display upgrade message only if
	the --host-db option wasn't used.
	Changed user messages to say "host-acls" instead of "known_hosts". 

Niels Möller's avatar
Niels Möller committed
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
2003-01-10  Niels Mller  <niels@s3.kth.se>

	* src/lsh-upgrade: New shell script.

	* src/testsuite/testutils.c (test_spki_match): Rewrote to use the
	new spki functions. Always fail on parse errors.

	* src/testsuite/spki-tag-test.c (test_main): Include the leading
	"(tag ..." in the tested expressions.

	* src/testsuite/Makefile.am (LDADD): Added libspki.a.

	* src/spki.c (make_ssh_hostkey_tag): Include the outer "(tag ...)"
	expression.
	(spki_add_acl): New function.
	(spki_lookup): Fixed some compile time errors.
	(spki_authorize): Likewise.

	* src/lsh.c (read_known_hosts): Don't read known_hosts any more,
	just display a warning message saying that it needs conversion.
	(read_known_hosts): spki_add_acl now takes an spki_iterator.
	(do_lsh_lookup): The access expression includes the complete tag
	expression, not just the body of it.

	* src/lsh-pam-checkpw.c: Include config.h.

	* src/Makefile.am.in (LDADD): Add libspki.a.

Niels Möller's avatar
Niels Möller committed
847
848
2003-01-09  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
849
850
851
852
853
854
	* src/lsh.c (read_known_hosts): Display a message if an old
	known_hosts file is used.

	* src/daemon.c (daemon_init): Fork once more, to lose process
	session leadership.

Niels Möller's avatar
Niels Möller committed
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
	* src/spki.c: Deleted old spki implementation.
	(spki_lookup, spki_authorize): New functions.
	(do_spki_acl_db_mark, do_spki_acl_db_free): New functions.

	* src/lsh.c (read_known_hosts): Read new known-hosts file as
	"~/.lsh/host-acls", and filter it through sexp-conv. Fall back to
	the old file name "~/.lsh/known_hosts" if the new file doesn't
	exist. 
	(do_lsh_lookup): Use the new spki_lookup function.
	(do_lsh_lookup): Use new spki_authorize function.
	(do_lsh_lookup): Disable spki fingerprinting for now.

	* src/io.c (lsh_popen): New argument for recording the child pid.
	(lsh_popen_read): New function.

	* doc/lsh.texinfo (Files and environment variables): Document
	SEXP_CONV. 

Niels Möller's avatar
Niels Möller committed
873
874
875
876
877
2003-01-08  Niels Mller  <niels@s3.kth.se>

	* src/Makefile.am.in (environ.h): New rule for creating environ.h
	from environ.h.in.

Niels Möller's avatar
Niels Möller committed
878
879
880
881
882
883
2003-01-02  Niels Mller  <nisse@cuckoo.hack.org>

	* src/Makefile.am.in (SUBDIRS): Compile in spki subdir.

	* configure.ac: Configure subdir src/spki.

Niels Möller's avatar
Niels Möller committed
884
885
886
887
2003-01-02  Niels Mller  <niels@s3.kth.se>

	* src/io.c (lsh_popen): New function.

Pontus Freyhult's avatar
Pontus Freyhult committed
888
889
890
891
892
893
894
895
896
2003-01-02  Pontus Skld  <pont@soua.net>

	* configure.ac: Check for alarm.

	* src/lsh-pam-checkpw.c (main): Set an alarm to exit after TIMEOUT
	(currently 600) seconds.

	* src/lsh-krb-checkpw.c (main): Dito.

Niels Möller's avatar
Niels Möller committed
897
898
899
900
901
2002-12-11  Niels Mller  <niels@s3.kth.se>

	* src/lsh-writekey.c (process_private): If no encryption, dup the
	input string.

Niels Möller's avatar
Niels Möller committed
902
903
904
905
906
907
908
909
910
911
912
913
914
2002-12-04  Niels Mller  <nisse@cuckoo.hack.org>

	* src/dsa.c (do_dsa_sign): Use %0s, not %z, when formatting
	s-expressions. 
	(do_dsa_public_spki_key): Likewise.
	* src/spki.c (spki_pkcs5_encrypt): Likewise.
	(make_ssh_hostkey_tag): Likewise.
	(spki_hash_data): Likewise.
	* src/rsa_keygen.c (rsa_generate_key): Likewise.
	* src/rsa.c (do_rsa_public_spki_key): Likewise.
	* src/lsh.c (do_lsh_lookup): Likewise.
	* src/dsa_keygen.c (dsa_generate_key): Likewise.

Niels Möller's avatar
Niels Möller committed
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
2002-11-16  Niels Mller  <nisse@cuckoo.hack.org>

	* src/testsuite/key-1.private, src/testsuite/key-2.private:
	Updated keys. 

	* src/testsuite/conv-1-test, src/testsuite/conv-2-test,
	src/testsuite/dsa-test.c, src/testsuite/export-1-test,
	src/testsuite/rsa-test.c: Updated key s-expressions to match new
	format. Positive numbers must start with an octed with the most
	significant bit zero.

	* src/srp_exchange.c (srp_hash_password): Use
	nettle_mpz_set_str_256_u. 
	(make_srp_entry): Check sign of verifier.

	* src/spki.c (spki_pkcs5_decrypt): Use sexp_iterator_get_uint32.

	* src/sexp.c (lsh_sexp_to_uint32): Deleted function (similar
	function added to nettle, sexp_iterator_get_uint32).

	* src/rsa.c (do_rsa_verify): Use nettle_mpz_set_str_256_u.

	* src/parse.c (parse_bignum): Use nettle_mpz_set_str_256_s.

	* src/format.c (ssh_vformat_length): Use nettle's bignum
	functions. 
	(ssh_vformat_write): Likewise.

	* src/dsa.c (do_dsa_verify): Use nettle_mpz_set_str_256_u.
	(dsa_blob_length): Use nettle_mpz_sizeinbase_256_u.
	(dsa_blob_write): Use nettle_mpz_get_str_256.

	* src/bignum.c (limbs_to_octets): Deleted function.
	(bignum_parse_s): Deleted function.
	(mpz_size_of_complement): Deleted function.
	(bignum_format_s_length): Deleted function.
	(bignum_format_s): Deleted function.
	(bignum_parse_u): Deleted function.
	(bignum_format_u_length): Deleted function.
	(bignum_write): Deleted function.
	(bignum_format_u): Deleted function.
	(bignum_random_size): Made static.
	(bignum_random_size): Use nettle_mpz_set_str_256_u.

	* src/Makefile.am.in (lshg_LDADD): lshg needs to be linked with
	nettle now, that the bignum functions used by ssh_format have
	moved there. It should be possible to get lshg to work without
	either nettle or gmp, currently it won't.

Niels Möller's avatar
Niels Möller committed
964
965
966
967
968
2002-11-13  Niels Mller  <niels@s3.kth.se>

	* src/spki.c (do_spki_authorize): Need braces around
	FOR_OBJECT_QUEUE loop.

