From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 97679C3DA42 for ; Wed, 17 Jul 2024 09:25:13 +0000 (UTC) Received: from mx0b-0064b401.pphosted.com (mx0b-0064b401.pphosted.com [205.220.178.238]) by mx.groups.io with SMTP id smtpd.web10.11298.1721208305112948725 for ; Wed, 17 Jul 2024 02:25:05 -0700 Authentication-Results: mx.groups.io; dkim=none (message not signed); spf=permerror, err=parse error for token &{10 18 %{ir}.%{v}.%{d}.spf.has.pphosted.com}: invalid domain name (domain: windriver.com, ip: 205.220.178.238, mailfrom: prvs=7928d6fc0d=qi.chen@windriver.com) Received: from pps.filterd (m0250812.ppops.net [127.0.0.1]) by mx0a-0064b401.pphosted.com (8.18.1.2/8.18.1.2) with ESMTP id 46H4eHar016568 for ; Wed, 17 Jul 2024 09:25:04 GMT Received: from pps.reinject (localhost [127.0.0.1]) by mx0a-0064b401.pphosted.com (PPS) with ESMTPS id 40dwenrkcq-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Wed, 17 Jul 2024 09:25:03 +0000 (GMT) Received: from m0250812.ppops.net (m0250812.ppops.net [127.0.0.1]) by pps.reinject (8.18.0.8/8.18.0.8) with ESMTP id 46H9MXiw022703 for ; Wed, 17 Jul 2024 09:25:03 GMT Received: from nam10-mw2-obe.outbound.protection.outlook.com (mail-mw2nam10lp2045.outbound.protection.outlook.com [104.47.55.45]) by mx0a-0064b401.pphosted.com (PPS) with ESMTPS id 40dwenrkcp-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 17 Jul 2024 09:25:03 +0000 (GMT) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=RvltwnaisShvXNXYIsiofEhNBL7tlwyZEdKAu8E/UdW/M18gQIEsgqSv//65rT+5nJw6V4Bdbp0p9mXvj45qkNl9I4hGNW8BPsgrYSfbJPUk5v+pd99a1qxH8HIxMYH7OQ/JIajul+PyZjR0STdz5xleGj4J8y8LeB3ajk19OEqy/tghnv/uTeG5W2A+TlXZdO6sXzMWh8SbSwdhHX41k9Nn1inQulmr68bgMl3HWfl3UpjSrjIdyQQXge1pAy1P0PUwAe3ojYBAzki5JNX3iq9Fy6lwUdtwMcyr5C+J3xspYCx6Gtw79C32nJT0LWTqsdIKd9PGgUhxfWU/5HeY3A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=UXiJObuOlIY4OY8hqwc7QF2kDvS2yUz/XQH/jeb2gT4=; b=R7B8CPSycSJ01OQ80RrJ/rjYjO1LQPYpt83UHna/MmU38Di9YwueOLVQG9TCs588DYgbphU4zCxionnVnkzRr4OhJdYBt1Onkc2ZJ1tHcfB7DJKSsKv1Xi+PfRDdIXpC4wM+HcaV1kTiy5w5MnRgpEVm0X3ZkrlAf5mZ0x0mN8Hl8Z31dNDcA/yaDoO+MJOvmDneIUrIxW3MurNzkduJVv/8TUNa8tkcgFVa0AJgN78Nk2EBf2nf6zwQV6u+MYoiXiZgXtGHo95PtXf+ABFQHlDog4J+uGSYaBoBy0SZXHufZ5XNbuLSf1oH6a7NmsIKnOzT8q7J8/FknklO4HHoSQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=windriver.com; dmarc=pass action=none header.from=windriver.com; dkim=pass header.d=windriver.com; arc=none Received: from CO6PR11MB5602.namprd11.prod.outlook.com (2603:10b6:303:13a::5) by PH8PR11MB8287.namprd11.prod.outlook.com (2603:10b6:510:1c7::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7762.28; Wed, 17 Jul 2024 09:24:59 +0000 Received: from CO6PR11MB5602.namprd11.prod.outlook.com ([fe80::a7e3:721d:9cec:6093]) by CO6PR11MB5602.namprd11.prod.outlook.com ([fe80::a7e3:721d:9cec:6093%4]) with