Re: bin/60512: sshd: hosts.deny and hosts.allow for NetBSD 10 not working for 11

Rin Okuyama <[email protected]> Wed, 29 Jul 2026 17:19:59 +0900
Newsgroups gmane.os.netbsd.bugs
Message-ID <[email protected]>
Thank you guys for your comments!

On 2026/07/28 22:18, Taylor R Campbell wrote:
>> Date: Tue, 28 Jul 2026 12:20:15 +0200
>> From: Martin Husemann <[email protected]>
>>
>> If that change is not acceptable, this needs to be checked by
>> postinstall(8). "postinstall check" could just fail with a message
>> pointing the admin at what manual fix would work.
> 
> That's absurd; the introduction of an internal privilege separation
> measure in the implementation of sshd should not reinterpret the
> operator's intent!
> 
> This was previously discussed at:
> 
> https://mail-index.netbsd.org/current-users/2025/01/06/msg045945.html

Ah, I missed this discussion.

> As a result of that discussion, we updated our local patch for libwrap
> support to check _both_ `sshd-session' and `sshd':
> 
> https://mail-index.netbsd.org/source-changes/2025/01/08/msg155130.html
> 
(snip)
> 
> https://nxr.netbsd.org/xref/src/crypto/external/bsd/openssh/dist/sshd-session.c?r=1.13#106
> 
> However, I suspect that logic only works for hosts.deny, not for
> hosts.allow.

Yes. It doesn't as described in this PR.

> Frankly, I don't think we should use the name sshd-session at all;
> it's an internal implementation detail, not the name of the service
> users are configuring.  We should just fix openssh to use the name
> "sshd" again.

I'm leaning toward this option. Christos, how do you think as
the maintainer of our in-tree OpenSSH?

Thanks,
rin