commit fdda125f5349558c17ef572f2afced1980b7d208
Author: Damien Miller <djm@mindrot.org>
Date:   Tue Oct 6 19:01:18 2026 +1100

    .depend

commit ce43722bcc9f5426c6469ae06527b809a9cb8920
Author: Damien Miller <djm@mindrot.org>
Date:   Tue Oct 6 18:57:28 2026 +1100

    update RPM spec files

commit b27b24bd295594816adcc979788eca001140532c
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Mon Oct 5 09:54:05 2026 +0000

    upstream: openssh-10.6
    
    OpenBSD-Commit-ID: 907104c6a6e058860522bf752663d71b37bfa43f

commit 1058092dba9145325a5f50793570fc754b375c3d
Author: dtucker@openbsd.org <dtucker@openbsd.org>
Date:   Sat Oct 3 05:08:49 2026 +0000

    upstream: Add test for proxycommand percent expansions.
    
    OpenBSD-Regress-ID: be34cb5cf08f1025413df248cb7a65e18ca3e2a1

commit 630144f410985ce9bad03929556b3c364bc0e255
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 23 21:45:51 2026 +0000

    upstream: backout regress bits related to multiplexing change
    
    OpenBSD-Regress-ID: 3fdaea9d640ce1d4950223b66f26f6f1ab46f4c9

commit ac6ad1afd1c3531fad2e96a00c84bd9867cf5561
Author: Damien Miller <djm@mindrot.org>
Date:   Tue Oct 6 16:48:54 2026 +1100

    remove the --disable-fd-passing configure option
    
    Also add a deprecation warning when the lack FD passing support and also
    requires root for the post-auth sshd-session process

commit b37c095aa39bb2c01754673dec50a684a536db24
Author: Damien Miller <djm@mindrot.org>
Date:   Tue Oct 6 16:43:39 2026 +1100

    disable features when post-auth sshd runs as root
    
    On platforms that require root privilege for the post-authentication
    sshd-session process (e.g. OpenServer 5, QNX 6), disable and restrict
    a number of features that assume user privilege.
    
    This includes GatewayPorts, StreamLocalForwarding and -R forwardings
    binding to ports <1024

commit 4b29da5952b1ede28f0d225cf722dee4923ba04c
Author: Darren Tucker <dtucker@dtucker.net>
Date:   Mon Oct 5 17:08:15 2026 +1100

    Don't automatically enable FORTIFY_SOURCE.
    
    It can cause problems on some platforms, in particular NetBSD <11 since
    it will cause function pointer comparisons in atomicio to fail and some
    things including scp to hang.  Previously we had a workaround but that
    was removed in a765b86d.  See NetBSD bug 45200 and pkgsrc bug pkg/60563.

commit 0c4c9a7b320bd7ff61c4a2dc345cb2e27e9663b2
Author: dtucker@openbsd.org <dtucker@openbsd.org>
Date:   Mon Oct 5 06:03:40 2026 +0000

    upstream: Further restrict the characters allowed in a command-line
    
    supplied user name, disallowing '$' and '\'. Reported by SecBuddyF KeenLab
    Tencent (CodeBuddy Security).
    
    OpenBSD-Commit-ID: 13671c178f492af63b5c1296f284818c7809ed9a

commit 15289cc38956aa74d4947174a68c10ac9ad2157f
Author: Darren Tucker <dtucker@dtucker.net>
Date:   Sat Oct 3 17:20:09 2026 +1000

    Remove NetBSD 9.0 test target.
    
    It can no longer install the sudo package and is covered by the
    selfhosted VMs.

commit 4f4bee9ec673b29949ec0e79c92cd56b61f772e6
Author: Darren Tucker <dtucker@dtucker.net>
Date:   Sat Oct 3 17:12:13 2026 +1000

    Replace native ARM runner with remote runner.
    
    Native ARM32 runners are no longer supported by Github.

commit e0f28caca5a77e84bef02c9f6476d2d4bd31b937
Author: Darren Tucker <dtucker@dtucker.net>
Date:   Sat Oct 3 16:18:30 2026 +1000

    Pull older NetBSD sudo package from archive.

commit d1d37e27a14f3336e36666d59c4b3e1c76cce328
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Sat Oct 3 00:46:58 2026 +0000

    upstream: make StreamLocalBindMask properly first-match-wins;
    
    spotted while fixing bz4013
    
    OpenBSD-Commit-ID: 35ef4524da0d03a439751f7bcd4847f76d93ec7f

commit bc00e06e0cda509c06b47ee4d1551efc904894a1
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Sat Oct 3 00:46:29 2026 +0000

    upstream: make StreamLocalBindMask properly respect Host/Match
    
    blocks and make it first-match-wins as documented. bz4013
    
    OpenBSD-Commit-ID: e2efc85b42bbf7067ece4f1ab12d7d02ec6c3e12

commit 87f0cd1892e501f835dd210abea5461807c8deba
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Thu Oct 1 07:10:56 2026 +0000

    upstream: start process of deprecating the -R flag. This was the
    
    old way of performing a remote-to-remote copy that was basically executed scp
    on the remote host. It barely worked (needing agent forwarding enabled or
    usable credentials on the remote host) and has largely been replaced by a
    better SFTP-protocol remote-to-remote copy that runs through the host
    performing the copy.
    
