OpenSSH 10.6p1 がリリースされました
2026/10/06, OpenSSH 10.6p1 がリリースされました.
- OpenSSH 10.6p1 Release Note 中の OpenSSH 10.6 での変更点のまとめ
- この記事にも添付します.
- OpenSSH 移植版付属文書の翻訳
# https://www.openssh.org/releasenotes.html#10.6
Future deprecation notice
-------------------------
将来非推奨となる機能の告知
* scp(1): begin deprecating the -R flag, which is used to perform a
remote-to-remote copy by executing scp on a remote host. This
option is a fragile optimisation that is difficult to use because
it requires credentials on the remote host. It also creates
security risks if the shell quoting rules on the remote system
where the copy is performed differ from the client's expectations.
scp(1): リモートホスト上で scp を実行することでリモートからリモートへの
コピーを行うために使われる -R フラグの非推奨化を開始する。このオプションは
リモートホスト上に認証情報を必要とするため使いにくい、壊れやすい最適化
である。また、コピーが実行されるリモートシステムのシェルのクオート規則が
クライアントの想定と異なる場合、セキュリティ上のリスクを生じる。
From OpenSSH 10.6, this option will continue to work but will
cause a deprecation warning to be emitted to standard error. In
a future release, the option will be ignored and will leave in
place the default remote-to-remote copy behaviour (copy via the
host running scp).
OpenSSH 10.6 からは、このオプションは引き続き動作するが、標準エラー出力に
非推奨の警告が出力される。将来のリリースでは、このオプションは無視され、
デフォルトのリモートからリモートへのコピーの挙動 (scp を実行している
ホストを経由したコピー) のままとなる。
* sshd(8): support for platforms that do not allow file descriptor
passing and that also require root privilege for PTY allocation
will be removed in a future release. Affected platforms are known
to include SCO OpenServer 5 and QNX 6 but may include other
similarly old operating systems. This deprecation can be avoided
if the user community for these platforms is able to assist us in
building alternatives, such as avoiding the need for root in PTY
allocation.
sshd(8): ファイル記述子の受け渡しができず、かつ PTY の割り当てに root
権限を必要とするプラットフォームのサポートは、将来のリリースで削除される。
影響を受けるプラットフォームには SCO OpenServer 5 と QNX 6 が含まれることが
わかっているが、同様に古い他のオペレーティングシステムも含まれる可能性が
ある。これらのプラットフォームのユーザーコミュニティが、PTY の割り当てに
root を必要としないようにするなどの代替手段の構築を支援してくれるなら、
この非推奨化は回避できる。
Potentially-incompatible changes
--------------------------------
互換性がなくなる可能性がある変更
* ssh(1), sshd(8): compression will be less effective as a result
of the change noted below in the "Security" section
ssh(1), sshd(8): 以下の「セキュリティ」の節に記載した変更の結果、
圧縮の効果が低くなる。
* ssh(1): destination usernames entered on the commandline are now
more stricly checked and will refuse usernames that include
backslash and dollar symbols. Usernames that are specified by
the "User" directive in configuration files are no subject to
these restrictions. This motivation for this change is mentioned
below in the "Security" section.
ssh(1): コマンドラインで入力された接続先のユーザー名がより厳密に
チェックされるようになり、バックスラッシュとドル記号を含むユーザー名は
拒否される。設定ファイルの "User" ディレクティブで指定されたユーザー名は
この制限の対象とならない。この変更の動機は、以下の「セキュリティ」の節で
述べる。
* sshd(8): on platforms that do not support file descriptor passing
and that require root for PTY allocation, the GatewayPorts and
StreamLocalForwarding options are forcibly disabled. The
motivation for this changes is discussed below in the "Security"
section.
sshd(8): ファイル記述子の受け渡しをサポートせず、かつ PTY の割り当てに
root を必要とするプラットフォームでは、GatewayPorts と
StreamLocalForwarding オプションが強制的に無効にされる。この変更の動機は、
以下の「セキュリティ」の節で議論する。
Changes since OpenSSH 10.5
==========================
OpenSSH 10.5 からの変更点
This release contains a number of security fixes, several new
features and some small bugfixes.