Niels Möller's avatar
Niels Möller committed
969
970
2002-11-11  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
971
972
	* src/Makefile.am.in (noinst_PROGRAMS): Don't build prime_table.  

Niels Möller's avatar
Niels Möller committed
973
974
975
	* src/digit_table.c: Deleted file.
	* src/prime_table.c: Deleted file.
	* src/sexp_parser.c: Deleted file.
Niels Möller's avatar
Niels Möller committed
976
	* src/digits.c: Deleted file.
Niels Möller's avatar
Niels Möller committed
977
978
979
980
981
982
983
984
985
986
987
	
	* src/bignum.c (bignum_small_factor): Deleted function.
	(bignum_next_prime): Deleted function.
	(bignum_random_prime): Deleted function.

	* src/lsh-decode-key.c (main): Use nettle's functions for base64
	decoding. 

	* src/Makefile.am.in: Don't build digit_table.h.
	(liblsh_a_SOURCES): Removed digits.c.

Niels Möller's avatar
Niels Möller committed
988
989
2002-11-10  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
990
991
992
993
994
995
	* src/lsh.c (do_lsh_default_handler): Deleted handling of obsolete
	exception types EXC_SEXP_SYNTAX and EXC_SPKI_TYPE.
	* src/lshd.c (do_exc_lshd_handler): Likewise.

	* src/srp_exchange.c (srp_make_verifier): Adapted to new sexp
	code.
Niels Möller's avatar
Niels Möller committed
996
997
	(make_srp_entry): Likewise.
	* src/srp-gen.c: Adapted to new sexp code.
Niels Möller's avatar
Niels Möller committed
998
999
1000
1001
	* src/server_keyexchange.c (do_server_srp_read_verifier):
	Adapted to new sexp code.
	* src/server_authorization.c (do_key_lookup): Adapted to new sexp
	code.
Niels Möller's avatar
Niels Möller committed
1002
	* src/server.c (read_host_key): Adapted to new sexp code.
Niels Möller's avatar
Niels Möller committed
1003
	* src/rsa_keygen.c (rsa_generate_key): Adapted to new sexp code.
Niels Möller's avatar
Niels Möller committed
1004
1005
1006
1007
1008
1009
1010
1011
1012
1013
1014
1015
1016
1017
1018
1019
1020
1021
1022
1023
1024
1025
1026
1027
1028
1029
1030
1031
1032
1033
1034
1035
1036
1037
1038
1039
1040
1041
1042
1043
1044
1045
1046
1047
1048
1049
1050
1051
1052
1053
1054
1055
1056
1057
1058
1059
1060
1061
1062
1063
1064
1065
1066
1067
1068
1069
1070
1071
1072
1073
1074
1075
1076
1077
1078
1079
1080
1081
1082
1083
1084
1085
1086
1087
1088
1089
1090
1091
1092
	* src/lshd.c: Adapted to new sexp code.
	* src/lsh.c (read_known_hosts): Adapted to new sexp code.
	(read_user_keys): Likewise.
	(do_lsh_lookup): Likewise.
	* src/lsh-keygen.c: Adapted to new sexp code.
	* src/lsh-writekey.c: Likewise.
	* src/lsh-decode-key.c: Adapted to new sexp code.
	* src/testsuite/testutils.c (test_sign): Adapted to new sexp code.
	(test_spki_match): Likewise.

	* src/spki.h (spki_exception): Deleted class.

	* src/spki.c: Adapted to new sexp code.
	(make_spki_exception): Deleted function.
	(spki_make_public_key): Deleted function, the PUBLIC_SPKI_KEY
	method can be used directly.directly.
	(spki_hash_sexp): Deleted function.
	(subject_match_hash): #if:ed out function for now.
	(spki_subject_by_hash): Likewise.
	(do_spki_lookup): #if:ed out lookup by hash.
	(spki_algorithm_lookup): New function.
	(spki_get_type): Deleted, moved similar code to sexp.c.

	* src/exception.h (EXC_SEXP, EXC_SPKI): Deleted SEXP and
	SPKI-related exceptions.

	* src/sexp.c: Rewrote using nettle's sexp functions.
	* src/sexp.h: Matching rewrite of declarations.
	
	* src/rsa.c (encode_rsa_sig_val): Deleted function.
	(decode_rsa_sig_val): Deleted function.
	(spki_init_rsa_verifier): Deleted function.
	(make_rsa_verifier_internal): Deleted function.
	(do_rsa_verify): Adapted to new sexp code.
	(do_rsa_public_spki_key): Likewise.
	(do_rsa_sign): Likewise.
	(make_rsa_verifier): Use rsa_keypair_from_sexp_alist.
	(make_rsa_signer): Likewise.

	* src/publickey_crypto.h: Added dsa declarations (used to be in
	dsa.h). 

	* src/lsh.h: Removed forward declaration of sexp structs.

	* src/lsh-export-key.c (encode_base64): New function (was in
	sexp.c earlier).
	(sexp_to_ssh2_key): Adapted to new sexp code.

	* src/lsh-authorize: Use new sexp-conv program. Check exit status
	of sexp-conv.

	* src/dsa_keygen.c (dsa_generate_key): Adapted to new sexp code.

	* src/dsa.h: Deleted file.

	* src/dsa.c (make_dsa_verifier_internal): Deleted function.
	(encode_dsa_sig_val): Deleted function.
	(decode_dsa_sig_val): Deleted function.
	(do_dsa_verify): Adapted to new sexp code.
	(do_dsa_public_spki_key): Return a string, in canonical or
	transport syntax. 
	(make_dsa_verifier): Use nettle's dsa_keypair_from_sexp_alist.
	(make_dsa_signer): Likewise.

	* src/abstract_crypto.h (PUBLIC_SPKI_KEY): Changed method, now
	returns a string and takes an extra argument to say if it should
	use transport syntax.

	* src/Makefile.am.in (bin_PROGRAMS): Don't build sexp-conv.
	(sbin_PROGRAMS): Don't build lsh_proxy.

	* src/testsuite/lsh-6-test (LSHD_FLAGS): Bugfix, test_success was
	used improperly, making the testcase always succeed.

	* src/testsuite/keygen-1-test: Use $SEXP_CONV.
	* src/testsuite/keygen-2-test: Likewise.

	* src/testsuite/functions.sh (SEXP_CONV): Use nettle's sexp-conv
	program. 

	* src/testsuite/conv-1-test: Use $SEXP_CONV, with explicit line
	width. 
	* src/testsuite/conv-2-test: Use $SEXP_CONV.
	* src/testsuite/conv-3-test: Skip test for now, new sexp-conv
	doesn't support hex output.

	* src/testsuite/Makefile.am (check): Set LD_LIBRARY_PATH when
	running tests.