    We'll disable this option in a release or two; ok dtucker@
    
    OpenBSD-Commit-ID: dc273300651e581c3db18edf21f2b05ceac60fd7

commit 88fe0b074ee0c0cdf6d87f8b86b4c959e7d2bdbc
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Thu Oct 1 07:08:05 2026 +0000

    upstream: mention default KDF rounds is now 32
    
    OpenBSD-Commit-ID: 0d17bf0ad02c8c0d897d9d01d1e4eb0f65ea749c

commit f938c78d490cb7556aa8ca1625e9b9bd1f963ed3
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Thu Oct 1 07:07:49 2026 +0000

    upstream: Implement a maximum number of KDF rounds that will be
    
    accepted when writing an OpenSSH-format private key or when loading one. This
    limit is set pretty high (1<<20), but ensures that a service that is passed a
    bad key with an ridiculously high number of rounds will _eventually_ complete
    parsing it.
    
    Also bump the default number of KDF rounds from 24 to 32 (this is a
    linear increase, not like bcrypt(3) which is exponential).
    
    Pointed out by Aris Adamantiadis
    
    OpenBSD-Commit-ID: 843ff37b066b2879f4579a784e42a3c9d22b2ddc

commit 39b9bd1cb7d32428842c67e7e8b217027c16962b
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Thu Oct 1 04:17:39 2026 +0000

    upstream: fix the bit length of ML-DSA 44/Ed25519 keys that was
    
    being incorrectly reported as 256. The private key length for these composite
    keys is 512 bits. This value is only used for display.
    
    Spotted by Yiyue Wang
    
    OpenBSD-Commit-ID: 5ba7c8a9a457434ca0652042e1c5940bbc6ef5e0

commit c07ea2180adebd6019a6ebdd89becb9d9f4b4897
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Thu Oct 1 03:11:49 2026 +0000

    upstream: sftp: be stricter in accepting paths returned by the
    
    server for SSH_FXP_REALPATH or SSH2_FXP_READDIR replies, as these can be used
    in some situations to decide the destination path for recursive transfers.
    
    Report and patch from Junghoon Cho
    
    OpenBSD-Commit-ID: ad357002a1b75c87113f01086a9f0c12c36082d8

commit 39cba820eda49ea084c9270917dfb5efc03f08cc
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Thu Oct 1 02:01:51 2026 +0000

    upstream: handle max-pk-ok path identically when the incoming user
    
    is invalid; avoids max-pk-ok feature presenting a username validity oracle
    
    analysis and patch from Chris Rohlf in collaboration with Claude and
    Anthropic Research
    
    OpenBSD-Commit-ID: c05d01b1724c76c9e30ed5e0f06686820f94bce8

commit e27b6cc2e6e8ba03808f7078740e5ba800515d4d
Author: dtucker@openbsd.org <dtucker@openbsd.org>
Date:   Sun Sep 27 22:39:40 2026 +0000

    upstream: Disallow nul byte in received scp -O filename. Not
    
    reachable in normal operation since a nul would cause a filename mismatch,
    but potentially possible if being used an unusual configuration such as a
    custom filter.
    
    Reported by Chua Wei Xun <weixun.chua at e-cq.net>, ok djm@
    
    OpenBSD-Commit-ID: 1fb35933acdc11dd66bdba780bd9e100bda69079

commit fc6ca48d15419f23a6a2ea3c0115b8f32c3dcc69
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 23 21:42:39 2026 +0000

    upstream: backout
    
    > avoid race between multiple processes attempting to
    >
    > establish multiplexing control socket by moving socket creation earlier in
    > ssh(1)'s life. Patch from Jens Rosenboom via bz3971
    
    It caused problems with ControlPersist sessions.
    