このリリースには、多数のセキュリティ修正、いくつかの新機能、いくつかの
小さなバグ修正が含まれている。
Security
========
セキュリティ
* sftp(1): more strictly validate paths returned from the server to
avoid some cases where a server could return paths that could
manipulate a recursive copy operation into writing outside its
target directory. Report and patch from Junghoon Cho.
sftp(1): サーバから返されたパスをより厳密に検証し、サーバが再帰コピー
操作を操作して対象ディレクトリの外へ書き込ませるようなパスを返しうる
いくつかのケースを回避する。Junghoon Cho による報告とパッチ。
* sshd(8): when GSSAPIAuthentication is in use, only store GSSAPI
credentials when authentication has succeeded. Avoids a situation
where credentials from a failed GSSAPIAuthentication attempt may
persist and be made inappropriately available if another
authentication subsequently succeeds. Issue report and patch from
Moritz Theile.
sshd(8): GSSAPIAuthentication が使われている場合、認証が成功したときに
のみ GSSAPI の認証情報を保存する。失敗した GSSAPIAuthentication の試行の
認証情報が残り、その後に別の認証が成功した場合に不適切に利用可能に
なってしまう状況を回避する。Moritz Theile による問題の報告とパッチ。
* sshd(8): reset GSSAPIAuthentication before authentication, avoiding
state from one authentication attempt being confused with that of
a later attempt. Report and feedback from Moritz Theile.
sshd(8): 認証の前に GSSAPIAuthentication をリセットし、ある認証の試行の
状態が後の試行の状態と混同されるのを回避する。Moritz Theile による報告と
フィードバック。
* sshd(8), ssh(1): disable LZ77 dictionary coder to mitigate the
side-channel leaks described in "Crossing the Streams: SSH
Plaintext Recovery via a Common Compression Context in
Multiplexed Channels" by Fabian Bäumer and Marcus Brinkmann,
preprint https://arxiv.org/abs/2609.07709 (2026)
sshd(8), ssh(1): Fabian Bäumer と Marcus Brinkmann による
"Crossing the Streams: SSH Plaintext Recovery via a Common Compression
Context in Multiplexed Channels" (プレプリント
https://arxiv.org/abs/2609.07709 (2026)) で述べられているサイドチャネル
による漏洩を緩和するため、LZ77 辞書符号化器を無効にする。
A chosen-plaintext attack method exists which makes use of
dictionary-based compression to recover secrets from one channel
by interacting with the SSH session's shared compression
dictionary through another channel.
辞書ベースの圧縮を利用し、別のチャンネルを通じて SSH セッションの共有
圧縮辞書とやりとりすることで、あるチャンネルから秘密を復元する選択平文
攻撃の手法が存在する。
Attacker-controlled input can recognizably reflect into the
total length of transmitted ciphertexts by virtue of LZ77
replacing repeated strings with back-references into the SSH
session's encoder search buffer, which is shared across all
channels. For this reason, the documentation already recommended
against enabling compression for connections that share trusted
and untrusted traffic.
LZ77 は、繰り返される文字列を、すべてのチャンネルで共有されている SSH
セッションの符号化器の探索バッファへの後方参照で置き換える。そのため、
攻撃者が制御する入力は、送信される暗号文の総長に識別可能な形で反映され
うる。この理由から、ドキュメントではすでに、信頼できる通信と信頼できない
通信を共有する接続では圧縮を有効にしないことを推奨していた。
This change will reduce the effectiveness of the Compression
option. Users are encouraged to use application-level compression
over the SSH protocol where possible, as this will typically be
more effective and will be completely immune to this type of
attack.
