diff options
author | djm@openbsd.org <djm@openbsd.org> | 2019-03-01 02:32:39 +0000 |
---|---|---|
committer | Damien Miller <djm@mindrot.org> | 2019-03-01 13:34:00 +1100 |
commit | 76a24b3fa193a9ca3e47a8779d497cb06500798b (patch) | |
tree | e0481606d35b25110206aefa6024588827f86996 /auth-skey.c | |
parent | de817e9dfab99473017d28cdf69e60397d00ea21 (diff) |
upstream: Fix two race conditions in sshd relating to SIGHUP:
1. Recently-forked child processes will briefly remain listening to
listen_socks. If the main server sshd process completes its restart
via execv() before these sockets are closed by the child processes
then it can fail to listen at the desired addresses/ports and/or
fail to restart.
2. When a SIGHUP is received, there may be forked child processes that
are awaiting their reexecution state. If the main server sshd
process restarts before passing this state, these child processes
will yield errors and use a fallback path of reading the current
sshd_config from the filesystem rather than use the one that sshd
was started with.
To fix both of these cases, we reuse the startup_pipes that are shared
between the main server sshd and forked children. Previously this was
used solely to implement tracking of pre-auth child processes for
MaxStartups, but this extends the messaging over these pipes to include
a child->parent message that the parent process is safe to restart. This
message is sent from the child after it has completed its preliminaries:
closing listen_socks and receiving its reexec state.
bz#2953, reported by Michal Koutný; ok markus@ dtucker@
OpenBSD-Commit-ID: 7df09eacfa3ce13e9a7b1e9f17276ecc924d65ab
Diffstat (limited to 'auth-skey.c')
0 files changed, 0 insertions, 0 deletions