    Reported by semarie@ job@
    
    OpenBSD-Commit-ID: b78a34d605c47cb145e16a3bba295caa0e9db680

commit e0f85d83ccc15b1b218fa8a000fc29a2e3d2defd
Author: job@openbsd.org <job@openbsd.org>
Date:   Tue Sep 22 22:51:43 2026 +0000

    upstream: Check that compressed payloads don't inflate beyond the
    
    maximum payload length
    
    From a report by Oleh Konko (1seal)
    
    OK djm@
    
    OpenBSD-Commit-ID: a0d3e7aa432777c28bfe23e5447ac117d6c151d9

commit ed67a24515aa65fded1e10426198a4251f836338
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 22 22:30:27 2026 +0000

    upstream: ssh-agent: no unlink(2) on empty filename
    
    from markus@ ok me
    
    OpenBSD-Commit-ID: 7a517a64389e389e5d23f781d1762c2b6aaffe98

commit d4ed84e4cb15305d763a3acb16d8cf8693c65840
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 22 22:29:27 2026 +0000

    upstream: ssh-agent: fix socket cleanup for -a option (no pathspec)
    
    from markus@ ok me
    
    OpenBSD-Commit-ID: 3194c1ed609eaa05932b9f6036ace7561e140627

commit 1d5340fce24526719e32aebc4c721fc228182ace
Author: job@openbsd.org <job@openbsd.org>
Date:   Tue Sep 22 04:38:09 2026 +0000

    upstream: Disable LZ77 dictionary coder to avoid a potential
    
    side-channel leak
    MIME-Version: 1.0
    Content-Type: text/plain; charset=UTF-8
    Content-Transfer-Encoding: 8bit
    
    A chosen-plaintext attack method exists which makes use of
    dictionary-based compression to recover secrets from one channel by
    interacting with the SSH session's shared compression dictionary through
    another channel.
    
    Attacker-controlled input can recognizably reflect into the total length
    of transmitted ciphertexts by virtue of LZ77 replacing repeated strings
    with back-references into the SSH session's encoder search buffer,
    which is shared across all channels. For this reason, the documentation
    already recommended against enabling compression for connections that
    share trusted and untrusted traffic.
    
    As an extra precaution, use only Huffman coding when compressing
    plaintexts, as this algorithm does not use a dictionary. But, this
    results in a reduction of compression effectiveness.
    
    Inspired by "Crossing the Streams: SSH Plaintext Recovery via a Common
    Compression Context in Multiplexed Channels." by Fabian Bäumer and
    Marcus Brinkmann, preprint https://arxiv.org/abs/2609.07709 (2026)
    
    OK djm@ dtucker@
    
    OpenBSD-Commit-ID: 839e5e53ad76786d0e90bed530304e4e13acbba0

commit ccc26c76cd47ca224ff5e4ef8b96007b65ff0b4e
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 22 03:26:32 2026 +0000

    upstream: check ssh's handling of stale multiplexing sockets From Jens
    
    Rosenboom
    
    OpenBSD-Regress-ID: 875302cf1f6546fe316ef7ca6f2cf24be12ad23f

commit 2a72e9755bdd63c3a4b6a25437a63e8b5eef23a4
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 22 03:22:00 2026 +0000

    upstream: avoid race between multiple processes attempting to
    
    establish multiplexing control socket by moving socket creation earlier in
    ssh(1)'s life. Patch from Jens Rosenboom via bz3971
    
    ok naddy dtucker
    
    OpenBSD-Commit-ID: 8361fb1cd20668216e06c9ba7b4ce72b2ba56fb7

commit 941d7632096abd37bb10826cf8f08c5cfb99ccc4
Author: dtucker@openbsd.org <dtucker@openbsd.org>
Date:   Tue Sep 22 00:24:47 2026 +0000

    upstream: Include local and remote versions in ~I connection info.
    
    ok job@ djm@.
    
    OpenBSD-Commit-ID: 8cc5d41e5e034e86de66c1e3bfda52c95f0e1c52

commit a765b86d03c442bfbe1144ac4f180c8ff9f543c4
Author: Darren Tucker <dtucker@dtucker.net>
Date:   Tue Sep 22 11:44:31 2026 +1000

    Remove the NetBSD BROKEN_READ_COMPARISON workaround.
    
    It does not seem to be needed on current versions, and it can cause
    pre-auth CPU spinning now that we're using atomicio() in the banner
    exchange.  ok djm@

commit a5094d4ec9046d5e0a26eb040ce69f05b61f535b
Author: Darren Tucker <dtucker@dtucker.net>
Date:   Sun Sep 20 18:06:27 2026 -0600

    Ignore build/install status of netcat in tests.
    
    If it fails (such as right now, since the hosts are missing a header
    change) but the old binary works for our purposes we can still run the
    tests we care about.

commit ffdb78080ffd97ccbb0a7af6737407e6963f362d
Author: Darren Tucker <dtucker@dtucker.net>
Date:   Sun Sep 20 15:46:31 2026 -0600

    Add FreeBSD 15 test targets.

commit eabf1987de772f0f2d772fd6bd72b4c84d0ab780
Author: dtucker@openbsd.org <dtucker@openbsd.org>
Date:   Sun Sep 20 01:05:55 2026 +0000

    upstream: Better wording.
    