この変更により Compression オプションの効果は低下する。ユーザーは、可能な
場合には SSH プロトコル上でアプリケーションレベルの圧縮を使うことが
推奨される。通常はそのほうが効果的であり、この種の攻撃の影響を完全に
受けないからである。
* ssh(1): disallow '$' and '\' characters in usernames entered on
the command-line to avoid usernames from untrusted sources
yielding injection in shell context via ProxyCommand, Match exec,
etc. Usernames specified via the configuration files are not
subject this this control. Reported by SecBuddyF KeenLab Tencent
(CodeBuddy Security)
ssh(1): コマンドラインで入力されたユーザー名に '$' と '\' の文字を
許可しないようにし、信頼できないソースからのユーザー名が ProxyCommand や
Match exec などを経由してシェルのコンテキストでインジェクションを
引き起こすのを回避する。設定ファイルで指定されたユーザー名はこの制御の
対象とならない。SecBuddyF KeenLab Tencent (CodeBuddy Security) により
報告。
We continue to recommend against directly exposing ssh(1) and
other tools' command-lines to untrusted input. Mitigations such
as this can not be absolute given the variety of shells and user
configurations in use.
我々は引き続き、ssh(1) や他のツールのコマンドラインを信頼できない入力に
直接さらさないことを推奨する。使われているシェルやユーザーの設定は多様で
あるため、このような緩和策は完全なものにはなりえない。
* ssh-keygen(1): correct handling of Daylight Saving Time when
converting dates. Previous handling could cause errors of
up to +/- 1 hour (unless you are in the Antarctica/Troll
timezone, where the error could be +/- 2 hours). These errors
could result in creation of certificates with incorrect expiry
times. bz4004; from Khush Patel
ssh-keygen(1): 日付を変換する際の夏時間の扱いを修正する。以前の扱いでは
最大 +/- 1 時間の誤差が生じる可能性があった (Antarctica/Troll タイム
ゾーンにいる場合は、誤差が +/- 2 時間になる可能性があった)。これらの誤差に
より、有効期限が不正確な証明書が作成される可能性があった。 bz4004
Khush Patel による。
* sshd(8), ssh(1): ensure that compressed payloads don't inflate
past the maximum supported packet length. Reported by Oleh Konko.
sshd(8), ssh(1): 圧縮されたペイロードが、サポートされる最大のパケット長を
超えて展開されないことを保証する。Oleh Konko により報告。
* sshd(8): fully honor the authorized_keys "restrict" keyword,
which was not being properly applied to tunnel forwarding
(PermitTunnel, disabled by default). This is a separate problem
to the one fixed in openssh-10.5.
sshd(8): authorized_keys の "restrict" キーワードを完全に尊重する。
このキーワードはトンネル転送 (PermitTunnel, デフォルトで無効) に正しく
適用されていなかった。これは openssh-10.5 で修正されたものとは別の問題で
ある。
* sshd(8): correctly handle some options that accept "none". Some
options, including AuthorizedPrincipalsFile, were documented as
accepting "none" as a way to disable them; however, when
overridden by an sshd_config(5) Match keyword, this argument was
being incorrectly interpreted as a literal file.
With Chris Rohlf in collaboration with Claude and Anthropic Research
sshd(8): "none" を受け付けるいくつかのオプションを正しく扱う。
AuthorizedPrincipalsFile を含むいくつかのオプションは、無効にする方法と
して "none" を受け付けるとドキュメントに記載されていた。しかし、
sshd_config(5) の Match キーワードで上書きされた場合、この引数は誤って
文字通りのファイル名として解釈されていた。
Claude および Anthropic Research と協力した Chris Rohlf による。
* sshd(8): On OS X SDK >= 27, sandboxing is no longer supported
as the API we depended upon has been removed and no obvious
alternative provided.
sshd(8): OS X SDK >= 27 では、依存していた API が削除され、明確な代替が
提供されていないため、サンドボックスはもはやサポートされない。
* sshd(8): on platforms that do not support file descriptor passing
and that require root for PTY allocation, the post-authentication
sshd-session process retains root privilege, whereas on other
platforms this process runs with the privilege of the logged-in
user. When sshd-session was run with elevated privlege, it could
perform certain actions as root and circumvent controls that
would normally have applied to the user, such as making unix
domain socket connections or binding (via -R forwarding) to low-
numbered TCP ports.
