Bug#1141420: marked as done (openssh-client: /usr/share/doc/openssh-client is an absolute symlink after upgrade)

"Debian Bug Tracking System" <[email protected]> Mon, 06 Jul 2026 19:21:03 +0000
Newsgroups gmane.linux.debian.devel.ssh
Message-ID <handler.1141420.D1141420.17833655701771865.ackdone@bugs.debian.org>
This is a multi-part message in MIME format...

------------=_1783365663-1772491-0
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="utf-8"

Your message dated Mon, 06 Jul 2026 19:19:27 +0000
with message-id <[email protected]>
and subject line Bug#1141420: fixed in openssh 1:10.4p1-1
has caused the Debian Bug report #1141420,
regarding openssh-client: /usr/share/doc/openssh-client is an absolute syml=
ink after upgrade
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


--=20
1141420: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1141420
Debian Bug Tracking System
Contact [email protected] with problems

------------=_1783365663-1772491-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at submit) by bugs.debian.org; 4 Jul 2026 10:14:52 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-17.0 required=4.0 tests=BAYES_00,
	BODY_INCLUDES_PACKAGE,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,
	DKIM_VALID_EF,FREEMAIL_FROM,HAS_PACKAGE,RCVD_IN_DNSWL_LOW,
	RCVD_IN_MSPIKE_H4,RCVD_IN_MSPIKE_WL,SPF_HELO_NONE,SPF_PASS,
	WORD_WITHOUT_VOWELS,X_DEBBUGS_CC autolearn=ham autolearn_force=no
	version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 221; hammy, 136; neutral, 20; spammy,
	0. spammytokens: hammytokens:0.000-+--H*Ad:N*Bug,
	0.000-+--H*Ad:N*Tracking, 0.000-+--HTo:N*Debian, 0.000-+--forky,
	0.000-+--HTo:N*Bug
Return-path: <[email protected]>
Received: from mout.gmx.net ([212.227.17.22]:36225)
	by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wfwxx-004UNg-00
	for [email protected];
	Sat, 04 Jul 2026 09:47:17 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmx.de;
	s=s31663417; t=1783158432; x=1783763232; [email protected];
	bh=YscRQk1mZi7wgraEEAQV7U6OVdkSUSLQh5p26ebt7cs=;
	h=X-UI-Sender-Class:From:To:Subject:Date:Message-ID:MIME-Version:
	 Content-Type:Content-Transfer-Encoding:cc:
	 content-transfer-encoding:content-type:date:from:message-id:
	 mime-version:reply-to:subject:to;
	b=mGwn+NOuIJT+mVoZHhWUtaFlqoO3j7KVeK3t8ONd5NrPY4Gyv68yfTdcoMbtve51
	 6va0ms4QILjURD94EVzxhyVuOyIG+AFgaYPZZWO7WrXbcqWAGYsNJyhw59R8WeFUa