    OpenBSD-Commit-ID: d8594787882a3cced845333bed4d222cc2427f1e

commit 62ed23d2f79616f86881da7d5e114b14bed7decc
Author: jsg@openbsd.org <jsg@openbsd.org>
Date:   Fri Sep 18 12:06:46 2026 +0000

    upstream: use Nm instead of Xr to self
    
    OpenBSD-Commit-ID: 5f298d9a35396cf82e70ed56af00617953d7dea4

commit b836083ed96a0f7b729d84d066cc657e6616112f
Author: Darren Tucker <dtucker@dtucker.net>
Date:   Sat Sep 19 15:13:55 2026 -0600

    Don't deref NULL on STREAMS tty alloc failure.

commit bc41d062cc0f305e49d58430b467c3ce8c822a87
Author: dtucker@openbsd.org <dtucker@openbsd.org>
Date:   Thu Sep 17 18:12:10 2026 +0000

    upstream: Plug leak. CID 913600.
    
    OpenBSD-Commit-ID: 24e1380bb4dbd11563e5a424dbee3255861aea6b

commit 967d4d0c0e386a71faee632deed4f1721e65b797
Author: schwarze@openbsd.org <schwarze@openbsd.org>
Date:   Thu Sep 17 15:32:07 2026 +0000

    upstream: an abbreviation ending in a dot at EOL requires escaping
    
    to not be treated as the end of a sentence, and add a handful of missing
    Oxford commas
    
    OpenBSD-Commit-ID: 0089fc774761080acb2204f6b1763db116bce939

commit 8359ec1f8b8a82f8e991ee2254d389d90a97a103
Author: schwarze@openbsd.org <schwarze@openbsd.org>
Date:   Thu Sep 17 15:27:05 2026 +0000

    upstream: tweak 1.406: minor wording and markup OK djm@
    
    OpenBSD-Commit-ID: 0140adabc2e9f04a6e297a8f58c3abf8bfcc5958

commit 3994b0bbedcde9d6a6cdecd23ab69b1955bc9611
Author: jsg@openbsd.org <jsg@openbsd.org>
Date:   Wed Sep 16 23:26:41 2026 +0000

    upstream: draft-ietf-sshm-ssh-agent became RFC 9987 ok dtucker@
    
    OpenBSD-Commit-ID: 78dca1a628c17adfebfa0d9b4ee5b3ce199d767f

commit a6fd293a3aeee640e41877078afd6a67e8ec5adb
Author: Darren Tucker <dtucker@dtucker.net>
Date:   Thu Sep 17 12:15:04 2026 -0600

    Remove leftover from testing.

commit fb6d39e619f721ff588719c3ac8d417c0ebcffce
Author: Darren Tucker <dtucker@dtucker.net>
Date:   Thu Sep 17 07:51:31 2026 +1000

    Add fallback for mkdir_path() without openat().
    
    Fixes builds on pre POSIX.1-2008 systems.

commit a738c19f9c197b13fcbc057c3c0d826fc1cd373c
Author: dtucker@openbsd.org <dtucker@openbsd.org>
Date:   Wed Sep 16 17:31:27 2026 +0000

    upstream: Use >= instead of > for max comparison so that the
    
    expression is not always false.  Should fix CIDs 913601 and 913602.
    
    OpenBSD-Commit-ID: b5d35e1ddd185dda9389a1b5202a382c1b68f002

commit 92120fec22e1b5df570c2d1860eee4613ed86e10
Author: dtucker@openbsd.org <dtucker@openbsd.org>
Date:   Wed Sep 16 16:46:07 2026 +0000

    upstream: Use equality not assignment in ternary. CID 913600.
    
    OpenBSD-Commit-ID: 83253cc2a81886b513b2880ec634531635893a98

commit efea9b3cb3ead7191ee8d81348479750e6eeb0db
Author: jsg@openbsd.org <jsg@openbsd.org>
Date:   Wed Sep 16 07:47:29 2026 +0000

    upstream: spelling; ok deraadt@
    
    OpenBSD-Commit-ID: 3c8e4604f2b7a1adb590ab4a42afd2f6c653be46

commit d0078f850832f428cf3ac2c48f20c5414d1d619b
Author: Darren Tucker <dtucker@dtucker.net>
Date:   Wed Sep 16 11:11:44 2026 -0600

    Also skip scp3 test on Darwin 26 and 27.