sshd(8): ファイル記述子の受け渡しをサポートせず、かつ PTY の割り当てに
root を必要とするプラットフォームでは、認証後の sshd-session プロセスは
root 権限を保持する。一方、他のプラットフォームではこのプロセスは
ログインしたユーザーの権限で動作する。sshd-session が昇格した権限で
実行されている場合、特定の操作を root として実行でき、unix ドメイン
ソケットへの接続や (-R 転送経由での) 小さい番号の TCP ポートへのバインド
など、通常はユーザーに適用されるはずの制御を回避できた。
For this reason, this release disables the GatewayPorts and
StreamLocalForwarding options and support for these (few)
platforms will be removed in future if no alteratives to
requiring privilege in the post-authentication process are found.
Affected platforms include QNX 6, SCO OpenServer 5 and builds
that were made with the --disable-fd-passing configure option.
この理由から、このリリースでは GatewayPorts と StreamLocalForwarding
オプションを無効にする。また、認証後のプロセスで権限を必要とすることへの
代替手段が見つからない場合、これらの (少数の) プラットフォームの
サポートは将来削除される。影響を受けるプラットフォームには、QNX 6,
SCO OpenServer 5, --disable-fd-passing configure オプション付きで作成
されたビルドが含まれる。
This problem was reported separately by sn0x-sharma and by Dark
River.
この問題は sn0x-sharma と Dark River によりそれぞれ別々に報告された。
New features
------------
新機能
* All: enable hybrid post-quantum ssh-mldsa44-ed25519 signature
algorithm. Note that this no longer uses the "@openssh.com"
vendor extension suffix that the previous experimental
implementation used. Keys generated with the previous experimental
support must be regenerated and/or removed.
全体: ハイブリッド耐量子署名アルゴリズム ssh-mldsa44-ed25519 を有効に
する。以前の実験的な実装が使っていた "@openssh.com" ベンダー拡張
サフィックスはもはや使わないことに注意。以前の実験的なサポートで生成
されたキーは、再生成および/または削除しなければならない。
* sshd(8): Add the WarnWeakCrypto option to sshd_config(5). This
option was previously available for the client only. This option
is enabled by default and will log when the client uses a key
agreement scheme that is not post-quantum safe.
sshd(8): sshd_config(5) に WarnWeakCrypto オプションを追加する。この
オプションは以前はクライアントでのみ利用可能だった。このオプションは
デフォルトで有効で、クライアントが耐量子安全でない鍵合意方式を使った
場合にログを記録する。
* ssh-keygen(1), ssh-add(1): preserve user-verification (PIN or
biometric) requirement for resident keys loaded from a FIDO
token, by checking the credential's credProtect policy.
GHPR701 from Savely Krasovsky
ssh-keygen(1), ssh-add(1): 認証情報の credProtect ポリシーをチェック
することで、FIDO トークンから読み込まれた resident キーに対するユーザー
検証 (PIN または生体認証) の要求を保持する。 GHPR701
Savely Krasovsky による。
* ssh(1): include local and remote version strings in the ~I
connection information display.
ssh(1): ~I による接続情報の表示に、ローカルとリモートのバージョン文字列を
含める。
* ssh-add(1): add a -P flag to skip PIN entry for FIDO and PKCS#11
tokens that do not require it.
ssh-add(1): PIN を必要としない FIDO および PKCS#11 トークンに対して PIN の
入力をスキップする -P フラグを追加する。
* sftp(1): add '-p' flag for mkdir/lmkdir to create directories as
required. This flag has similar ergonomics to mkdir(1), and
previously-existing directories do not cause an error.