	 KO+LbD2E3AvBVtFUUNLWU2Np7siedCBYYhy7WTLyuSHj0ChnL5k6XEEbnWpDJeTpi
	 yXOvEibWit7s53d8pgT2J7nRuKHZPGioCHbsa7kZ9qUz1NnqlU3DFeJjZlVOUOf6u
	 0SiehVFQH8rXfBna+kKJ5M7SjsyBeIG4YNWdEx9y4IRQKm7Zyy01QmYhaL/X9CYdR
	 g+Pgrxz4Hi2NVZW8tw==
X-UI-Sender-Class: 724b4f7f-cbec-4199-ad4e-598c01a50d3a
Received: from client.hidden.invalid by mail.gmx.net (mrgmx105
 [212.227.17.168]) with ESMTPSA (Nemesis) id 1M5QFB-1whK0j2v0n-004KhK for
 <[email protected]>; Sat, 04 Jul 2026 11:47:12 +0200
Received: by localhost.localdomain (Postfix, from userid 1000)
	id 333FB8005F; Sat, 04 Jul 2026 11:47:12 +0200 (CEST)
From: Sven Joachim <[email protected]>
To: Debian Bug Tracking System <[email protected]>
Subject: openssh-client: /usr/share/doc/openssh-client is an absolute
 symlink after upgrade
X-Debbugs-CC: Sven Joachim <[email protected]>
Date: Sat, 04 Jul 2026 11:47:12 +0200
Message-ID: <[email protected]>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: text/plain
X-Provags-ID: V03:K1:EVk2uQ14XJK27JnAA+vZ193Nnk1yelH//Uj80AopnQZm10zbVua
 SOfQyDaj7pP23fL17bVdeTtW8OsdqBHtuxta2ySteGSR1TqpFjh8lSeeilCCMfsozoi4Qdg
 YDsWuSXehHtKPyii2b7yMqAG9aU7Qo/KagD1LB/Azr7xArWw0lebJIc4Z0HFrMTmhvxzLZe
 ss+Rv4aoFZbzRepFdULsQ==
UI-OutboundReport: notjunk:1;M01:P0:SF0d+qLzRtM=;6BV/RTF9oX4mDwhiglLx4+byAHO
 0BA0FGUWr/jMtUNmJhngwxwnQXt6GJN2XZ4EuUzL2VHkvkxEysUBT3bgtjR2aDETB6uPTXr1T
 fS8wVu7R59VLJ1hX1vCFS/lyj+6JldY3gYZiUG7IuPAo9z3soQQsja6FHaU9o+t7dsGjKG8Yo
 E7kbh1pxZin46+STN0ByYCKWbJxGYX6YgEFlf9OzO71tz+CHX7xAz1C+nsWQqXxUnivq495vk
 FwD159woW+RuMIwksh7a1XrHiivv2IO/6Isy2CApv+BVnM5g6ojqZv23Ym04y4OUxMRZldlpC
 eqAn7qNpLpzv7j90p0TBOHKNSn9aOYPDnXGZNjveICJfWqLqZbx7Jy/+7ul5KLE3SHZglM4gH
 sON9b0zDekMfg8Bznq1fnTrflF8Z1rphGkqeuP/7UvFeC2wFPmKbJm37VgV+GYYiFrPQXNl+p
 QKUc8WSKajb9TGeqaWgjdreDmyhdxVjkWS5RXUg/hPbyuK9HshGkyKXBAooiYyC2NLV8bTpDm
 aj8gicAGW5mEPqEPplbHeHp7dH1sQ1s56CcH8+2bjTk49nY/aAx/KDf4eEKJhjBLkGezfccVd
 LbEX6ZUEg5VV/aVOO8Ew8d4sxuHLV55AghYNNrPCmxzNKPG+kzraftaZKyTWBEZ7Q8KfezvK+
 FvsoYSr/gNHQCah3Q9d1zT+ZnFZALSbyOuNNSswfCr1m2H4IUtefwLBZO9lYlpvybq/RG0oqf
 HwUYePAtzMDtc1iRce9Ly1qBR13oG0IuZL4tfHN8FWyr+gyhR9jfOj/WVCxXSvCSMEPMMe2T0
 hvji0YHVx3D7LG+Ln+ioq4iJ8bn5SdswqxU7QoawjSizseoGVxSFxRng7/4Evc2/dUaFP3qOK
 K3pUDqUN2Ql0RSyFrWz3eolY4mefvI7ezaIRf97yrKYzPuaNRyXIIpydd16lckowaEfQMHMOS
 dzpuCx+6QJe55AQ4QjsnrpLGnCoIFoAvIkFGv9O486Dsh7fYZwVOTjM/yyJg5DOW4sx1V+XSx