commit a253258c6d9ed991d7390f0d5569f83f189eab75
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 06:23:15 2026 +0000

    upstream: convert channel timeouts to use floating points, allows
    
    fractional and subsecond timeouts; ok markus, deraadt
    
    OpenBSD-Commit-ID: f25665fc4e734ade36f6cb631dc28c6c54bb9e76

commit 43f59b81017e3a80f8683044eaaab1621063eae1
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 06:12:42 2026 +0000

    upstream: masking signals requried sigaddset, not sigdelset; bz3981
    
    OpenBSD-Commit-ID: 9a85d68149d2840201cb59ca39ae5eb24bff0d80

commit 3c11ea405486b5ec08f56b7d181ab77e98fdb96b
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 05:10:12 2026 +0000

    upstream: bz3635 - ssh-add -P to skip PIN entry
    
    ok dtucker
    
    OpenBSD-Commit-ID: ca89f9cdc1dad7b5d28d55e342e4e110e7cc3d98

commit a30bafcbbd44dc4dc91916240c32ecabff899338
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 04:56:12 2026 +0000

    upstream: simpler
    
    OpenBSD-Regress-ID: c7f30b865abd0b3e0e5514f861509c32e352a760

commit 600eca5cfd7e054af1d4d15394c474df07ae2d44
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 05:03:07 2026 +0000

    upstream: leaks on error paths; spotted by Coverity CID 913598
    
    OpenBSD-Commit-ID: 70cde2c42ea549b6f8aff523428e221aad4be1d8

commit 56c1d08b6c5c2ec867c3ebf2e68a283ccb5b1701
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 05:00:51 2026 +0000

    upstream: fix inverted logic that could cause a memleak; spotted en
    
    passant by Coverity CID 913599
    
    OpenBSD-Commit-ID: 72f712175bdf2daf660d4dd193316681aa9eed94

commit e158e008a851c8679ddceab5450338883cf258dc
Author: dtucker@openbsd.org <dtucker@openbsd.org>
Date:   Wed Sep 16 04:12:42 2026 +0000

    upstream: Add missing semicolon after return. CID 913599, ok
    
    deraadt@
    
    OpenBSD-Commit-ID: d44361633f2791eeeb4bd160bebedf3ad07a9c05

commit ded92bffa2e2f2db9b83245c5061812791bfa47f
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 04:51:28 2026 +0000

    upstream: correctly check sshauthopt->restricted merging
    
    OpenBSD-Regress-ID: e81e9267514338d6cf6bd2f83dcb722538af528e

commit e3cb2b2278c265072d6ba6f0adf30b5dec0fbcd8
Author: Damien Miller <djm@mindrot.org>
Date:   Wed Sep 16 12:28:40 2026 +1000

    unbreak readpassphrase.c sync

commit 58db2ec9cac0d391b9c0f353a13b516e132f890a
Author: Damien Miller <djm@mindrot.org>
Date:   Wed Sep 16 11:26:40 2026 +1000

    sync readpassphrase(3) with OpenBSD libc
    
    Should fix bz3995: ssh-add spins when started in a background group,
    with no controlling tty and with certain signals ignored.

commit bc15793b2abce850340be6c0b36b83c330c7a887
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:59:12 2026 +0000

    upstream: whitespace
    
    OpenBSD-Commit-ID: b8d7e0a0b7b1a15941df5bfa91998f988e2346e2

commit fc5bed4b1c71441db27b8040bfcae237f1786656
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:45:03 2026 +0000

    upstream: adapt to libsodium ed25519 implementation
    
    OpenBSD-Regress-ID: d084e761416cea1f00d4f295aa92b737b28cebae

commit c5c4ca2b77fa8f4498d46d59dde81a57111c5660
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:46:17 2026 +0000

    upstream: missing part of previous commit: update script to
    
    import ed25519 implementation from libsodium
    
    OpenBSD-Commit-ID: 1f3d60686a8ce15212d8730814dfb8213fdf96ac

commit eab91661367a61debb1fcf94b46fff4278999f81
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:43:00 2026 +0000

    upstream: switch from SUPERCOP ed25519 to libsodium
    
    The libsodium implementation includes a number of strictness and
    malleability checks over the original reference implementation we
    have used to this point.
    
    libsodium also offers a more traditional "detached" signature
    verification API (SUPERCOP required the signature to be contiguous
    with the signed data). Switch to this and avoid a bunch of fiddly
    code.
    
    ok markus, deraadt
    
    OpenBSD-Commit-ID: ea9c958435790c391b031bd9f0599f1ebf48d516

commit 6f9cd19af05aa828d7778cfb047faaed1679e8b7
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:37:52 2026 +0000

    upstream: Only store GSSAPI creds when authn succeeds
    
    Issue report and patch from Moritz Theile
    
    ok markus, deraadt
    
    OpenBSD-Commit-ID: 812bbd22b8dd5a1583094ab2b6ff0045e4088467

commit 670510d1e190b0f4e47066f24498c04ada1da0f0
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:37:07 2026 +0000

    upstream: Reset GSSAPI client state before authentication
    
    Avoids situation where a partially-completed GSSAPI authentication attempt
    can retain state that is subsequently used by a later attempt.
    