sftp(1): 必要に応じてディレクトリを作成する '-p' フラグを mkdir/lmkdir に
追加する。このフラグは mkdir(1) と同様の使い勝手で、すでに存在する
ディレクトリはエラーにならない。
* ssh-keygen(1): add a "hexdump" key export mode that dumps the SSH
wire-formatted key blob in hex format. Useful when writing
documentation, tests, etc. E.g. `ssh-keygen -em hexdump -f /key`
ssh-keygen(1): SSH のワイヤフォーマットのキー blob を 16 進形式で
ダンプする "hexdump" キーエクスポートモードを追加する。ドキュメントや
テストなどを書く際に便利である。例: `ssh-keygen -em hexdump -f /key`
* ssh(1), sshd(8): ChannelTimeout now accepts timeouts with
fractional seconds.
ssh(1), sshd(8): ChannelTimeout が小数の秒数のタイムアウトを受け付ける
ようになった。
* sshd(8): allow specification of the location of $SSH_AUTH_SOCK
used for agent forwarding using a new AgentSocketPath option.
This supports both using a user-specific path, such as the
default of a subdirectory of $HOME ("user:.ssh/agent"), and
the previous approach of allowing agent forwarding sockets to be
located in a shared directory (e.g. "shared:/tmp"). Sockets
created in shared directories will be created inside a
subdirectory with a randomised name. bz3860
sshd(8): 新しい AgentSocketPath オプションを使って、エージェント転送に
使われる $SSH_AUTH_SOCK の場所を指定できるようにする。これは、デフォルト
である $HOME のサブディレクトリ ("user:.ssh/agent") のようなユーザー固有の
パスを使うことと、エージェント転送のソケットを共有ディレクトリ
(例: "shared:/tmp") に置くことを許す以前の方法の両方をサポートする。
共有ディレクトリに作成されるソケットは、ランダムな名前のサブディレクトリ
内に作成される。 bz3860
* ssh-agent(1): allow specification of agent socket directories
using a -A flag. It accepts "user:" and "shared:" directory
styles similar to the sshd AgentSocketPath option.
ssh-agent(1): -A フラグを使ってエージェントのソケットのディレクトリを
指定できるようにする。sshd の AgentSocketPath オプションと同様に、
"user:" と "shared:" の形式のディレクトリを受け付ける。
* sshd(8): account for public key authentication "key ok" tests
separately to auth attempts. Add a `PubkeyOptions max-pk-ok:nnnn`
option to allow a number of PK_OK tests (asking whether the
server might accept a given public key) that do not count against
MaxAuthTries, defaulting to 6 attempts. After these attempts are
exhausted, further attempts count as failed authentications
against MaxAuthTries. Practically, this allows more keys on disk
or held in ssh-agent to be checked for use before the server
disconnects.
sshd(8): 公開鍵認証の "key ok" テストを認証の試行とは別に数える。
`PubkeyOptions max-pk-ok:nnnn` オプションを追加し、MaxAuthTries に
数えられない PK_OK テスト (サーバが与えられた公開鍵を受け入れるかどうかの
問い合わせ) の回数を指定できるようにする。デフォルトは 6 回である。
これらの試行を使い切った後は、それ以降の試行は MaxAuthTries に対する
認証の失敗として数えられる。実際には、これにより、サーバが切断する前に、
ディスク上や ssh-agent に保持されているより多くのキーを使用できるか
チェックできるようになる。
* ssh(1), sshd(8): extend the existing TCPKeepAlive option to also
support setting keepalives on sockets created for forwarding
connections. Previously this option controlled keepalives on the
connection socket only. TCPKeepAlive "yes" or "transport" enables
keepalives on the connection socket. "TCPKeepAlive all" additionally
enables them for forwarding sockets. bz3921
ssh(1), sshd(8): 既存の TCPKeepAlive オプションを拡張し、転送接続の
ために作成されたソケットにもキープアライブを設定できるようにする。以前は
このオプションは接続のソケットのキープアライブのみを制御していた。
TCPKeepAlive "yes" または "transport" は接続のソケットのキープアライブを
有効にする。"TCPKeepAlive all" はさらに転送のソケットのキープアライブも
有効にする。 bz3921
Bugfixes
--------
バグ修正
* sshd(8), ssh(1): fix configuration matching on more Turkic
languages which have disjoint dotted and dotless i/I characters,
specifically Azerbaijani and Crimean Tatar. bz3991
sshd(8), ssh(1): 点付きと点なしの i/I の文字が別々に存在するさらなる
テュルク系言語、具体的にはアゼルバイジャン語とクリミア・タタール語での
設定のマッチングを修正する。 bz3991
* ssh(1), sshd(8): don't attempt to set TCP_NODELAY on non-IP/IPv6
sockets. Eliminates some noise in debug logs.