 jpR/PtzvCvGwIw5SEGqUOVeeGgMCUfdk89tEIUjZjWBLnxiv0egChaDWLmufde7rjgdBPQbty
 OaI3o2BjPx+BfNTHQ9Bkv0Hr4U4kw6Ql189LNwjOKJo58/owpr6JX+l7bCzXJ+5oUEYTkpfqy
 hzvuT4EGKjGOpPNHlioOezkOV0md6624MnZN55pcVzEM/CUry2CTiPJx3JhAttamgPvWHcw/3
 m1oJN9moEzZasl4VIImlAECbyDyFIboI5JEMuxx/+KXZZJxIwkYAP/6jDk1QdtowM04uXRG0F
 ASQPAxwnHFSZ18hsbzs/aFOElD6gjHF1nR0rAcJKsuwvD1bSyk8qv2asTRi2uv85eWr4jg7nz
 xpnX716h+aDbGyvRqRsN0bj812mB5oIKVUCBhlxrDRkuPL3I2LdCT/DA2IHRmr0JHAOMcs5s8
 FXO/8DJ9xLHdBT6mQJrpyYBiDK6MOYO9zFxbcJoCm98IKvVNqzCfZdUCqU1M3cKUG4HR7mYhi
 ebtPjxWCNsNcbDVZxBVYaIhn3O4LaNISvYhP4qHwVDMewth+6KnP3Jndu7if0Y9xHj4YBP85G
 U67ORIs4f17dDfOn6XU4QPIdzauyLu0hABWgHceupBgBF0gcLDuyNPvgwalkLNZ6LvpocV/1H
 eEaoDnI+amjGjnHX000RR7tgPVvH+Q+eRMGaF36jVqTkLFfOCc86aPE7Nm5flW6FovoeQJOA9
 9FMEmEI9LP6CSymXh8CLg0BAFafm4sFhdqKjpm0aGxqRF/tFvDdt7/t8+c+QqadTyCJ5rkjwi
 ImyFk81Y0DVMFJCa5Ss6kRlYOl37Ldsbz5H250xqEgsL5WUwHLh9ONclDAQN2zkomSWIJfAGa
 okxWOj04KJ3t23kClzzG2aUZ68iu/xkLYlr0BfHwDaS0iUBHxoJ0ZUj8sYAZqG4nPIq2OjOIM
 VIq5RgiE5a7EHX+VNqqJ7gZ2QoMzzYVJzzgzJ000V4mbQJdpneJMt9LBqbX2lYt15ooyU+Is8
 tUVSRR9gYCc/rJDY4tJfB7z5OHOSBbR2wR3g+e45cesv36paptc4sYP71d5SwVFUvJTWZeMwJ
 L5T7VIj6tVV4TP+4Y6FeerCnv432RI+2CAFyAigq9PQDIbR/j0Z4QPNUcA3oqt9ukzImGNW0E
 A8cvtWr4SqO51H0ZTjAtBy9Hq0fxuf0ZzPJyDXS+AeYJneV0gN56eV2jN0ZlLbDUp5PcjsOka
 984NX9odmNdT6ZbDn4qAZOAe5N6SBm78tMiqnAxQqkp5OGVT4ppKcXTP7HRlLiKLijaAhnhAP
 zdmGClzaTvrA/QEcb85imDioiWPuO8aTJ/1FwpaH9hZ0Bk4hBIcuwvmkSiGqXQqbgvc5nUaK8
 axk054II3frhOJgAYji8DBFtGftqmewHFKxYrCvoMYNvpRU9wkURmGox14n6mS5pqWfm8YQO6
 aJ3WMHpkTfyU+JNYe7hjkTmFkturHXWuDVmdE3+rWaAiDqSnKanjiS/yCP0vKhA2zfskmirh4
 /7VnO/2dRX2HRdvjnuQekiHS/x7x1GUDl6rNGQj6OZ9j9LpgxEwn6V9nW1KEyGmJA5jZ2OFiJ
 zzvhDcHkzm7r+1qYoTV0x6pX2zfghQJ5u/eaz2a+Tlx5fIoonEPeKAMI90O4wLSZ13gEnr4dl
 TEO9mnaT0QLFWoQs1W2yMh8FTdA9ck1cgLUBdYUdlmmvjUYG8aJb+muFd1GzbtL1+ySpOkVW6
 esGA2vcRMuuRERl195XhP5A683BQL/kcW2cohhIHdKVD5rQnivvjXaEMkF6lSyJxSj2HcaS6S
 hd75qzJvpS6coJXyMoxdzROGIzSYg9p1orfxbmjsfLea7g+oAeWiLdVv0pvxFIoGgDQIRVkS3
 fd4VgW2PvSMTVc+1sljR0c3aWxZnBiqOVsNd7zFtht84pxkmZqIOeccfDtxxn+JsJ88ONVFum
 FCu1AB7acfZbXFkYrGfk6pqUmKlSQ5L+IwEs2GJMARz+k4MDGGVP1O13KVhroqMPDaBZjPrZe
 HCDitg0qS+2FMbsaLrMAm31y0yti3jIMnyP4lpAfn1O541477IAC9ApaqxmId4fzq7yAoBe4L
 282U5OAo5m1IV3fM+WEJwC2pD/PsTWZ6BOT+30IHtXTLUX9qM4++Ev/5io4o717WofnTwQ/DT
 co+bzshZAg0XyvhVE8BsLuPpcnOx+xGNVtX9cIjfuIZB7szKRCGuwyFbN1/OBsx8Ir+T2JaVj
 hF+CHwRMgXolyIPdqDfFjUAph3gbQ5il25ix16HLIJpAz2tAhssxwAxFMdwxrb6pSWFwQsEYW