mapi id 15.20.7762.027; Wed, 17 Jul 2024 09:24:58 +0000 Content-Type: multipart/alternative; boundary="------------Pxf8tph81NE98HgK2Imn5nbA" Message-ID: <7a2ff36a-b221-2743-0ecc-a46b26b79c29@windriver.com> Date: Wed, 17 Jul 2024 17:24:52 +0800 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.10.0 Subject: Re: [OE-core][PATCH v5 2/3] openssh: systemd notification was implemented upstream Content-Language: en-US To: Jose Quaresma , Khem Raj Cc: openembedded-core@lists.openembedded.org, Jose Quaresma References: <20240716141639.1564355-1-jose.quaresma@foundries.io> <20240716141639.1564355-2-jose.quaresma@foundries.io> From: ChenQi In-Reply-To: X-ClientProxiedBy: SI1PR02CA0031.apcprd02.prod.outlook.com (2603:1096:4:1f6::11) To CO6PR11MB5602.namprd11.prod.outlook.com (2603:10b6:303:13a::5) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: CO6PR11MB5602:EE_|PH8PR11MB8287:EE_ X-MS-Office365-Filtering-Correlation-Id: 98a0426a-8bc0-4bf1-b357-08dca64253c9 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|366016|4022899009|376014; X-Microsoft-Antispam-Message-Info: =?utf-8?B?YUg5MDB5NWJwWDF3MmlZTHZJN1FPZFB5Z3AvMTNmRm9XUk1OT1J6V3grQWdZ?= =?utf-8?B?L2NCd1dyajFMZ2FHeFZtcENTZmliZWRBeVFtaU5YQi9UbTBUejdiWXpGRWcr?= =?utf-8?B?Y3FRb29iWU1XbXJVczhpU2dzR1I1YXlJTHNMM1c0d252M0ZSMzJxbVVRRjhi?= =?utf-8?B?VjBwRXhlcFpxZjBQcjkvV3JGY2UxcWdiTVFNZHFBc3FULzVUbk13a1FENFhK?= =?utf-8?B?YWpXRmZZM0FiQ3lDdlhMalBhWUhiUzB2QXh4MWVrVUMvNk9NTXRPM2NIS25t?= =?utf-8?B?akk2R1JIRUlGMHhPUEZxZHdsZUsxRS82aXBaOUFna0h6WHhjTm9zLzJReVRT?= =?utf-8?B?ZjU2WHh1R1U0b2tId242alRReGZGTVVOQ3ZHTlUxbXc1OGF3ZlBxdU1ESllx?= =?utf-8?B?WXkzOEdXdXV5bVBJMllUOFFwRU5JQ3lGVEJLY3hMMmZocHQ1R0I3dktXcTdF?= =?utf-8?B?Q0tBUlVVSUdaa3FRRjBkYURWaWZUZ3JycHV1YTRWYWZoZHQ5YjhmMnI5Njc5?= =?utf-8?B?NnA1Ui8zVGxWNzlYWnE0R1VpMUlDVmVLUmJpSUZ1UFJHbkRDT3VLNE02N3VW?= =?utf-8?B?MjlTU3ZsSkRsOWF0cmJOUGY2WG03cXNQQzR0YmVrb042VW13ZnkwRUtWdDdU?= =?utf-8?B?MFVicVRYU2x6MVZtOVlDdmhuSjdNMGFXd1FzdGNieWUwQUVSKzFuOXErdWY0?= =?utf-8?B?dkZNSXVRdEdoTVBFQ2ZGTERQR09acHc3NkNhU1dJWnBRMkRUd0d4QVpmRlN3?= =?utf-8?B?c1dpZjc4L0ZTaGlRNGtla05zRkQyR0NwWGdGcVNBZVMramNnL2Q5aHZDOXhl?= =?utf-8?B?dEJBWExlNXF4RzVLOFpMMFZHWlNadXBIL0xZUndTTytnc1pyd0JPeUh6YW52?= =?utf-8?B?VXVMOUx3WUxZVll2OUxhd296WDRDaDUzQmljMUo0L2tNWkhHeklmSUp3YVZw?= =?utf-8?B?NGdBZzBCZUtqcUlmK2laN1pja00zZ0xCdUJoL2psS093eG9oMWlrZUxFYkIv?= =?utf-8?B?NFNmRWpyUFVMLzZVSXF4RUVDREZyYjJ6WEI1ajY1SkpGM09ZUUtTcnRCbUtD?= =?utf-8?B?ZjNCLyttTit3OW1DeGxzNlEzZ0JGNnkyclUrajIxbzZ6UjYxeExyQjRDRkZO?= =?utf-8?B?M0wvUzZJakZweW4zOEMvdGN5NXdsMytNNlA4bE1BOVVUejJhaDZUd0NZdEFl?= =?utf-8?B?V3I2ckYyZ2tVbHJicHdTTDdXaGNTSHBPR2tNMVFXdC8ydXNHSUt5Tk9LUWVo?= =?utf-8?B?ZUdkeDZNeHlrT2JGa0QzQVFKS2diOFdCUTBDYnBWMEFON0V6TXVvMmRabFZD?= =?utf-8?B?Z3pRK0hMeW5rYU13dFZFVDFGMEV0ZlJGM0VQQVVkc0Z2QzB6R1hGWjlyTkhX?