ssh(1), sshd(8): IP/IPv6 でないソケットに TCP_NODELAY を設定しようと
しない。デバッグログのノイズを一部取り除く。
* ssh(1): fix case for ssh -G option output; bz4005
ssh(1): ssh -G オプションの出力の大文字小文字を修正する。 bz4005
* ssh(1), sshd(8): Fix ChannelTimeout specificity; previously a
more specific channel type (e.g. "session:shell") could clobber
a user-specified ChannelTimeout if it was less specific (e.g.
"session"). Also, in some cases, the debug messages were
printing 0 instead of the effective timeout. bz3994
ssh(1), sshd(8): ChannelTimeout の特定度を修正する。以前は、より特定的な
チャンネルタイプ (例: "session:shell") が、ユーザーが指定したより特定的で
ない ChannelTimeout (例: "session") を上書きしてしまう可能性があった。
また、いくつかのケースでは、デバッグメッセージが実際のタイムアウトでは
なく 0 を表示していた。 bz3994
* sftp(1): avoid NULL dereference crash in some circumstances when
a server fails a stat/lstat operation. GHPR707
sftp(1): サーバが stat/lstat 操作に失敗した際に、いくつかの状況で NULL
参照によりクラッシュするのを回避する。 GHPR707
* sshd(8): close a race condition where a SIGTERM/SIGQUIT would be
ignored if it was received by the server while it was processing a
SIGHUP restart request. bz3981
sshd(8): サーバが SIGHUP による再起動要求を処理している間に SIGTERM/
SIGQUIT を受け取ると、それが無視されてしまう競合状態を解消する。 bz3981
* sshd(8), ssh(1): check key and CA signature types during key
parsing against allowlists (PubkeyAcceptedAlgorithms, etc) as
early as possible. This reduces the attack surface presented by
disabled algorithms. Suggested by and with extensive feedback
from Chris Rohlf in collaboration with Claude and Anthropic
Research.
sshd(8), ssh(1): キーの解析中に、キーと CA の署名タイプを許可リスト
(PubkeyAcceptedAlgorithms など) とできるだけ早くチェックする。これにより、
無効にされたアルゴリズムによる攻撃面が減る。Claude および Anthropic
Research と協力した Chris Rohlf による提案と多くのフィードバック。
* All: switch the fallback implementation of the ed25519 signature
algorithm used when libcrypto is disabled from SUPERCOP ed25519
to libsodium. The libsodium implementation includes a number of
strictness checks over the original reference implementation we
have used to this point and a more ergonomic API.
全体: libcrypto が無効な場合に使われる ed25519 署名アルゴリズムの
フォールバック実装を、SUPERCOP ed25519 から libsodium に切り替える。
libsodium の実装には、これまで使ってきた元のリファレンス実装に比べて
多くの厳密性のチェックと、より使いやすい API が含まれている。
* ssh-add(1), ssh(1), ssh-keygen(1): fix spin on password entry when
the program attempting to read a password was started in a
background process group, with no TTY and with certain signals
ignored. bz3995
ssh-add(1), ssh(1), ssh-keygen(1): パスワードを読もうとするプログラムが、
バックグラウンドのプロセスグループで、TTY なしで、特定のシグナルを無視
する状態で起動された場合に、パスワード入力時に空回りするのを修正する。
bz3995
* scp(1): disallow nul byte in received scp -O filename. This was
not reachable in normal operation. Reported by Chua Wei Xun.
