diff options
author | semarie@openbsd.org <semarie@openbsd.org> | 2015-12-03 17:00:18 +0000 |
---|---|---|
committer | Damien Miller <djm@mindrot.org> | 2015-12-04 15:14:59 +1100 |
commit | b91926a97620f3e51761c271ba57aa5db790f48d (patch) | |
tree | ab1f30a7c36b682e33e97ef4dfa852c4abc7f734 /mux.c | |
parent | bcce47466bbc974636f588b5e4a9a18ae386f64a (diff) |
upstream commit
pledges ssh client: - mux client: which is used when
ControlMaster is in use. will end with "stdio proc tty" (proc is to
permit sending SIGWINCH to mux master on window resize)
- client loop: several levels of pledging depending of your used options
ok deraadt@
Upstream-ID: 21676155a700e51f2ce911e33538e92a2cd1d94b
Diffstat (limited to 'mux.c')
-rw-r--r-- | mux.c | 11 |
1 files changed, 10 insertions, 1 deletions
@@ -1,4 +1,4 @@ | |||
1 | /* $OpenBSD: mux.c,v 1.55 2015/10/15 23:51:40 djm Exp $ */ | 1 | /* $OpenBSD: mux.c,v 1.56 2015/12/03 17:00:18 semarie Exp $ */ |
2 | /* | 2 | /* |
3 | * Copyright (c) 2002-2008 Damien Miller <djm@openbsd.org> | 3 | * Copyright (c) 2002-2008 Damien Miller <djm@openbsd.org> |
4 | * | 4 | * |
@@ -1851,6 +1851,9 @@ mux_client_request_session(int fd) | |||
1851 | mm_send_fd(fd, STDERR_FILENO) == -1) | 1851 | mm_send_fd(fd, STDERR_FILENO) == -1) |
1852 | fatal("%s: send fds failed", __func__); | 1852 | fatal("%s: send fds failed", __func__); |
1853 | 1853 | ||
1854 | if (pledge("stdio proc tty", NULL) == -1) | ||
1855 | fatal("%s pledge(): %s", __func__, strerror(errno)); | ||
1856 | |||
1854 | debug3("%s: session request sent", __func__); | 1857 | debug3("%s: session request sent", __func__); |
1855 | 1858 | ||
1856 | /* Read their reply */ | 1859 | /* Read their reply */ |
@@ -1996,6 +1999,9 @@ mux_client_request_stdio_fwd(int fd) | |||
1996 | mm_send_fd(fd, STDOUT_FILENO) == -1) | 1999 | mm_send_fd(fd, STDOUT_FILENO) == -1) |
1997 | fatal("%s: send fds failed", __func__); | 2000 | fatal("%s: send fds failed", __func__); |
1998 | 2001 | ||
2002 | if (pledge("stdio proc tty", NULL) == -1) | ||
2003 | fatal("%s pledge(): %s", __func__, strerror(errno)); | ||
2004 | |||
1999 | debug3("%s: stdio forward request sent", __func__); | 2005 | debug3("%s: stdio forward request sent", __func__); |
2000 | 2006 | ||
2001 | /* Read their reply */ | 2007 | /* Read their reply */ |
@@ -2159,6 +2165,9 @@ muxclient(const char *path) | |||
2159 | } | 2165 | } |
2160 | set_nonblock(sock); | 2166 | set_nonblock(sock); |
2161 | 2167 | ||
2168 | if (pledge("stdio sendfd proc tty", NULL) == -1) | ||
2169 | fatal("%s pledge(): %s", __func__, strerror(errno)); | ||
2170 | |||
2162 | if (mux_client_hello_exchange(sock) != 0) { | 2171 | if (mux_client_hello_exchange(sock) != 0) { |
2163 | error("%s: master hello exchange failed", __func__); | 2172 | error("%s: master hello exchange failed", __func__); |
2164 | close(sock); | 2173 | close(sock); |