Niels Möller's avatar
Niels Möller committed
1093
1094
2002-11-07  Niels Mller  <niels@s3.kth.se>

Niels Möller's avatar
Niels Möller committed
1095
1096
1097
1098
	* configure.ac: Don't use quotes with AM_CONFIG_HEADER, it seems
	to confuse automake.
	Bugfix: Don't generate nettle/Makefile here.

Niels Möller's avatar
Niels Möller committed
1099
1100
	* src/testsuite/functions.sh: Tolerate unset failing.

1101
1102
2002-11-04  Pontus Skld  <pont@soua.net>

1103
1104
	* src/testsuite/functions.sh: Unset LSHGFLAGS and LSHFLAGS.

1105
1106
1107
	* src/client.c (envp_parse): Certain versions of argp needs to be
	fed with ARGP_NO_ERRS for this to work.

1108
1109
1110
1111
1112
	* misc/Makefile.am.in: Removed obsolete reference to (and include
	of) ctags.mk.

	* doc/Makefile.am.in: Removed inclusion of ctags.mk.
	
Niels Möller's avatar
Niels Möller committed
1113
1114
2002-11-03  Niels Mller  <nisse@cuckoo.hack.org>

Niels Möller's avatar
Niels Möller committed
1115
1116
	* misc/Makefile.am.in: Don't include ctags.mk.

Niels Möller's avatar
Niels Möller committed
1117
1118
1119
1120
1121
1122
1123
1124
1125
1126
1127
1128
1129
1130
1131
1132
1133
1134
1135
1136
1137
1138
1139
1140
1141
1142
1143
1144
1145
1146
1147
1148
1149
1150
1151
1152
1153
1154
1155
1156
1157
1158
1159
1160
1161
	* src/testsuite/testutils.c (test_sign): Use SIGN and VERIFY, not
	the obsolete methods SIGN_SPKI and VERIFY_SPKI.

	* src/testsuite/Makefile.am (AM_CFLAGS): Use AM_CFLAGS to disable
	optimization. Don't set CFLAGS explicitly.

	* misc/ctags.mk: Deleted file. Not needed anymore, since automake
	supports ctags it out of the box.
	* Makefile.am.in: Don't include ctags.mk.
	* src/Makefile.am.in: Likewise.

	* src/rsa_keygen.c (get_random): Deleted function. Replaced by ... 
	* src/randomness.c (lsh_random): New function.

	* src/rsa.c (do_rsa_verify): Recognize algorithm "spki".
	(do_rsa_sign): Likewise.
	(do_rsa_verify_spki): Deleted function.
	(do_rsa_sign_spki): Likewise.

	* src/dsa_keygen.c (dsa_generate_key): Rewrote to use nettle's
	dsa_generate_keypair function.

2002-11-02  Niels Mller  <nisse@cuckoo.hack.org>

	* src/dsa.c (dsa_hash): Deleted function.
	(generic_dsa_verify): Rewrote to use nettle's dsa_verify.
	(do_dsa_verify_spki, do_dsa_sign_spki): Deleted method.
	(generic_dsa_sign): Rewrote to use nettle's dsa_sign.
	(dsa_blob_length): Use struct dsa_signature for the argument.
	(dsa_blob_write): Likewise.
	(encode_dsa_sig_val): Likewise.
	(decode_dsa_sig_val): Likewise.
	(make_dsa_signer): Use dsa_private_key_init.
	(class dsa_verifier): Use nettle's struct dsa_public_key.
	(class dsa_signer): Use nettle's struct dsa_private_key.
	(do_dsa_verify): Recognize algorithm "spki".
	(do_dsa_sign): Likewise.

	* src/bignum.c (bignum_write): Use const.

	* src/atoms.in: New atom "spki", for generic spki operations.

	* src/abstract_crypto.h (SIGN_SPKI, VERIFY_SPKI): Deleted methods
	used only by the testsuite.

1162
1163
1164
1165
1166
1167
1168
1169
1170
1171
1172
1173
1174
1175
1176
1177
1178
1179
1180
2002-11-01  Pontus Skld  <pont@soua.net>

	* src/testsuite/Makefile.am (TS_SH): New test lsh-9-test.

	* src/testsuite/lsh-9-test: Test for LSHFLAGS.
	
	* src/client.h (client_options): New attribute, inhibit_actions.
	Declaration of envp_parse.

	* src/client.c (envp_parse): New function envp_parse.
	(client_argp_parser): Honour inhibit_actions.
	(init_client_options): Initialize inhibit_actions.

	* src/lshg.c (main_argp_parser): Honour inhibit_actions.
	(main): Use envp_parse.

	* src/lsh.c (main_argp_parser): Honour inhibit_actions.
	(main): Use envp_parse.

1181
1182
2002-10-23  Pontus Skld  <pont@soua.net>

Pontus Freyhult's avatar
Pontus Freyhult committed
1183
1184
1185
	* src/client_x11.c (parse_display): Handle special case
	DISPLAY=unix:x.y for local delivery.

1186
1187
1188
1189
1190
1191
1192
	* src/client.c (do_detach_cb): New function replacing
	do_detach_cb_first and do_detach_cb_second.
	(do_detach_cb_first): Deleted.
	(do_detach_cb_second): Deleted.
	(make_detach_callback): Use new function stead of
	do_detach_cb_first.

1193
1194
1195
1196
1197
1198
1199
1200
1201
1202
1203
1204
1205
1206
1207
1208
1209
1210
1211
1212
1213
1214
1215
2002-10-22  Pontus Skld  <pont@soua.net>

	* src/client.c: Include io.h.
	(detach_callback): New class to handle detachment and
	synchronization with fds.
	(detach_resource): New class used for synchonization with channel
	disappearance.
	(do_detach_res_kill): Kill method for detach_resource.
	(make_detach_resource): New function.
	(do_detach_cb_second): New function that does the actual
	detaching.
	(do_detach_cb_first): Callback for synchronization with fds.
	(make_detach_callback): New function.
	(init_client_options): Set options->detach_end to 0 (detachment
	disabled by default).
	(client_options): Help message for detach and no-detach.
	(make_client_session): If options->detach_end, make a callback for
	stdout and set a resource on the channel to synchronize. Also
	reset options->detach_end to 0 (so it only affects one action).
	(client_argp_parser): Handle detach and no-detach.

	* src/client.h: New variable in client_options: detach_end.

1216
1217
1218
1219
1220
1221
1222
2002-10-03  Niels Mller  <nisse@cuckoo.hack.org>

	* configure.ac: Use AC_SEARCH_LIBS instead of AC_CHECK_LIB when
	looking for libnsl, so we don't pick it up unless it really is
	needed. 

2002-10-02  Pontus Skld  <Pontus.Skold@dis.uu.se>
1223
1224
1225
1226
1227
1228
1229

	* src/lshd.c: Include <sys/resource.h> if it exists.
	(main): setrlimit to raise max number of open files
	if available.

	* configure.ac: Check for <sys/resource.h> and setrlimit.
	
1230
2002-10-02  Pontus Skld  <Pontus.Skold@dis.uu.se>
1231
1232
1233
1234

	* configure.ac: Don't AC_PATH_PROG for bash, m4 and groff if
	given. Made them precious.