 fDcqdGCXN8otYsONXbnquXmSUFu8sUgBBs0zuziy10u5HuYDa3pUokHC/e+8aWJm05coohO3c
 b10UImWDNUkRzfvfILI0zwX0OXuANIYoKNCHeaIiiZEsd9g5Lc4oOUVyVNz18bEE6WlW827DU
 55AGgSapUE3WiNhNmQ+z1BQ+DVhBjialVfgRfli9zrTiwhSsOUhDGNKXzXy82FSOx+d0H/UkP
 sTEhDJw6+1s3uB0UPRR2v94fqIMO1WtGocpARBqg2zGVsLlwWsi9wOGQk9DYWvG66RgTKmiGc
 wdTw1Yt5cwiv6JcYXHwraN/z2N1rCmqEIYPK3k8hNckD6z8CJQaDCa0RhXJvvrFWM+z2beKwi
 is4Y3eM1VIDEdmf/C/WKY91cTKMIY5YC17+9SRUJvfcCBU8EErg29qIkcboy4iZcxn+6jwGTr
 pHfiX7y9WpZdgEBRPVnO2Te+z365at0FzuKzUAJ3W6mGKHY4JEoefs7iXObMCZV+dbXtIkCaq
 S7rRcOAFT4wIKUO2n7rNx68dGYSpzo/nnonKMY7gnbTMc2XE9eX9s95SHvvqsgohYFToCPVGx
 aPD37WzdX9KmdTzAo8pFv4KCttun41ntelcp/jASO3YrAED/dpjYE1cAAaFgjRysI0VZaJq5I
 bo0Bk+RcTAhtTXAc6bpUHNXe83cRiMTfhv6Js9SPUlm7Rn6qq0WaS1CwDNS61Y+6qUvp8DkWl
 0xSK39Bx9MSpqlBphIrU93uWvFHFe2UL1N7YYorVagrMR6o00OiHlTLl4rzzvEAXGSUi3u0KJ
 Y5sivBpXOY7x+jfzYw6+6IsFertiOf7MHA8lRtYnrkT8MluwQP5w1NLmDlgvv94x9ZgVmnJDB
 r4A6gG1wUfpXnX8KoPtVD+W9iNLNKZRLq7tjkdYtkxEeEaDdAim73t8AY04yN+URoOA6lDWqW
 p5zqd35hZQ77v7CqGmDvs7XsVCrBFxW0ngqw9ZN++qzko8Kq5Xuiv/2oMAcdDEJojPhKrYRyq
 FYL/w/cRetqdCXm+aw/zyMjB4tQ3zB0qWBZzc2UpkzKq2S4pPBepar5nbbZrlJBGqmnqtkPti
 AEYW/P1yKtKvmI+x/8XmXBWX1pvKTV8MPsrKf7dNiZHCTPvFT7hioc3PZvNJg2SQyckV67h7H
 ogzpIOnrYogUk+ZHq10ST00ncU+aOHCdHcInYts5YtUbK/Rj3SLlkiTad4W8EjJcNzSaGUGmh
 VVRQ5dQSLk+Hu6XC8ZNzl7AZ2gPfP7nJlpOdfh0yJri9ap2NmTH2qn1jzIKLUUighyI1Zp6ov
 0FUFBA1P/P3jEaH8CYDrFewjN4MXuYiG8k1Kez5Bqks3yOL0EE3bSy8bCMU3Uw3XYC8aXRnOU
 KnLKWbRpxaDihJGf59yjSFkllXdZxC7eKaXSNw7ZFpH2fs7+d8kRUgxjUZlUGwNt/B5c1J5sv
 UKdFvDGWN21HB6yZrEO5P35LDd8A0uBIItpwzdWH2Fm0b1Fz40eZGawffWztEZCg5kdME1UdY
 NXgPOvvPd2zaZNQXJES9ru8e54EbUBEi2RDMOF6ME1jwRQ9As436QwdzyFaIcxeBf8JF3zr9h
 Vlx2gSjwqg14GJnIYchrMV0a3+AWhcGe/A6Ap0/Blrce+EDVsd0L4cHUyBZqlTfY8bUjvPaU8
 Y376J6iDNvAGYGyCVQzbueHksubBjbhpkGq6ptKvzhAFfO0MEmnf0r85CN48CIscpeAASK+zJ
 xjdie7KmDNNX4yE6tCOS++cbX03X3DHM63VJdGi/VLDNMo5wdO9X0kXYQFTM8257Q14CIuU47
 CVf45EtvjK5JY6Z6bw7YUccRUCghp+Wc+mdcSHbODMg94hF4tT7CIQEWAiKR6e4TgNCUYVDLJ
 iAcqD5JBTMygQ7SfJSOdxNWQS5FFveqUAlhSlOjIQHOSQHjFSvEUf2xsTTJ5EVm65MeHu1iro
 ca2MIeBu2CAWEGZt1SW14StWKN+sPDXyuf0I/7VD7Y15HLINLR8awq0vwGA7x12kut7lccik4
 7LAw2hO3sW5CoDXpsk+cfkxYSOPpdO7QaStx0MYCFFDdse1ZQybK0FVG0iwV8Nh0EGTj1uulF
 uyh6BBxrn5KaOHpsZ9VOsjGT6NAbrVsQLkZ4fIZq2eVtcgKGn7H2wUpUDu3atwl+XoMjcEYOo
 6k9oAybd21UylTenfrm2K6BOPArwkqIs12wo=
Content-Transfer-Encoding: quoted-printable
Delivered-To: [email protected]