= =?utf-8?B?N2NnMldCaDNJdWlVWHMyb0llbzNnRVhjOXRKK2dwRVl4eHphVlZ2VnJ5TzdN?= =?utf-8?B?NDdneGFtUnptVVNvclpYTWhDTXJzNEpWU1I5b3ROVG5RYmxUdW0vaFA5WnZL?= =?utf-8?B?TDdnNjJQUnhUSDl6cWNtb3ZLYmVWZzAzWTd4TFVWZ01NbHhDamp5a2h0Yitp?= =?utf-8?B?ZTZiSnZIcVNVeTdPQ2pKbHJURkZvMWZRVEk1ZzNDTWRCWk9rbmRzM0JGaWhj?= =?utf-8?B?S2FuZ0VCOGQzdm0xNFdEMDlRQXhST1I1OFFzRHpyK3Jpc3pYVjJBQ1gvVE5v?= =?utf-8?B?M1RoWEdBRG1aQmczNnVtWlhUZVkzQ3FUU09nanppeTB6ZWtoL3ZyQytVMlln?= =?utf-8?Q?3eisl3nHVKThWKcsQQ=3D?= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:CO6PR11MB5602.namprd11.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(4022899009)(376014);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?B?L3dRWjlvcXlEVFNXSWRHTzQxUG5QRmI3c3dtamEvSVVKNFVTU3ErSlZOYmp1?= =?utf-8?B?Y00yRWoybWdZOVlONmtRQjlWOVN0eGhRRTVPN21sOER0a0lzd3dFdzloSFE1?= =?utf-8?B?TkQ0NDFEUFNRMmhXRmoxY0s3VGYzZlFrZjZSN3RXMURIbG9YNmx5TFhNSUhF?= =?utf-8?B?bzJ6T01XeXh4eGZZaUMxK0REUndudHBFbS9KMXA4K0RRTUlHZ3AwSHVhckdl?= =?utf-8?B?Ti9ZdTlOVDkybWFta1BaTmsyYWtLWHZJRURzcjJrNmZmTGROWFNMekxmQ3Z4?= =?utf-8?B?a0ZuMmtyL0ZHZnZQTE4zRS9vMkhEbENWM3ZwdXFQbUMvTDU3dUhIakVCekF5?= =?utf-8?B?UGZ1ZTF2OGEwYkFOaExnNjBnOHZQcGM1VFQrb1RhakFUWG1Wd2hlaTRmalpx?= =?utf-8?B?K0h2Y2tPMzZTK1pKTVl3bmV3dTZMZmlVRG5DaEVTY1E2bXVNK2lDYzJJMXM0?= =?utf-8?B?TTFZeVRjb1hCQzN1Q1g4ZThXK3cvQmpIdWlZekZidG5uT1dXdVNIQWpzTVc3?= =?utf-8?B?QW50cnZVRTgxWCtDT1BQTmVhTG0yNERLZ1BHYUtnN2VjMjBhZDFOVDBORGw4?= =?utf-8?B?a0YzejN2OGlUVXdBMnp2RzRML05tNVNaUnpVYTBTWmI1dHFsdmloN21VaDFW?= =?utf-8?B?MzBvanVIOEdxbTBnY0RyL3BPYXRrVmcwdFFWQUVmNGNudGU5RGFrbUNqUldo?= =?utf-8?B?S3pleElmcDFRV01hT2k3cFFNdndDSGFZTXB1cVc4MVZoL3QxWlhRVXBIN1g4?= =?utf-8?B?aDJHQmx5dkNDZ0xUM3F4ZFFyKzN5TC9YaWRZYXpRWFJIOWhjYzg4dE1sdUFa?= =?utf-8?B?RXczZEZwenVrbUdoRU4reTBrVmdWK1gzeTIrWXRhRnlHNExjWnFNZDN2QUdw?= =?utf-8?B?WWFjWlk3MXFSdkpWbzl1RWplWUlONTJCZG1LZGpJdVlLSHZYc2kzcEJPT2Jy?= =?utf-8?B?eUNVTXRnRnZDS01EV1hlRFlMSHorTHR3dE5wTW9JV1hZQ05xZklhd29vVkNn?= =?utf-8?B?d0hHMVEzT0N4NlRyOFBLMllCY2JxUE9SOFZaZ3N2cFpYelJ6UjVrcDRFSG9r?= =?utf-8?B?RlcySmRGTTROelJwLzVhd2VQaklBVjdLRDhTYmVoWXY3eHF5THVBUTd3M0gy?= =?utf-8?B?NXdXZm83dGRFMHhFZ1IrZkswUGZvTmhNYzNPNkNrYVBBQ3BZa3lYYldyNklT?= =?utf-8?B?empvTytkcXh4Qlo3azRLckZqUlJNRVM5eEQ2R2YrUXpKa3lTaUYwdlB3VFlB?= =?utf-8?B?VjhmWUJsb0N0VTh1b3lSRmVYaGFUTDhwSTcxeEpHaVhVazRzaUdqcGp3Nng0?= =?utf-8?B?S3EzRldKcjZBUWU5YkJhVFo4MmtZaTlvbFN1ZE5CN3VlejdSVzRzWjI1R2di?= =?utf-8?B?dFc3SWdEMzd0SENFWm9Lcmt4K09JRnNUMkJPYldWdlBsa1VrdVZnbXI4ZzNE?= =?utf-8?B?UHRrNTgwM1dmYlpRekVTVGZOd2NZZzRlZ25OMUQ0SW1iS0JoNnJVajg0RXJr?= =?utf-8?B?eDgraTJJOG5mL0lnenhjNktJQjlZRFErMzBDVjZRcDVvQ2ZGUS82dHZjak5V?= =?utf-8?B?VmxycjcyQzgvKzFiYUxEcW1NNFY0MlhmMXZaemFady9aaVVZZjdkbng5UkFC?= =?utf-8?B?TWswY0ZSYjFHUmtTN254WGtFSTlJWGdLVENZemJBWGtORmtMWjRvNVcwSGV4?= =?utf-8?B?bTdnMHB4cFZUYndubGhRS01jeS8rTWY4YjdOb0pJUnBlSENGWFhZc2luYXFz?