1235
2002-10-01  Niels Mller  <niels@s3.kth.se>
Niels Möller's avatar
Niels Möller committed
1236
1237
1238
1239

	* src/testsuite/run-tests (test_program): Use basename (fix copied
	from src/nettle/examples/).

1240
2002-09-12  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1241

Niels Möller's avatar
Niels Möller committed
1242
1243
	* Released lsh-1.5.0.

Niels Möller's avatar
Niels Möller committed
1244
1245
1246
1247
1248
1249
1250
1251
1252
1253
1254
	* misc/make-dist: Deleted obsolete make check-more call.

	* src/keyexchange.c (kex_make_encrypt, kex_make_decrypt): Changed
	interface so that we can both support the "none" cipher, and
	return failure for weak keys.
	(install_keys): Updated to the new kex_make_encrypt and
	kex_make_decrypt interface.

	* configure.ac: Deleted the ipv6 test that tried to create an ipv6
	socket. 

1255
2002-09-03  Pontus Skld  <pont@soua.net>
Pontus Freyhult's avatar
Pontus Freyhult committed
1256

1257
1258
1259
	* src/server_x11.c (XAUTH_PROGRAM): Use predefined value if
	available and built in default if not.

Pontus Freyhult's avatar
Pontus Freyhult committed
1260
1261
	* configure.ac: Search for xauth.

1262
2002-09-02  Pontus Skld  <pont@soua.net>
Pontus Freyhult's avatar
Pontus Freyhult committed
1263
1264
1265
1266

	* src/testsuite/lsh-8-test: New test. Check whatever unencrypted
	sessions work.

1267
2002-08-30  Pontus Skld  <pont@soua.net>
1268
1269
1270
1271

	* src/testsuite/functions.sh: Defaults need to be quoted if they
	contain spaces.

1272
2002-08-29  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1273

Niels Möller's avatar
Niels Möller committed
1274
1275
	* src/testsuite/x11-1-test: Renamed, was lshd-x11-1-test.

Niels Möller's avatar
Niels Möller committed
1276
1277
1278
1279
1280
1281
1282
1283
1284
1285
1286
	* src/testsuite/functions.sh (test_fail, test_result): Call exit.
	(test_skip): New function.
	(check_x11_support): New function.

	* src/testsuite/Makefile.am (distclean-local): Delete files and
	directories created by the test cases.
	(EXTRA_DIST): Distribute key-2.private and fake-sshd1.

	* src/lsh.c (main_options, main_argp_parser): Handle X11 options
	only if WITH_X11_FORWARD is defined.

1287
2002-08-28  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1288
1289
1290
1291
1292
1293

	* doc/lsh.texinfo (Top): Use @ififo around the @top directive, to
	get rid of the empty menu item inthe html output.

	* configure.ac: Bumped version to 1.5.

1294
2002-08-28  Niels Mller  <niels@s3.kth.se>
Niels Möller's avatar
Niels Möller committed
1295

Niels Möller's avatar
Niels Möller committed
1296
1297
1298
1299
	* doc/index.html: New file.

	* src/lsh-authorize: Use the construction ": ${var:=default}".

Niels Möller's avatar
Niels Möller committed
1300
1301
1302
1303
1304
	* src/testsuite/functions.sh: New variables TEST_HOME and
	SEXP_CONV. Changed the initialization of LSH_YARROW_SEED_FILE. Use
	TEST_HOME when running lsh and lshd. Should make the tests
	independent of our own ~/.lsh. Also updated comments in
	test-scripts that said they were dependent on ~/.lsh.
Niels Möller's avatar
Niels Möller committed
1305
	Use the construction ": ${var:=default}".
Niels Möller's avatar
Niels Möller committed
1306
1307
1308
1309
1310
1311
1312
1313
1314

	* src/testsuite/setup-env: New script to set up a HOME-directory
	for the tests.

	* src/testsuite/lshd-x11-1-test: New test.

	* src/lsh-authorize: Set SEXP_CONV to "sexp-conv", unless that
	variable is already defined by the caller.

Niels Möller's avatar
Niels Möller committed
1315
1316
	* src/server_x11.c (SUN_LEN): #define SUN_LEN if needed.

1317
2002-08-27  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1318
1319
1320
1321

	* src/server_x11.c (new_x11_channel): We don't have any ip-address
	of the client, so send <"unix-domain", 0> as the peer address.

1322
2002-08-27  Niels Mller  <niels@s3.kth.se>
Niels Möller's avatar
Niels Möller committed
1323

Niels Möller's avatar
Niels Möller committed
1324
1325
1326
	* src/server_pty.c (pty_open_slave): Removed call to setsid(),
	moved to...
	* src/unix_user.c (do_spawn): Call setsid(). Was previously done by
Niels Möller's avatar
Niels Möller committed
1327
	the pty code, and only in the pty case. XXX: Fix in 1.4 branch.
Niels Möller's avatar
Niels Möller committed
1328
1329
1330
1331
1332
1333
1334
1335
1336
1337
1338
1339
1340
1341
1342
1343
1344
1345
1346

	* src/server_session.c (init_spawn_info): Save the SSH_CLIENT
	value in the session struct, so that it can be gc:ed properly.

	* src/charset.c (low_utf8_to_local): Use lsh_string_trunc.
	* src/digits.c (decode_base64): Likewise.
	* src/io.c (do_consuming_read): Likewise.
	* src/read_base64.c (do_read_base64): Likewise.
	* src/read_file.c (do_read_file): Likewise.
	* src/string_buffer.c (string_buffer_final_write): Likewise.
	(string_buffer_final): Likewise.
	* src/channel.c (channel_data_handler): Likewise.
	(channel_extended_data_handler): Likewise.
	* src/tty.c (tty_encode_term_mode): Likewise.

	* src/abstract_crypto.c (crypt_string): Check that input is a
	multiple of the block size.
	(crypt_string_unpad): Use lsh_string_trunc.

Niels Möller's avatar
Niels Möller committed
1347
1348
1349
	* src/format.c (lsh_string_trunc): New function, needed to get
	proper NUL-termination when strings are truncated.

Niels Möller's avatar
Niels Möller committed
1350
1351
1352
	* src/server_x11.c (do_xauth_exit): Fixed format strings for error
	messages. 

1353
2002-08-27  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1354
1355
1356
1357

	* src/server_x11.c (server_x11_setup): Bugfix, really call
	server_x11_listen.

1358
2002-08-26  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1359

Niels Möller's avatar
Niels Möller committed
1360
1361
1362
1363
1364
1365
1366
1367
1368
1369
1370
1371
1372
1373
1374
	* src/server_x11.c (OPEN_FORWARDED_X11): Added forward
	declaration. 
	(server_x11_callback): Renamed (was server_x11_forward), and
	enabled.
	(server_x11_socket): New attribute display_number.
	(open_x11_socket): Pass an exception handler to io_bind_sockaddr.
	Start listening on the socket. Record the display_number.
	(server_x11_setup): Added argument single (and fail if it is
	non-zero). Updated caller in server_session.c. Call
	server_x11_setup. Ues the real display number when formatting the
	DISPLAY string.