Package: openssh-client
Version: 1:10.3p1-8

Upgrading from version 1:10.3p1-5 turns /usr/share/doc/openssh-client
into a symlink, but it is an absolute symlink rather than a relative one
as recommended by policy and shipped by the package:

,----
| # apt install openssh-client
| Upgrading:                     =20
|   openssh-client
|=20
| Installing dependencies:
|   openssh-common
|=20
| [...]
| Preparing to unpack .../openssh-client_1%3a10.3p1-8_amd64.deb ...
| Unpacking openssh-client (1:10.3p1-8) over (1:10.3p1-5) ...
| Selecting previously unselected package openssh-common.
| Preparing to unpack .../openssh-common_1%3a10.3p1-8_amd64.deb ...
| Unpacking openssh-common (1:10.3p1-8) ...
| Setting up openssh-common (1:10.3p1-8) ...
| Setting up openssh-client (1:10.3p1-8) ...
| # ls -ld /usr/share/doc/openssh-client
| lrwxrwxrwx 1 root root 29 Jul  4 09:25 /usr/share/doc/openssh-client -> =
/usr/share/doc/openssh-common
`----

I think in debian/*.maintscript a relative path for the symlink target
ought to be used, but I have not tested that.  Suggested patch:

sed -i 's#/usr/share/doc/openssh-common#openssh-common#' debian/*.maintscr=
ipt


=2D- System Information:
Debian Release: forky/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (101, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