= =?utf-8?B?THZkNlk3Rmt2SXhCbzBnM29KeURIN3loQXB5aVJTQ3VNazA3cHk3ZS80RFRh?= =?utf-8?B?QVNzMjA3ZW8wQnhNY2pEYjZQeVpPOHZjWDdnVjB3YysyMlRiRnZETzA0MVQx?= =?utf-8?B?emRHNDVra3RPbHZMRXdTNE9qU3hMM1lZSm4wRkRKd3BudU40bDJWb1BzWGZB?= =?utf-8?B?d1VTcVhXNzhIeEpkSStJSVJwM3FuNkNlbnpKYzQ5YVJKNTduaS9RN09VcllD?= =?utf-8?B?OStuRHc3dVNQUTdjYmRKTFpYUUNQVmQ3TGJkOGFmRll5ZUk4T0diR1ZMUkpH?= =?utf-8?B?R3ZzTGxmTDczY2NuRU85MlZIeUhhUTdMeXg0c2hGNGtzNGVEN1lCWXl0dWdD?= =?utf-8?Q?vvACnBs03Mz0+lmhr1nz3kET9?= X-OriginatorOrg: windriver.com X-MS-Exchange-CrossTenant-Network-Message-Id: 98a0426a-8bc0-4bf1-b357-08dca64253c9 X-MS-Exchange-CrossTenant-AuthSource: CO6PR11MB5602.namprd11.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Jul 2024 09:24:58.7741 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 8ddb2873-a1ad-4a18-ae4e-4644631433be X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: e2gcHtLzBdKvk+5GbsoFyBVn9cZHKy4QCk3JsSAG1TBxurLZAmkxXJ9dB6MeT1dQ6Maz9X0cU0Gsjcl2B/5MPw== X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH8PR11MB8287 X-Proofpoint-GUID: amkHl_IVtCnLpPGMfYS2FCd2aHktmA73 X-Proofpoint-ORIG-GUID: RNSyk-xYTYufShkFxsLnuUE3niJoCND9 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1039,Hydra:6.0.680,FMLib:17.12.28.16 definitions=2024-07-17_06,2024-07-16_02,2024-05-17_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 lowpriorityscore=0 priorityscore=1501 mlxscore=0 adultscore=0 spamscore=0 suspectscore=0 malwarescore=0 clxscore=1015 phishscore=0 mlxlogscore=999 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.21.0-2407110000 definitions=main-2407170072 List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 17 Jul 2024 09:25:13 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/202150 --------------Pxf8tph81NE98HgK2Imn5nbA Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: quoted-printable X-MIME-Autoconverted: from 8bit to quoted-printable by mx0a-0064b401.pphosted.com id 46H4eHar016568 I think the problem might be related to the "+Type=3Dnotify-reload" chang= e=20 in sshd@.service. It's in inetd mode so the upstream change about=20 SYSTEMD_NOTIFY should have nothing to do with it. I also doubt if the following line should be removed from sshd.service. -ExecReload=3D@BASE_BINDIR@/kill -HUP $MAINPID Regards, Qi On 7/17/24 16:46, Jose Quaresma wrote: > > Khem Raj escreveu (quarta, 17/07/2024 =C3=A0(s) 07= :38): > > actually I narrowed down my problem of disconnection to this patch = in > the series. Earlier I thought it might be related to the openssh > upgrade patch > but reverting that still causes the problem but this patch when > reverted, the problem is gone. > > > I will jump on this today and try to find the root cause. > The ptest goes well in my local tests but I didn't do anything with=20 > testimage. > I'll see if the testimage picks up