	* src/channel_forward.c (catch_channel_open): Moved here...
	* src/tcpforward_commands.c: ...from here.

Niels Möller's avatar
Niels Möller committed
1375
1376
1377
1378
1379
1380
1381
1382
1383
1384
1385
1386
1387
1388
1389
1390
1391
1392
1393
1394
1395
	* src/tcpforward_commands.c (tcpip_connect_io_command): Renamed,
	was tcpip_connect_io.
	(do_tcpip_start_io): Deleted, replaced by channel_forward_start_io.

	* src/tcpforward.c: No need to include string.h and errno.h.
	* src/tty.c: Likewise.

	* src/server_userauth.c: No need to include string.h.

	* src/randomness.c: No need to include errno.h.
	* src/read_packet.c: Likewise.

	* src/io_commands.h (make_listen_local, make_connect_local):
	Deleted prototypes.

	* src/werror.c (werror_vformat): Added %e specifier. Updated all
	errno printing functions to use it.
	(werror_format): New function.
	(fatal): Compile time flag to display pid and hang, instead of
	aborting. Useful for debugging.

1396
2002-08-25  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1397
1398
1399
1400
1401
1402
1403
1404
1405
1406
1407
1408
1409
1410
1411
1412
1413
1414
1415
1416
1417
1418
1419
1420
1421

	* src/server_x11.c (new_x11_channel): New function.
	(open_forwarded_x11): New command.

	* src/lsh.c (main_argp_parser): Updated call of
	make_gateway_setup. 

	* src/io_commands.c (bind_local_command): New command.
	(do_listen_local): Deleted function.
	(make_listen_local): Deleted function.
	(do_connect_local): Deleted old #if:ed out function.
	(make_connect_local): Deleted old #if:ed out function.

	* src/gateway_commands.c (make_gateway_setup): Take a local_info
	as argument. Use the new bind_local command.

	* src/lsh.h: Added forward declarations for structs in command.h.
	Removed the inclusion of command.h from other header files.

	* src/channel_forward.c (start_io_command): New command, to
	replace tcpip_start_io.

	* src/lsh_proxy.c (lsh_proxy_listen): Replaced listen_callback
	with new bind and listen commands.

1422
2002-08-24  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1423
1424
1425
1426
1427
1428
1429
1430
1431
1432
1433
1434
1435
1436
1437
1438
1439
1440
1441
1442
1443
1444
1445
1446
1447
1448

	* src/io_commands.c (do_listen): Deleted function.
	(listen_with_callback): Deleted command.

	* src/lshd.c (make_lshd_listen): Replaced listen_callback with new
	bind and listen commands.

	* src/io_commands.c (listen_command): New command, to replace
	listen_with_callback. 
	(bind_address_command): New command.

	* src/io.c (make_listen_callback): Use a command, not a
	continuation, to represent the callback. Updated callers.

	* src/io_commands.c (do_listen): Use io_bind_sockaddr.
	(do_listen_local): Use io_bind_local.

	* src/io.c (io_bind_sockaddr): New function.
	(io_listen_fd): Take a struct lsh_fd * as argument, instead of an
	int. 
	(io_listen): Use io_bind_sockaddr.
	(io_listen, io_listen_fd): Deleted function io_listen. Renamed
	io_listen_fd to io_listen. 
	(io_bind_local): New function replacing io_listen_local. Updated
	callers. 

1449
2002-08-11  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1450
1451
1452
1453
1454
1455
1456
1457
1458
1459
1460
1461
1462
1463
1464
1465
1466
1467
1468

	* src/unix_user.c (do_read_file): Use seteuid, not setuid.

	* src/server_x11.c (server_x11_socket): New class.
	(delete_x11_socket): New function.
	(do_kill_x11_socket): New function.
	(open_x11_socket): New function.
	(server_x11_listen): New function.

	* src/lshd.c: Enable X11 support.
	* src/server_session.c: Likewise.

	* src/io.c (io_listen_fd): New function.
	(io_listen): Use io_listen_fd.
	(lsh_popd): Renamed safe_popd, and made non-static. 
	(lsh_pushd_fd): New function.
	(lsh_pushd): Renamed safe_pushd, and use lsh_pushd_fd. Also added
	arguments result and secret. Updated all callers.

1469
2002-07-18  Niels Mller  <niels@s3.kth.se>
Niels Möller's avatar
Niels Möller committed
1470
1471
1472

	* configure.ac: Use -ggdb3 for gcc, except for gcc-2.96.

1473
2002-07-05  Niels Mller  <nisse@cuckoo.hack.org>
1474
1475
1476
1477
1478

	* src/lshd.c: Disabled incomplete x11 forwarding for now.
	* src/server_session.c: Likewise.
	* src/server_x11.c: Likewise.
	
1479
2002-07-03  Pontus Skld  <pont@soua.net>
Pontus Freyhult's avatar
Pontus Freyhult committed
1480
1481
1482
1483
1484
1485
1486
1487
1488
1489
1490
1491
1492
1493
1494
1495
1496
1497
1498

	* src/lshg.c: Include <unistd.h> to get execvp declaration, define
	LSH_FILENAME if not defined.
	(lshg_options): New attribute fallback_lsh.
	(make_options): Initialize fallback_lsh.
	(main_options): New option -G to handle fallback.
	(main_argp_parser): Handle new option.
	(main_argp): Added missing space in message.
	(lshg_exception_handler): New class.
	(do_exc_lshg_handler): If the exception was because there was no
	usable gateway and fallback is enabled, launch lsh instead.
	(make_lshg_exception_handler): No longer call
	make_exception_handler but construct the object ourself.
	(main): make_lshg_exception_handler takes more arguments to handle
	the lsh fallback.

	* src/io_commands.c (connect_local_command): Check if the
	connection was successfull and raise an exception otherwise.

1499
2002-07-02  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1500
1501
1502
1503
1504
1505
1506
1507
1508
1509
1510
1511
1512
1513
1514
1515
1516

	* src/unix_user.c (do_spawn): Allow err[1] and out[1] to be the
	same fd.

	* src/server_x11.c (do_xauth_exit): Log a message if xauth failed. 
	(server_x11_setup): Fixed format of display string.
	(server_x11_setup): Use an absolute filename for the xauth program.
	(server_x11_setup): Added missing new line on the xauth command
	line. 

	* src/server_session.c (init_spawn_info): Set DISPLAY and
	XAUTHORITY, if x11 forwarding was requested. Updated callers, as
	the size of env changed.
	(do_x11_req): Bugfix, the single flag is one byte, not four.

	* src/Makefile.am.in (liblsh_a_SOURCES): Added server_x11.c.