------------=_1783365663-1772491-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at 1141420-close) by bugs.debian.org; 6 Jul 2026 19:19:30 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-113.0 required=4.0 tests=BAYES_00,DKIM_SIGNED,
	DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,FVGT_m_MULTI_ODD,
	HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,RCVD_IN_DNSWL_MED,
	SPF_HELO_PASS,SPF_PASS,USER_IN_DKIM_WELCOMELIST autolearn=ham
	autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 13; hammy, 150; neutral, 697; spammy,
	0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
	0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--HX-DAK:process-upload,
	0.000-+--UD:debian.tar.xz, 0.000-+--H*r:sk:fasolo.
Return-path: <[email protected]>
Received: from mitropoulos.debian.org ([2001:648:2ffc:deb:216:61ff:fe9d:958d]:42730)
	by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wgoqo-007QwI-2E
	for [email protected];
	Mon, 06 Jul 2026 19:19:30 +0000
Received: via submission
	from C=NA,ST=NA,L=Ankh Morpork,O=Debian SMTP,OU=Debian SMTP CA,CN=fasolo.debian.org,[email protected] (verified)
	by mitropoulos.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wgoqm-002AB7-2l
	for [email protected];
	Mon, 06 Jul 2026 19:19:29 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
	d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
	Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
	:Content-Description:In-Reply-To:References;
	bh=Ybc8DgZv8PX2QSKh29SQ7AKvG6Ydxe06JcPPZQ88IqQ=; b=Eri7C0gLqMiRqQZZIAZ5hdY24u
	8AhCH/WyfFcs7pfaTTxKLy/Nay4C0/47gDW3vgONJHa495dKPGI1r5XSyR+BsM57pZZinAUJqAVx7
	PV4oxI4ZCdLnBiRxbE8drWJj/RX2Q2U+40M6CSqHybLWDcEiVM/sPNJt++22F7DgUdLCtzpMQI5vW
	ghsX7Prf6V02j+B5TfsofjmhEXsXO3n9tqvGNo40bUbk3GsxOC7boSJeZHfjMVPMtqVFY/feB/g1c
	sfDbg7sgnd8GXGKIthaaXN5bfBZwRWrJmnh12+9/tyP5W5kdOaB+FIcC3nYx2LO78mU0P6kL4agBC
	1Vr6OetQ==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
	(envelope-from <[email protected]>)
	id 1wgoql-00000002KbP-2gWG;
	Mon, 06 Jul 2026 19:19:27 +0000
From: Debian FTP Masters <[email protected]>
Reply-To: Colin Watson <[email protected]>
To: [email protected]
X-DAK: dak process-upload
X-Debian: DAK
X-Debian-Package: openssh
Debian: DAK
Debian-Changes: openssh_10.4p1-1_source.changes
Debian-Source: openssh
Debian-Version: 1:10.4p1-1
Debian-Architecture: source
Debian-Suite: unstable
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1141420: fixed in openssh 1:10.4p1-1
Content-Type: multipart/signed; micalg="pgp-sha256";
 protocol="application/pgp-signature";
 boundary="===============7417338983551805170=="
Message-Id: <[email protected]>
Date: Mon, 06 Jul 2026 19:19:27 +0000
X-CrossAssassin-Score: 2

--===============7417338983551805170==
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Source: openssh
Source-Version: 1:10.4p1-1
Done: Colin Watson <[email protected]>