    Report and feedback Moritz Theile, also reported by several others.
    
    ok markus, deraadt
    
    OpenBSD-Commit-ID: 95758f23e358b7c19e6205ac1c979193a9145556

commit 526fd2771342f36142099bec82c49ce0457c5016
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:35:09 2026 +0000

    upstream: Correctly handle some options that accept "none"
    
    Some options, including AuthorizedPrincipalsFile were documented as accepting
    "none" as a way to disable them, however when overriddes by a ssh_config(5)
    Match keyword, this argument was being interpreted as a literal file.
    
    With Chris Rohlf in collaboration with Claude and Anthropic Research
    
    ok markus, deraadt
    
    OpenBSD-Commit-ID: 802f3a7695eba20924c05e500b0ecd34ec877756

commit 991f1f31dde2797416acaf4319dbebe764446c6f
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:33:44 2026 +0000

    upstream: Propagate authorized_keys "resrict" keyword
    
    The "restrict" keyword was not pervasively being applied to TunnelForwarding
    connections (which are administratively disabled by default). This is a
    separate problem to the one fixed in openssh-10.5
    
    reported by several people; ok markus, deraadt
    
    OpenBSD-Commit-ID: 8c36c31dc2bdbc0c432d1056496b2f1ce93198d1

commit 65666f4e820051da00c4a8ef0b1555a9f881050a
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:31:27 2026 +0000

    upstream: Check key and CA sig type during key parsing
    
    Checks key type and CA signature algorithm allowlists as early as
    possible during public key deserialisation.
    
    Use this in the client and server to reduce attack surface from
    disallowed key/signature types.
    
    With Chris Rohlf in collaboration with Claude and Anthropic Research
    
    ok markus, deraadt
    
    OpenBSD-Commit-ID: b03cb3755506231a742eed844f269524812f560a

commit 813f670ccc086aeb48ca6bf701e6a73c098a65bb
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:29:44 2026 +0000

    upstream: Add WarnWeakCrypto to sshd
    
    This option was previously available for the client only. This adds it to
    sshd, so allow logging of non-PQ key exchanges.
    
    ok markus, deraadt
    
    OpenBSD-Commit-ID: 524564b82a7a20a4ff984c948fb75aa2b0f9b707

commit cee6aedb1a176959164ab92556402e316469b8fb
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:25:50 2026 +0000

    upstream: Allow specification of agent socket directories
    
    Add AgentSocketPath for sshd_config and -A flag for ssh-agent.
    
    Agent socket directories may be shared or user-specific.
    
    Shared directories (specified like "shared:/tmp") will cause the listening
    program to create a temporary subdirectory ssh-XXXXXXXXXX under the requeted
    path to hold the socket. This supports the old sshd/ssh-agent behaviour before
    we switched to the socket directory being under ~/.ssh/agent
    
    User-specific directories just create the socket directly in the requested
    directory. This is the default, as user:.ssh/agent
    
    bz3860; ok markus, deraadt
    
    OpenBSD-Commit-ID: 91b95d02f376ad8959ffb23902cc115a0b74d9bf

commit 14843e73b970e248b785d84df0e54ae9f3992cff
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:16:52 2026 +0000

    upstream: Account pubkey checks separately to auth attempts
    
    Add a `PubkeyOptions max-pk-ok:nnnn` option to allow PK_OK tests (asking
    whether the server might accept a given public key) that do not count
    against MaxAuthTries, defaulting to 6 attempts.
    
    After these attempts are exhausted, futher attempts count as failed
    authentications against MaxAuthTries.
    
    ok markus, deraadt
    
    OpenBSD-Commit-ID: 4a02d2f303f4d83c10871221dce1db1f9fe2936f

commit 8895b5ae1b638148d35c2ee0b0726c66cdd39fd0
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:13:58 2026 +0000

    upstream: Extend TCPKeepAlive to support forwardings too
    
    This allows the existing client and server TCPKeepAlive option to optionally
    enable keepalives on TCP connections that are created for forwardings.
    
    Previously this option controlled keepalives on the connection socket only.
    