1517
2002-06-28  Niels Mller  <niels@s3.kth.se>
Niels Möller's avatar
Niels Möller committed
1518
1519
1520
1521
1522
1523
1524
1525
1526
1527
1528

	* src/lshd.c (main_options): New options, --tcpip-forward,
	--no-tcpip-forward (earlier there was no option for disabling
	tcpip forward), --x11-forward and --no-x11-forward.
	(main_argp_parser): Handle x11 options.
	(main): Install handler for x11-req, if appropriate.

	* src/server_session.h (x11_req_handler): Declare handler.

	* src/server_session.c (do_x11_req): Fixed error message.

1529
2002-06-27  Niels Mller  <niels@s3.kth.se>
Niels Möller's avatar
Niels Möller committed
1530

Niels Möller's avatar
Niels Möller committed
1531
1532
1533
1534
1535
1536
1537
1538
	* src/lsh_proxy.c (main) [WITH_X11_FORWARD]: Fixed type warning.

	* src/lsh.c (main_argp_parser): Use STATIC_REPORT_EXCEPTION_INFO,
	and const.
	* src/lshd.c (main): Likewise.

	* configure.ac: Fixed type, enable_x11_forward should work now.

Niels Möller's avatar
Niels Möller committed
1539
1540
1541
1542
1543
1544
1545
1546
1547
1548
1549
1550
1551
	* src/server_x11.c (server_x11_setup): Bugfixes. Send cookie on
	xauth stdin. 

	* src/tcpforward_commands.c (open_tcpip_report): Declare const.: 

	* src/server_session.c (do_x11_req): Use server_x11_setup.

	* src/channel.c (channel_request_handler): Use a const
	report_exception_info. 
	(global_request_handler): Likewise.

	* src/exception.c (make_report_exception_handler): Use a const
	report_exception_info object.
Niels Möller's avatar
Niels Möller committed
1552
1553
	* src/command.c (make_catch_report_apply): Likewise.

Niels Möller's avatar
Niels Möller committed
1554

1555
2002-06-27  Pontus Skld  <pont@soua.net>
Pontus Freyhult's avatar
Pontus Freyhult committed
1556
1557
1558
1559

	* src/testsuite/string-test.c (test_main): Added extra bubble
	babble check for a typo Richard Kettlewell discovered.

1560
2002-06-26  Pontus Skld  <pont@soua.net>
1561
1562
1563
1564
1565

	* src/format.c (lsh_string_bubblebabble): Fixed stupid typo making
	w occur in bubble babble fingerprint where it should be z. Also
	fixed the size of the cons array.

1566
2002-06-26  Niels Mller  <niels@s3.kth.se>
Niels Möller's avatar
Niels Möller committed
1567

1568
1569
1570
	* src/unix_user.c (do_lookup_user): Don't treat accounts with a
	single "*" in the paswd-field as disabled.

Niels Möller's avatar
Niels Möller committed
1571
1572
1573
1574
1575
1576
1577
1578
1579
1580
1581
1582
1583
1584
1585
1586
1587
1588
1589
1590
1591
1592
1593
1594
1595
1596
1597
1598
1599
1600
1601
	* src/spki.c (spki_pkcs5_decrypt): Bug fixes. Friendlier pass
	phrase prompt.

	* src/unix_user.c (do_verify_password): Interpret short
	passwd-fields as password login disabled.
	(do_lookup_user): Improved rules for dealing with shadow
	passwords, disabled accounts, etc.

	* src/io.c (do_write_callback): Added some code to ignore write
	errors for the final , but #if:ed out the code again.

	* src/client_userauth.c (do_none_login): Print a verbose message.
	(send_password): Likewise.
	(do_userauth_pk_ok): Likewise.
	(do_publickey_login): Likewise.

	* src/client_session.c (do_client_io): Updated invocations of
	make_channel_io_exception_handler. 

	* src/server_session.c (spawn_process): Create a silent exception
	handler for i/o errors on stdout, to avoid cluttering down the
	log. 

	* src/channel.c (make_channel_io_exception_handler): New argument
	silent.

	* configure.ac: Bumped version to 1.4.2.

	* src/lsh.c (read_user_keys): Support aes for encrypted private
	keys. 

1602
2002-06-26  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1603

Niels Möller's avatar
Niels Möller committed
1604
1605
1606
	* src/lsh-make-seed.c (get_dev_random): Bugfix: Actually try both
	/dev/random and /dev/urandom.

Niels Möller's avatar
Niels Möller committed
1607
1608
	* doc/lsh.texinfo (lshd basics): Changed invokation of lsh-keygen. 

1609
2002-06-25  Niels Mller  <niels@s3.kth.se>
Niels Möller's avatar
Niels Möller committed
1610
1611

	* src/server_x11.c, src/server_x11.h: New files.
Niels Möller's avatar
Niels Möller committed
1612
1613
	(make_xauth_exit_callback): New function.
	(server_x11_setup): New function.
Niels Möller's avatar
Niels Möller committed
1614
1615
1616
1617

	* src/server_session.c (server_session): New attribute x11.
	(do_x11_req): New function.

1618
2002-06-23  Pontus Skld  <pont@soua.net>
1619
1620
1621
1622

	* configure.ac: Cosmetic changes of message shown when libwrap
	detection fails.

1623
2002-06-18  Niels Mller  <nisse@cuckoo.hack.org>
1624
1625
1626
1627
1628
1629

	* src/server_session.c (spawn_process): Call io_set_type, if stdin
	is a pty.
	(do_eof): Removed the pty ^D hack,a s it's now taken care of by
	close_fd_write. 
	
1630
2002-06-17  Niels Mller  <nisse@cuckoo.hack.org>
1631
1632
1633
1634
1635
1636
1637
1638

	* src/io.c (io_set_type): New function.
	(close_fd_nicely): Call close_fd_write, for handling the
	write-related work.
	(close_fd_write): If the fd is a pty, write a EOF (^D) character. 

	* src/io.h (lsh_fd): New attribute TYPE.

1639
2002-06-05  Niels Mller  <nisse@cuckoo.hack.org>
1640
1641
1642
1643

	* configure.ac: Bumped version to 1.4.1. New option
	--enable-initgroups-workaround, copied from the 1.2 branch.

1644
2002-06-04  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1645

Niels Möller's avatar
Niels Möller committed
1646
1647
	* Released lsh-1.4.

Niels Möller's avatar
Niels Möller committed
1648
1649
1650
1651
1652
	* src/rsa.c (do_rsa_public_spki_key): Reverted the 2001-01-24
	change "rsa-pkcs1-sha1" -> "rsa-pkcs1".
	* src/testsuite/conv-2-test, src/testsuite/conv-3-test: Updated
	testcases.

1653
2002-05-30  Pontus Skld  <pont@soua.net>
Pontus Freyhult's avatar
Pontus Freyhult committed
1654
1655
1656
1657
1658
1659
1660
1661
1662
1663
1664
1665
1666
1667
1668
1669
1670
1671
1672
1673
1674
1675
1676
1677
1678
1679
1680
1681
1682
1683
1684
1685

	* src/server_session.c (init_spawn_info): Require more entries
	available for environment variables. Set SSH_TTY if appropiate as
	well as SSH_CLIENT.
	(shell_request_handler): Reserve more environment variable
	entries.
	(exec_request_handler): Dito.
	(do_spawn_subsystem): Dito.