We believe that the bug you reported is fixed in the latest version of
openssh, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Colin Watson <[email protected]> (supplier of updated openssh package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 06 Jul 2026 19:11:28 +0100
Source: openssh
Architecture: source
Version: 1:10.4p1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenSSH Maintainers <[email protected]>
Changed-By: Colin Watson <[email protected]>
Closes: 1134814 1141420
Changes:
 openssh (1:10.4p1-1) unstable; urgency=3Dmedium
 .
   [ Sven Joachim ]
   * Make doc symlinks relative on upgrade from 1:10.3p1-5 (closes:
     #1141420).
 .
   [ Colin Watson ]
   * New upstream release:
     - SECURITY: sftp(1): when downloading files on the command-line using
       "sftp host:/path .", a malicious server could cause the file to be
       downloaded to an unexpected location. This issue was identified by the
       Swival Security Scanner.
     - SECURITY: scp(1): when copying files between two remote destinations,
       do not allow a malicious server to write files to the parent directory
       of the intended target directory. This issue was identified by the
       Swival Security Scanner.
     - SECURITY: sshd(8): when using the "internal-sftp" SFTP server
       implementation (this is not the default), long command lines were
       previously truncated silently after the 9th argument. If a
       security-relevant option was in the 10th or later position, it would
       be discarded. Reported by Steve Caffrey.
     - SECURITY: sshd(8): add a documentation note to mention that the
       GSSAPIStrictAcceptorCheck option is ineffective when the server is
       joined to a Windows Active Directory. Reported by Yarin Aharoni of
       Safebreach.
     - SECURITY: sshd(8): DisableForwarding=3Dyes didn't override
       PermitTunnel=3Dyes as it was documented to do. Note that PermitTunnel =
is
       not enabled by default. Reported independently by Huzaifa Sidhpurwala
       of Redhat and Marko Jevtic.
     - SECURITY: sshd(8): avoid a potential pre-authentication denial of
       service when GSSAPIAuthentication was enabled (this feature is off by
       default). This was not mitigated by MaxAuthTries, but would be
       penalised by PerSourcePenalties. This was reported by Manfred Kaiser
       of the milCERT AT (Austrian Ministry of Defence).
     - SECURITY: sshd(8): fix a number of cases where the minimum
       authentication delay was not being enforced. Reported by the Orange
       Cyberdefense Vulnerability Team.
     - SECURITY: ssh(1): fix a possible client-side use-after-free if the
       server changes its host key during a key reexchange. This was reported
       by Zhenpeng (Leo) Lin of Depthfirst.
     - All: add experimental support for a composite post-quantum signature
       scheme that combines ML-DSA 44 and Ed25519 as specified in
       draft-miller-sshm-mldsa44-ed25519-composite-sigs. This scheme is not
       enabled by default. To use it, you'll need to add it to
       HostKeyAlgorithms, PubkeyAcceptedAlgorithms, etc. Keys may be
       generated using "ssh-keygen -t mldsa44-ed25519".
     - ssh(1), sshd(8): replace the wildcard pattern matcher with an
       implementation based on an NFA. This avoids exponential worst-case
       behaviour for the old implementation.
     - ssh-agent(1): fix incorrect reply to "query" SSH_AGENTC_EXTENSION
       requests.
     - sshd(8): avoid sending observably different messages for valid vs
       invalid users in GSSAPIAuthentication (disabled by default).
     - ssh(1), sshd(8): fix several bugs that incorrectly classified bulk
       traffic as interactive.
     - ssh-keygen(1), ssh-add(1): skip unsupported key types when downloading
       resident keys from a FIDO token. Previously, downloads would abort
       when one was encountered.
     - ssh(1): fix a potential use-after-free on an error path if
       cipher_init() fails.
     - sshd(8): perform stricter encoding and validation of transport state
       passed between sshd privilege separation subprocesses. This somewhat
       further hardens the server against attacks on sshd-auth or
       sshd-session subprocesses.
     - ssh-agent(1): avoid possible runtime denial of service by enforcing
       some limits on the length of usernames in key use constraints.
     - sftp(1): fix two separate one-byte out-of-bounds reads, in
       SSH2_FXP_REALPATH and batch command processing.
     - sftp-server(8): disallow use of the copy-data extension to read and
       write to the same inode simultaneously.
     - ssh(1), sshd(8): avoid strlen(NULL) crash if an X11 channel was
       created before the x11-req SSH_MSG_CHANNEL_REQUEST was sent.
     - sftp(1), scp(1): avoid a situation where sftp_download() could get
       stuck in a loop if a broken server repeatedly returned zero length