scp(1): scp -O で受信したファイル名に nul バイトを許可しない。これは
通常の操作では到達不可能だった。Chua Wei Xun により報告。
* ssh-keygen(1), ssh(1), sshd(8): implement a maximum number of KDF
rounds that will be accepted when writing an OpenSSH-format
private key or when loading one. This limit is set quite high
(1M), but ensures that a service that is passed a bad key with a
ridiculously high number of rounds will eventually complete
parsing it.
ssh-keygen(1), ssh(1), sshd(8): OpenSSH 形式の秘密鍵を書き出す際や
読み込む際に受け付ける KDF のラウンド数の最大値を実装する。この制限は
かなり高く (1M) 設定されているが、途方もなく高いラウンド数を持つ不正な
キーを渡されたサービスが、最終的にはその解析を完了することを保証する。
* ssh-keygen(1): bump the default number of KDF rounds from 24 to
32 (this is a linear increase, not like bcrypt(3) which is
exponential).
ssh-keygen(1): KDF のデフォルトのラウンド数を 24 から 32 に増やす
(これは線形の増加であり、指数的である bcrypt(3) とは異なる)。
* ssh(1): make StreamLocalBindMask properly respect Host/Match
blocks and make it first-match-wins as documented. bz4013
ssh(1): StreamLocalBindMask が Host/Match ブロックを正しく尊重するように
し、ドキュメントの記載どおり最初にマッチしたものが優先されるようにする。
bz4013
* sshd(8): make StreamLocalBindMask properly first-match-wins.
sshd(8): StreamLocalBindMask で、正しく最初にマッチしたものが優先される
ようにする。
Portability
-----------
移植性
* All: remove the NetBSD BROKEN_READ_COMPARISON workaround. This
appears to be no longer required and caused pre-auth CPU spinning.
全体: NetBSD の BROKEN_READ_COMPARISON の回避策を削除する。これは
もはや必要ないようであり、認証前に CPU の空回りを引き起こしていた。
* sshd(8): don't link sshd against libselinux when SELinux support
is enabled (note: this library is still linked for the sshd-auth
and sshd-session helper binaries).
sshd(8): SELinux のサポートが有効な場合に、sshd を libselinux と
リンクしない (注意: このライブラリは sshd-auth と sshd-session の
ヘルパーバイナリには引き続きリンクされる)。
* sshd(8): allow madvise(..., MADV_DONTNEED_LOCKED) in the seccomp
sandbox; needed by GrapheneOS' hardened allocator. bz4001
sshd(8): seccomp サンドボックスで madvise(..., MADV_DONTNEED_LOCKED) を
許可する。GrapheneOS の hardened allocator で必要となる。 bz4001
* sshd(8): restrict mremap(2) flags accepted by the seccomp
sandbox. Only MREMAP_MAYMOVE is now accepted as other flags may
have some utility in attack chains. Reported by: Mohammad Hossein
Abedini.
sshd(8): seccomp サンドボックスが受け付ける mremap(2) のフラグを制限
する。他のフラグは攻撃チェーンで何らかの役に立つ可能性があるため、
MREMAP_MAYMOVE のみを受け付けるようになった。Mohammad Hossein Abedini
により報告。
* sshd(8): allow PAMServiceName in Match (regressed in 10.4).
During the refactor of server option parsing, the ability to set
PAMServiceName in Match blocks was accidentally disabled.
sshd(8): Match 内での PAMServiceName を許可する (10.4 での退行)。
サーバのオプション解析のリファクタリング中に、Match ブロック内で
PAMServiceName を設定する機能が誤って無効にされていた。
* sshd(8): the --disable-fd-passing configure option has been
removed.
sshd(8): --disable-fd-passing configure オプションは削除された。