	* src/io_commands.c (do_connect_continuation): Derive local
	address_info from fd and pass to make_listen_value.

	* src/io.c (make_listen_value): Takes an extra struct
	address_info* to initialize local with.
	(do_listen_callback): Get a local address_info and pass to
	make_listen_value.
	(fd2info): New function.

	* src/io.h: New variable local in listen_value. make_listen_value
	takes an extra struct address_info*.
	(fd2info): declaration of new function.

	* src/gateway_commands.c (gateway_make_connection): Also pass
	lv->local to make_ssh_connection.

	* src/handshake.c (handshake_command): dito.
	
	* src/connection.h: New variable local in ssh_connection.
	make_ssh_connection takes an extra struct address_info*.

	* src/connection.c (make_ssh_connection): dito.
	
1686
2002-05-24  Pontus Skld  <pont@soua.net>
Pontus Freyhult's avatar
Pontus Freyhult committed
1687
1688
1689
1690
1691
1692

	* src/io.c (io_final): Set stdin, stdout and stderr to blocking mode.

	* src/io_commands.c (do_tcp_wrapper): Send a copy of self->msg to
	A_WRITE instead of the string itself.

1693
2002-05-15  Pontus Skld  <pont@soua.net>
Pontus Freyhult's avatar
Pontus Freyhult committed
1694
1695
1696
1697
1698
1699
1700
1701
1702
1703
1704
1705
1706
1707
1708

	* configure.ac: Added things neccessarry for tcp wrappers to work.

	* src/lshd.c (OPTIONS2TCP_WRAPPER): New command.
	New options: --tcpwrappers, --no-tcpwrappers, --tcpwrappers-msg.
	
	* src/io_commands.c: Include <tcpd.h> if building with tcp
	wrappers. Also include <syslog.h>.
	(tcp_wrapper): New class.
	(do_tcp_wrapper): New function.
	(do_tcp_wrapper): New function.

	* src/io_commands.h (make_tcp_wrapper): Definition of new
	function.

1709
2002-05-14  Pontus Skld  <pont@soua.net>
1710
1711
1712
1713
1714

	* src/algorithms.c (list_algorithms): Added missing newline after
	the list of algorithms.
	(list_hostkey_algorithms): dito.

1715
2002-05-13  Pontus Skld  <pont@soua.net>
1716
1717
1718
1719
1720
1721
1722
1723
1724
1725
1726
1727
1728
1729
1730

	* src/lsh.c (make_options): Don't fail totally if we can't create
	a randomness source.
	(main_argp_parser): Do argp_failure unless we have a valid
	randomness object.

	* src/lshd.c (main): Check for a correctly initialized random
	object in options.
	(make_lshd_options): Don't return failure if random creation
	failed, just initialize signature_algorithms with a null random
	source (this should enable users without a seed to do lsh --help
	and normal users to do lshd --help).
	(main_argp_parser): Do argp_failure unless we have a valid
	randomness object.

1731
2002-05-06  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1732
1733
1734
1735
1736
1737

	* README: Document requirement of autoconf-2.52 and
	automake-1.6.1. 

	* configure.ac: Require autoconf-2.52.

1738
2002-05-06  Niels Mller  <niels@s3.kth.se>
Niels Möller's avatar
Niels Möller committed
1739
1740
1741

	* configure.ac (CFLAGS): Don't enable -Waggregate-return.

1742
2002-05-06  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1743
1744
1745
1746
1747
1748
1749
1750
1751
1752
1753
1754
1755
1756
1757
1758

	* src/gateway_channel.c (do_gateway_channel_open): Undid previous
	change. Let channel.c:check_rec_max_packet adjust the
	rec_max_packet size if needed, when it gets to the channel.
	(do_gateway_channel_open_continuation): Likewise.

	* src/channel.c (check_rec_max_packet): New function, that adjusts
	our advertised rec_window_size so that we won't exceed the
	connection's packet size limit.
	(format_open_confirmation): Call check_rec_max_packet.
	(format_channel_open_s): Likewise.
	(format_channel_open): Likewise.

	* src/read_data.c (do_read_data_query): Undid previous change. Now
	look at only send_window_size and send_max_packet.

1759
2002-05-05  Niels Mller  <nisse@lysator.liu.se>
Niels Möller's avatar
Niels Möller committed
1760
1761
1762

	* configure.ac: Pass no options to AM_INIT_AUTOMAKE.

1763
2002-05-05  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1764

Niels Möller's avatar
Niels Möller committed
1765
1766
1767
1768
1769
1770
1771
1772
1773
	* configure.ac: Update for automake-1.6.

	* src/gateway_channel.c (do_channel_open_forward): Added a FIXME
	comment. We should install a new exception handler here.

	* configure.ac: Renamed file, used to be configure.in.

	* configure.in: Bumped version number to 1.4.

Niels Möller's avatar
Niels Möller committed
1774
1775
1776
	* doc/lsh.texinfo (Algorithm options): Updated description of the
	default cipher. We now use AES, not triple-DES.

1777
2002-05-02  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1778
1779
1780
1781
1782
1783
1784
1785
1786
1787
1788
1789
1790
1791
1792

	* src/gateway_channel.c (do_gateway_channel_open): Limit
	rec_max_packet to SSH_MAX_PACKET.
	(do_gateway_channel_open_continuation): Likewise.

	* src/channel.c (parse_channel_open): Don't subtract
	SSH_MAX_PACKET_FUZZ here, it's handled in read_data.c.
	* src/server_session.c (make_server_session): Likewise.
	* src/client_session.c (make_client_session_channel): Likewise.
	* src/channel_forward.c (init_channel_forward): Likewise.

	* src/read_data.c (do_read_data_query): Don't read more than
	send_max_packet - SSH_MAX_PACKET_FUZZ, as to not exceed the
	receivers maximum packet size. 

1793
2002-04-04  Pontus Skld  <pont@soua.net>
Pontus Freyhult's avatar
Pontus Freyhult committed
1794
1795
1796
1797

	* src/lsh.c (do_lsh_lookup): Cosmetic changes of unauthenticated
	key fingerprint text.

1798
2002-04-03  Pontus Skld  <pont@soua.net>
Pontus Freyhult's avatar
Pontus Freyhult committed
1799

Pontus Freyhult's avatar
Pontus Freyhult committed
1800
1801
1802
1803
1804
1805
1806
1807
1808
1809
1810
1811
1812
1813
1814
1815
1816
	* src/format.c (lsh_string_bubblebabble_c): New function to define
	the che bubble babble checksum series, used by
	lsh_string_bubblebabble.