    TCPKeepAlive "yes" or "transport" enables keepalives on the connection
    socket. "TCPKeepAlive all" additionally enables them for forwarding
    sockets.
    
    bz3921. ok markus, deraadt
    
    OpenBSD-Commit-ID: c29b075968e6fa88fd9773bdea8174e70229262e

commit 0f90a8417bf6063b661cc3069b9f5a7d19c69242
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 16 00:08:52 2026 +0000

    upstream: Mask SIGTERM/SIGQUIT when processing a SIGHUP restart
    
    request. This ensures that these signals are subsequently delivered after the
    restart has been completed, rather than ignored. bz3981
    
    OpenBSD-Commit-ID: a69ff4121882583edcba319fa40adfc6ba75377c

commit ae7373dfe1e967036cdb948b814bb1eca78bc5ff
Author: Damien Miller <djm@mindrot.org>
Date:   Tue Sep 15 21:17:51 2026 +1000

    fix merge botch that put lines in wrong function
    
    sdirent_cmp() looked similar enough to sglob_cmp() for patch

commit aef20dfe30e68a469911a229b9117e7134766311
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 15 08:31:46 2026 +0000

    upstream: Correct handling of DST when converting dates
    
    Timestamps conversion was ignoring Daylight Savings Time (DST) causing
    date conversions to be +/-1 hour under some circumstances.
    
    bz4004; from Khush Patel, ok deraadt
    
    OpenBSD-Commit-ID: bd5eb2603c04d4b5072b0e593b137a98ef75b731

commit e1d1c95160f75e50890fad446aa2f89216037a9f
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 15 08:28:26 2026 +0000

    upstream: sk-usbhid: preserve UV requirement for resident keys
    
    When loading resident credentials, derive SSH_SK_USER_VERIFICATION_REQD
    directly from the credential's credProtect policy.
    
    The previous code only preserved the flag when the authenticator did not
    report the uv capability. As a result, UV_REQUIRED credentials downloaded
    from authenticators with built-in UV were saved with flags 0x21 instead
    of 0x25.
    
    Do not make preservation of the credential policy depend on the
    authenticator's current UV capability. Keep compatibility with libfido2
    versions without fido_cred_prot().
    
    GHPR701 from Savely Krasovsky
    
    OpenBSD-Commit-ID: ece9e236cdb6a2b7e973fdc266801f65a3feb12e

commit 961cc92164f0a68f93d1c8dfdf12fa807c3ab8ab
Author: job@openbsd.org <job@openbsd.org>
Date:   Tue Sep 15 08:26:49 2026 +0000

    upstream: Fix memory leak on an error path in mkdir_path
    
    CID 913589
    
    OK djm@
    
    OpenBSD-Commit-ID: 0050b75ec87722e115d33a3d181a3c24175079e5

commit 805388d59d82e80c2f07fefa9e1d28a7aa1ce3fc
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 15 08:17:57 2026 +0000

    upstream: sftp: don't crash when glob(3) results lack stat information
    
    Avoid NULL deref crashes when remote glob(3) results lack stat
    information. This can happen if the sftp server selectively fails
    a stat/lstat operation.
    
    GHPR707 from Nguyễn Anh Bình
    
    OpenBSD-Commit-ID: d76b6fe49bfe1b53908d83cf67ab624b7436279f

commit b99b84822cce120af6faf958d258b6f4b8dfc2c2
Author: Mike Frysinger <vapier@chromium.org>
Date:   Sun Jul 12 20:48:13 2026 +0545

    openpty: mark inputs const
    
    This matches BSD & GNU implementations.

commit fb9aad71c9ea8c62a3c3216013f26afd88d055b9
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Wed Sep 2 00:39:18 2026 +0000

    upstream: replace testing of vendor PQ signature algorithm
    
    "ssh-mldsa44-ed25519@openssh.com" with the IANA-registered
    "ssh-mldsa44-ed25519"
    
    OpenBSD-Regress-ID: 294c729668844a63f90c7fc0d7bbdcf4bb732ad8

commit 2eff38e46faddf19cba5d206a2e5bd2e6db607a2
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 15 08:00:01 2026 +0000

    upstream: minor leak of fingerprint text when printing
    
    certificates. bz3997 from Ekaterina Esina
    
    OpenBSD-Commit-ID: a837c2e113b42df3d58c9db783d2992f1ba1f0e0

commit 9713aaa65fc5d49d717e9819a82b5a6fd4b8f5cb
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 15 07:40:58 2026 +0000

    upstream: the default KDF rounds for keys generated by ssh-keygen
    
    is 24, not 16 bz3975; from lbrick
    
    OpenBSD-Commit-ID: 68030733eb680a817bcbd371793824f6aafc538a

commit d9166333616f4575749e64873796ad6a96f01c93
Author: Colin Watson <cjwatson@debian.org>
Date:   Tue Sep 1 01:14:44 2026 +0100

    Don't link sshd against libselinux
    
    When configured with --with-selinux, the main sshd binary only appears
    to need symbols from libselinux because functions that it needs are in
    the same translation units as functions that use libselinux, meaning
    that `ld --as-needed` doesn't realize that it can drop those functions
    and the resulting DT_NEEDED tag.
    