       while reading a file.
     - ssh(1): avoid leaking DNS0x20 case-randomised names into names
       canonicalised using CanonicalizePermittedCNAMEs.
     - sftp-server(8): avoid truncation of pathnames passed to lstat() during
       SSH_FXP_REALPATH handling on systems where PATH_MAX is not the actual
       max.
     - ssh(1), sshd(8): correct arming of poll(2) event masks for some
       socket-type channels.
     - sshd(8): major refactor of sshd_config parsing and management code, to
       allow for more exact serialisation/deserialisation across privilege
       separation boundaries.
     - ssh-add(1): open connection to the agent only after getopt()
       processing has completed, to give options like "-v" a chance to
       display debug information about this operation.
     - sshd(8): differentiate between execution failures and a subsystem that
       was not found when logging why a subsystem failed to start.
     - All: use safer idioms for timegm(3) and mktime(3) error detection.
     - ssh(1), sshd(8): avoid accepting invalid cipher or MAC lists in config
       files or command-line arguments. This could cause runtime failures
       later.
     - ssh(1): fix NULL deref crash during pubkey auth when using a PEM style
       private key with no corresponding .pub key adjacent to it (closes:
       #1134814).
     - sshd(8): don't print an error message when trying to load a host
       private key when PKCS#11 keys are in use, as these don't need the
       private half on the filesystem.
     - All: don't use deprecated ERR_load_crypto_strings().
     - ssh(1): properly report errors during configuration default setting.
     - ssh(1): use correct directive name (Match instead of Host) in error
       message.
     - sftp(1): fix "ls -ln" which was not correctly showing numeric UID/GIDs
       but rather user and group names.
     - sshd(8): avoid possible NULL dereference if an allocation fails during
       config parsing.
     - All: fix ineffective guards against loading overly large public keys
       in several places.
     - sftp(1): ensure file descriptors used by sftp to communicate to its
       ssh(1) subprocess don't leak into executed subprocesses (e.g. via
       "!").
     - Sync fmt_scaled.c with OpenBSD upstream, picking up an exactness fix
       for large exponents.
     - sshd(8): remove duplicate sandbox entry for clock_gettime64.
     - Sync getrrsetbyname.c with OpenBSD upstream, picking up robustness
       fixes.
     - Fix a number of memory leaks on error paths in the portability code.
     - Revise the README.privsep documentation to reflect sshd's recent
       switch to a multi-binary model.
Checksums-Sha1:
 df9f47c0f27ac289f28a014382b376c751b36030 3651 openssh_10.4p1-1.dsc
 ae8650a71cc52dbbd049519cee276ae6d65c2c4d 2321796 openssh_10.4p1.orig.tar.gz
 024bbb98d37dc35c31a49144770c6e38bfe53829 833 openssh_10.4p1.orig.tar.gz.asc
 eba70bbacbe02995f7eeec31a1dd96a7cd7a8058 208228 openssh_10.4p1-1.debian.tar.=
xz
Checksums-Sha256:
 878de8e50995ae6a2eaad52c829036729c48a57a104d9ba32d558fb82096ee5e 3651 openss=
h_10.4p1-1.dsc
 ef6026dd2aea8d56059638d5d3262902c892ceba9f88395835e0d06d3fb63238 2321796 ope=
nssh_10.4p1.orig.tar.gz
 9206329419c45245913ae42fd290e2ed5b1669df97d9cf0d3e28c06b63035e51 833 openssh=
_10.4p1.orig.tar.gz.asc
 5c5d2f7ee53bef6f96355eab24062b82f226ead501dc3f8630f75202f662ca1f 208228 open=
ssh_10.4p1-1.debian.tar.xz
Files:
 e89a2b713609f72642c98c6a454c45e1 3651 net standard openssh_10.4p1-1.dsc
 c5fb91ded926b38e8956074cac2cd44f 2321796 net standard openssh_10.4p1.orig.ta=
r.gz
 105ff131214dc93a4892488bc80b444a 833 net standard openssh_10.4p1.orig.tar.gz=
.asc
 c9d6a49c9f1d34a9b0358f3860a9f1b2 208228 net standard openssh_10.4p1-1.debian=
.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEErApP8SYRtvzPAcEROTWH2X2GUAsFAmpL+hEACgkQOTWH2X2G
UAtBwBAAhHqb1L4vbgAc1c0LGWm+Ebx6zyCgxVhwa6kHyy/+L2NtUmPIpwSlmIdw
TIbpnKfqVXgvvykMHqXQQOU8fWWt4Q715m4UGv6F0NgDNr7RKicND6DfIlDXdzCp
dwNZFLkqLMIrn8+DzYoNcMN2nN1q62jQ+cVc4q13UvK4uUrxQSGrdAb6dr3zaoMR
/Exj6aPD++Tf5JoOt+BDnqRln/hjhsqnN3NqJ1000PaRi4JzP0YmZOz1/40Ja0dm
yQ6Xo6bg+hasGcMa4GYXdFXFqI6mVRGItZ1CZgCCG9kfvDtXnSzgCC3no7BgW0bU
Iyt5EVlauSiEEePOnn+I9FK+PDmfL6n4CmV2/DM2btbpjFO9g3FjUGRADDA5H6Fo
wE5cEmISiRKO28qjAFyNDpSDqzN1GDE9RKMCf/l5lZLetMl3/8rfkwDRD1L/A5qb
9tz1NyycIH4Qlpv7++WUXzFxLJyQptrGD6Fj6uPdC6mmCAeeo6yy6DwAm5NxtntG
nD2CH8zzHxJ0oLY/6sM8cgEvNfuok6tCNdHeyLUpI8DZXi3tzJToH92yd7uzLt3m
pMM/BY/t05GZ3HabhxOCJi7H/OOk1MwNaDtlJnG1AOkwuYXXUDmwbPGYvXiDjsC5
uJ9SE+LmTcrZ8a/ms24nuf38GPta4mLTDY5OHBUNk6Ixj707nRo=3D
=3DLnvT
-----END PGP SIGNATURE-----


--===============7417338983551805170==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCakv/vwAKCRCb9qggYcy5
IeuFAQCpno8TpKYooomIYmhTVIC9ycHSIB1xbSQL+9hPpTl0gQEAlB/Azd7WqWo0
obhNMQ9WyjBP/pWMKUUZ1n68ZEjW3Ac=
=WVto
-----END PGP SIGNATURE-----

--===============7417338983551805170==--
------------=_1783365663-1772491-0--