	* src/lsh.c (do_lsh_lookup): Rearranged the unauthenticated key
	fingerprint display somewhat and added bubble babble SHA1 of
	keyblob (which seems to be what OpenSSH is using at least).

	* src/format.c (lsh_string_bubblebabble): New function to
	bubblebabble a string.

	* src/format.h (lsh_string_bubblebabble): New function to
	bubblebabble a string.

	* src/testsuite/string-test.c (test_main): Added checks for
	lsh_string_bubblebabble.

Pontus Freyhult's avatar
Pontus Freyhult committed
1817
1818
1819
1820
1821
1822
1823
1824
1825
1826
1827
1828
	* src/lsh.c (do_lsh_lookup): Output the fingerprint of the remote
	host according to draft-ietf-secsh-fingerprint-00.txt (and keep
	the old way of outputing).

	* src/format.c (lsh_string_colonize): New function to insert
	colons in a lsh_string.

	* src/format.h (lsh_string_colonize): Likewise
	
	* src/testsuite/string-test.c (test_main): Added tests for
	lsh_string_colonize.

Pontus Freyhult's avatar
Pontus Freyhult committed
1829
1830
1831
	* src/client.c (client_options): Bugfix: OPT_SUBSYSTEM shouldn't
	be inside char quotes.

1832
2002-03-27  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1833
1834
1835
1836
1837
1838
1839
1840
1841

	* src/io.c (lsh_oop_stop_callback): Use the OOP_HALT constant.

	* src/client_x11.c (do_client_channel_x11_receive): Allow
	lowercase letters 'l' and 'b' for the endianness indicator.

	* src/client.c: Removed the short alias, -C, for the --subsystem
	option. 

1842
2002-03-26  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1843
1844
1845
1846

	* src/lsh-authorize: Don't use &>-redirects, as /bin/sh doesn't
	understand that. Noticed by Timshell Knoll.

1847
2002-03-25  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1848
1849
1850
1851

	* src/lsh-execuv.c: Deleted utmp stuff, this is not the right
	place for that.

1852
2002-03-26  Pontus Skld  <pont@soua.net>
Pontus Freyhult's avatar
Pontus Freyhult committed
1853

Pontus Freyhult's avatar
Pontus Freyhult committed
1854
1855
1856
	* configure.in: If with_scheme is absolute, don't AC_PATH_PROG for
	it but just use it directly.

Pontus Freyhult's avatar
Pontus Freyhult committed
1857
1858
1859
1860
1861
	* src/client.c (client_options): Added implication of no-pty in
	subsystem help text if PTY-support is enabled.
	(client_argp_parser): Turn of pty-request if there is a subsystem
	request.

1862
2002-03-22  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1863
1864
1865

	* src/sexp-conv.c (main): Add newline at end of --raw-hash output.

1866
2002-03-20  Pontus Skld  <pont@r3>
Pontus Freyhult's avatar
Pontus Freyhult committed
1867

Pontus Freyhult's avatar
Pontus Freyhult committed
1868
1869
1870
1871
1872
1873
1874
	* src/testsuite/lsh-1-test: Run "exec 0" instead of "exec" in case
	the last command in the user's startup files ended with nonzero
	exit status.

	* src/testsuite/lsh-5-test: Likewise.
	* src/testsuite/lsh-6-test: Likewise.
	
Pontus Freyhult's avatar
Pontus Freyhult committed
1875
1876
1877
	* src/testsuite/lshg-1-test: grep -q changed to redirection to
	/dev/null.

Pontus Freyhult's avatar
Pontus Freyhult committed
1878
1879
	* src/testsuite/ssh1-fallback-test: Likewise.
	
1880
2002-03-20  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1881
1882
1883
1884

	* src/testsuite/run-tests (test_program): Added missing single
	quote.

1885
2002-03-20  Niels Mller  <nisse@lysator.liu.se>
Niels Möller's avatar
Niels Möller committed
1886

Niels Möller's avatar
Niels Möller committed
1887
1888
1889
1890
	* src/testsuite/functions.sh (at_connect): Put -- between the
	options and the arguments, as that is the correct place according
	to POSIX. 

Niels Möller's avatar
Niels Möller committed
1891
1892
1893
	* src/testsuite/lsh-7-test: Rewrote !command-expressions as an if
	expression, to work with /bin/sh.

1894
2002-03-20  Niels Mller  <nisse@cuckoo.hack.org>
Niels Möller's avatar
Niels Möller committed
1895
1896
1897
1898

	* src/io.c (address_info2sockaddr): Zero-terminate the
	default_preferences list.

1899
2002-03-20  Niels Mller  <nisse@lysator.liu.se>
Niels Möller's avatar
Niels Möller committed
1900

Niels Möller's avatar
Niels Möller committed
1901
1902
1903
	* src/client_session.c (make_client_session_channel): Clear the
	CHANNEL_CLOSE_AT_EOF flag.

Niels Möller's avatar
Niels Möller committed
1904
1905
1906
1907
1908
1909
1910
1911
1912
1913
	* src/testsuite/run-tests (test_program): Test the exit status of
	the right process.

	* src/testsuite/fail-test: New, always failing, testcase. For
	testing run-tests.

	* src/testsuite/functions.sh (at_connect): Don't use -- in
	argument list to mini-inetd, appearantly Solaris' getopt
	doesn't handle that. 

1914
2002-03-19  Niels Mller  <nisse@lysator.liu.se>
Niels Möller's avatar
Niels Möller committed
1915
1916
1917
1918
1919
1920

	* src/io.c (address_info2sockaddr): Prefer AF_INET addresses over
	AF_INET6 (as it seems common that localhost has an ipv6 address
	that doesn't work). Even better would be to try all addresses, but
	that has to wait for later.

1921
2002-03-19  Pontus Skld  <pont@docs.uu.se>
Pontus Freyhult's avatar
Pontus Freyhult committed
1922
1923
1924
1925
1926
1927

	* src/sftp/testsuite/*-test: grep -q is XPG4, which not all
	greps (notably Solaris /bin/grep) are.

	* src/sftp/testsuite/run-tests: Replaced bashims.
	
1928
2002-03-19  Pontus Skld  <pont@it.uu.se>
Pontus Freyhult's avatar
Pontus Freyhult committed
1929
1930
1931

	* src/testsuite/seed-test: Fixed bashism.

1932
2002-03-19  Pontus Skld  <pont@it.uu.se>
Pontus Freyhult's avatar
Pontus Freyhult committed
1933
1934
1935

	* src/testsuite/run-tests: Replaced bashims.

1936
2002-03-19  Pontus Skld  <pont@it.uu.se>
Pontus Freyhult's avatar
Pontus Freyhult committed
1937
1938
1939
1940
1941
1942

	* src/unix_process.c: Added GETUTXID and UPDWTMPX.
	(do_utmp_cleanup): Write cleared entry to wtmp{,x} with
	updwtmp{,x} if logwtmp is not available.
	(utmp_book_keeping): Likewise.	 

1943
2002-03-18  Niels Mller  <nisse@lysator.liu.se>