    This should have the effect of dropping libselinux and libpcre2-8 from
    sshd's linkage in the configuration used by several common Linux
    distributions, including Debian.

commit a92ec36c73a0026fd75ac48810f215167cf33dcb
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 15 07:08:09 2026 +0000

    upstream: warnings fixes (static vs missing prototype, sign conversion)
    
    OpenBSD-Commit-ID: 9c9eca0844dd7205597c6a4bd6f97d868ca2a74c

commit 563087a648e1490582582381ac723c85ad6f457c
Author: Damien Miller <djm@mindrot.org>
Date:   Tue Sep 15 17:00:01 2026 +1000

    sshd doesn't need sshpty.c any more

commit 6d558485ffdbd671cd340483799082330ce7d858
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 15 06:49:51 2026 +0000

    upstream: wrap line
    
    OpenBSD-Commit-ID: 14b59bf44214a9f46d6f0b5281f94420ef0fc888

commit 21abb626291ad14029f86fafc97a78f4af6848f9
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 15 06:47:42 2026 +0000

    upstream: g/c prototype
    
    OpenBSD-Commit-ID: a55c5782dc733fa66b28085abdb10c39cb4d2a2e

commit a7f490e1e3d758df1ccd42a70f2ca47d7a09fe89
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 15 06:30:58 2026 +0000

    upstream: disconnect_controlling_tty() is the only thing from sshpty.c
    
    used in sshd, and sshd is the only thing that calls this function.
    
    Move it into sshd.c and we no longer need to compile sshd against
    sshpty.c
    
    Part of bz3996 from Colin Watson
    
    OpenBSD-Commit-ID: cbfb0ecba5c63852d33e930d01f00586ce15ad1d

commit 02cf3c2bd6150c359b0da8f1e25994e4e9214d3f
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 15 06:05:47 2026 +0000

    upstream: Fix ChannelTimeout specificity
    
    Previously a more specific channel type (e.g. "session:shell") could
    clobber a user-specified ChannelTimeout if it was less specific
    (e.g. "session").
    
    Also, in some cases, the debug messages were printing 0 instead of the
    effective timeout.
    
    From Bhagavathiyappan Shanmugam <Bhagavathiyappan.Shanmugam@ibm.com>
    via bz3994
    
    OpenBSD-Commit-ID: ba88e80db4957b98dfc0cc3b93a8d6d34e18d32d

commit 78db1b7e9f70c9ec827476dbae7fc8ca7d127815
Author: Damien Miller <djm@mindrot.org>
Date:   Tue Sep 15 15:37:02 2026 +1000

    allow madvise(..., MADV_DONTNEED_LOCKED)
    
    allow MADV_DONTNEED_LOCKED in the seccomp sandbox; needed by GrapheneOS'
    hardened allocator. bz4001

commit 8abd726ee36ddfabdbee50c325264d68d99ff21c
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 15 05:16:43 2026 +0000

    upstream: fix case for ssh -G option output; bz4005, reported by
    
    Khush Patel
    
    OpenBSD-Commit-ID: 7ad9df4697b653c21253cea94bf95b87e7108717

commit 7f671c49eba7b1eacaf4ca35e9f4b65cef14fa8a
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Mon Sep 14 02:40:27 2026 +0000

    upstream: mux proxy sockets also share in and out fds, so using
    
    this as a heuristic to decide whether the connection is on an inet/inet6
    socket is incorrect.
    
    Fixes breakage in t-multiplex after recent pledge(2) changes where
    the packet code would attempt to set TCP_NODELAY on a mux proxy
    connection (which is AF_UNIX).
    
    OpenBSD-Commit-ID: f6706e90d499ac0a22322df11935205f38c5ae85

commit 4fc22252c403d5a996a9921f3b7f9b2c5c972645
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Mon Sep 14 02:38:27 2026 +0000

    upstream: don't attempt to set TCP_NODELAY on non-AF_INET[6]
    
    sockets. Fixes some of the regress failures in t-multiplex after recent
    pledge(2) strictification.
    
    OpenBSD-Commit-ID: ff64648747176a3192c97df50d6a8fb66b926828

commit 7cc27ceb87d4707323ba682a6b03f1810971167f
Author: djm@openbsd.org <djm@openbsd.org>
Date:   Tue Sep 8 02:55:58 2026 +0000

    upstream: add a "hexdump" export mode that dumps the key blob in
    
    hex format. Very useful when writing internet-drafts.
    
    E.g. ssh-keygen -em hexdump -f /path/key
    
    OpenBSD-Commit-ID: 922f997de2c691cf7ddf4067a5406d39b36b25ef

commit d991f23d451c0c862ba7d14144f4ea44e1fb2a88