something. > > Thanks=C2=A0for the feedback. > > Jose > > > On Tue, Jul 16, 2024 at 7:17=E2=80=AFAM Jose Quaresma via > lists.openembedded.org > > wrote: > > > > Still side effects of the XZ backdoor. The systemd sd-notify patc= h > > was rejected [1] upstream and was chosen a standalone implementat= ion > > that does not depend on libsystemd [2]. > > > > Racional [1]: > > > > License incompatibility and library bloatedness were the reasons. > > Given recent events we're never going to take a dependency on > libsystemd, > > though we might implement the notification protocol ourselves if > it isn't too much work. > > > > [1] > https://github.com/openssh/openssh-portable/pull/375#issuecomment-2= 027749729 > > > [2] > https://github.com/openssh/openssh-portable/commit/08f579231cd38a1c= 657aaa6ddeb8ab57a1fd4f5c > > > > > Signed-off-by: Jose Quaresma > > --- > > > > v4: > >=C2=A0 - split update of Upstream-Status in new patches in the ser= ie > > > > v5: > >=C2=A0 - use the upstream solution > > > >=C2=A0 ...-notify-systemd-on-listen-and-reload.patch | 225 > ++++++++++++++++++ > >=C2=A0 ...tional-support-for-systemd-sd_notify.patch |=C2=A0 96 --= ------ > >=C2=A0 .../openssh/openssh/sshd.service=C2=A0 =C2=A0 =C2=A0 =C2=A0= =C2=A0 =C2=A0 =C2=A0 |=C2=A0 =C2=A02 +- > >=C2=A0 .../openssh/openssh/sshd@.service=C2=A0 =C2=A0 =C2=A0 =C2=A0= =C2=A0 =C2=A0 =C2=A0|=C2=A0 =C2=A01 + > >=C2=A0 .../openssh/openssh_9.7p1.bb > > =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 |=C2=A0 =C2= =A04 +- > >=C2=A0 5 files changed, 228 insertions(+), 100 deletions(-) > >=C2=A0 create mode 100644 > meta/recipes-connectivity/openssh/openssh/0001-notify-systemd-on-li= sten-and-reload.patch > >=C2=A0 delete mode 100644 > meta/recipes-connectivity/openssh/openssh/0001-systemd-Add-optional= -support-for-systemd-sd_notify.patch > > > > diff --git > a/meta/recipes-connectivity/openssh/openssh/0001-notify-systemd-on-= listen-and-reload.patch > b/meta/recipes-connectivity/openssh/openssh/0001-notify-systemd-on-= listen-and-reload.patch > > new file mode 100644 > > index 0000000000..4925c969fe > > --- /dev/null > > +++ > b/meta/recipes-connectivity/openssh/openssh/0001-notify-systemd-on-= listen-and-reload.patch > > @@ -0,0 +1,225 @@ > > +From fc73e2405a8ca928465580b74a4d76112919367b Mon Sep 17 > 00:00:00 2001 > > +From: Damien Miller > > +Date: Wed, 3 Apr 2024 14:40:32 +1100 > > +Subject: [PATCH] notify systemd on listen and reload > > + > > +Standalone implementation that does not depend on libsystemd. > > +With assistance from Luca Boccassi, and feedback/testing from Co= lin > > +Watson. bz2641 > > + > > +Upstream-Status: Backport > [https://github.com/openssh/openssh-portable/commit/08f579231cd38a1= c657aaa6ddeb8ab57a1fd4f5c > ] > > + > > +Signed-off-by: Jose Quaresma > > +--- > > + configure.ac > > =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 |=C2=A0 1 + > > + openbsd-compat/port-linux.c | 97 > ++++++++++++++++++++++++++++++++++++- > > + openbsd-compat/port-linux.h |=C2=A0 5 ++ > > + platform.c=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0= =C2=A0 | 11 +++++ > > + platform.h=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0= =C2=A0 |=C2=A0 1 + > > + sshd.c=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 |=C2=A0 2 + > > + 6 files changed, 115 insertions(+), 2 deletions(-) > > + > > +diff --git a/configure.ac > > b/configure.ac > > > +index 82e8bb7c1..854f92b5b 100644 > > +--- a/configure.ac > > > ++++ b/configure.ac > > > +@@ -915,6 +915,7 @@ int main(void) { if > (NSVersionOfRunTimeLibrary("System") >=3D (60 << 16)) > > +=C2=A0 =C2=A0 =C2=A0 =C2=A0AC_DEFINE([_PATH_BTMP], ["/var/log/bt= mp"], [log for bad > login attempts]) > > +=C2=A0 =C2=A0 =C2=A0 =C2=A0AC_DEFINE([USE_BTMP]) > > +=C2=A0 =C2=A0 =C2=A0 =C2=A0AC_DEFINE([LINUX_OOM_ADJUST], [1], [A= djust Linux > out-of-memory killer]) > > ++=C2=A0 =C2=A0 =C2=A0 AC_DEFINE([SYSTEMD_NOTIFY], [1], [Have ssh= d notify > systemd on start/reload]) > > +=C2=A0 =C2=A0 =C2=A0 =C2=A0inet6_default_4in6=3Dyes > > +=C2=A0 =C2=A0 =C2=A0 =C2=A0case `uname -r` in > > +=C2=A0 =C2=A0 =C2=A0 =C2=A01.*|2.0.*) > > +diff --git a/openbsd-compat/port-linux.c > b/openbsd-compat/port-linux.c > > +index 0457e28d0..df7290246 100644 > > +--- a/openbsd-compat/port-linux.c > > ++++ b/openbsd-compat/port-linux.c > > +@@ -21,16 +21,23 @@ > > + > > + #include "includes.h" > > + > > +-#if defined(WITH_SELINUX) || defined(LINUX_OOM_ADJUST) > > ++#if defined(WITH_SELINUX) || defined(LINUX_OOM_ADJUST) || \ > > ++=C2=A0 =C2=A0 defined(SYSTEMD_NOTIFY) > > ++#include > > ++#include > > ++ > > + #include > > ++#include > > + #include > > + #include > > + #include > > + #include > > ++#include > > + > > + #include "log.h" > > + #include "xmalloc.h" > > + #include "port-linux.h" > > ++#include "misc.h" > > + > > + #ifdef WITH_SELINUX > > + #include > > +@@ -310,4 +317,90 @@ oom_adjust_restore(void) > > +=C2=A0 =C2=A0 =C2=A0 =C2=A0return; > > + } > > + #endif /* LINUX_OOM_ADJUST */ > > +-#endif /* WITH_SELINUX || LINUX_OOM_ADJUST */ > > ++ > > ++#ifdef SYSTEMD_NOTIFY > > ++ > > ++static void ssh_systemd_notify(const char *, ...) > > ++=C2=A0 =C2=A0 __attribute__((__format__ (printf, 1, 2))) > __attribute__((__nonnull__ (1))); > > ++ > > ++static void > > ++ssh_systemd_notify(const char *fmt, ...) > > ++{ > > ++=C2=A0 =C2=A0 =C2=A0 char *s =3D NULL; > > ++=C2=A0 =C2=A0 =C2=A0 const char *path; > > ++=C2=A0 =C2=A0 =C2=A0 struct stat sb; > > ++=C2=A0 =C2=A0 =C2=A0 struct sockaddr_un addr; > > ++=C2=A0 =C2=A0 =C2=A0 int fd =3D -1; > > ++=C2=A0 =C2=A0 =C2=A0 va_list ap; > > ++ > > ++=C2=A0 =C2=A0 =C2=A0 if ((path =3D getenv("NOTIFY_SOCKET")) =3D= =3D NULL || > strlen(path) =3D=3D 0) > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 return; > > ++ > > ++=C2=A0 =C2=A0 =C2=A0 va_start(ap, fmt); > > ++=C2=A0 =C2=A0 =C2=A0 xvasprintf(&s, fmt, ap); > > ++=C2=A0 =C2=A0 =C2=A0 va_end(ap); > > ++ > > ++=C2=A0 =C2=A0 =C2=A0 /* Only AF_UNIX is supported, with path or= abstract > sockets */ > > ++=C2=A0 =C2=A0 =C2=A0 if (path[0] !=3D '/' && path[0] !=3D '@') = { > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 error_f("socke= t \"%s\" is not compatible with > AF_UNIX", path); > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 goto out; > > ++=C2=A0 =C2=A0 =C2=A0 } > > ++ > > ++=C2=A0 =C2=A0 =C2=A0 if (path[0] =3D=3D '/' && stat(path, &sb) = !=3D 0) { > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 error_f("socke= t \"%s\" stat: %s", path, > strerror(errno)); > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 goto out; > > ++=C2=A0 =C2=A0 =C2=A0 } > > ++ > > ++=C2=A0 =C2=A0 =C2=A0 memset(&addr, 0, sizeof(addr)); > > ++=C2=A0 =C2=A0 =C2=A0 addr.sun_family =3D AF_UNIX; > > ++=C2=A0 =C2=A0 =C2=A0 if (strlcpy(addr.sun_path, path, > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 sizeof(addr.sun_path)) >=3D = sizeof(addr.sun_path)) { > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 error_f("socke= t path \"%s\" too long", path); > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 goto out; > > ++=C2=A0 =C2=A0 =C2=A0 } > > ++=C2=A0 =C2=A0 =C2=A0 /* Support for abstract socket */ > > ++=C2=A0 =C2=A0 =C2=A0 if (addr.sun_path[0] =3D=3D '@') > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 addr.sun_path[= 0] =3D 0; > > ++=C2=A0 =C2=A0 =C2=A0 if ((fd =3D socket(PF_UNIX, SOCK_DGRAM, 0)= ) =3D=3D -1) { > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 error_f("socke= t \"%s\": %s", path, strerror(errno)); > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 goto out; > > ++=C2=A0 =C2=A0 =C2=A0 } > > ++=C2=A0 =C2=A0 =C2=A0 if (connect(fd, &addr, sizeof(addr)) !=3D = 0) { > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 error_f("socke= t \"%s\" connect: %s", path, > strerror(errno)); > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 goto out; > > ++=C2=A0 =C2=A0 =C2=A0 } > > ++=C2=A0 =C2=A0 =C2=A0 if (write(fd, s, strlen(s)) !=3D (ssize_t)= strlen(s)) { > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 error_f("socke= t \"%s\" write: %s", path, > strerror(errno)); > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 goto out; > > ++=C2=A0 =C2=A0 =C2=A0 } > > ++=C2=A0 =C2=A0 =C2=A0 debug_f("socket \"%s\" notified %s", path,= s); > > ++ out: > > ++=C2=A0 =C2=A0 =C2=A0 if (fd !=3D -1) > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 close(fd); > > ++=C2=A0 =C2=A0 =C2=A0 free(s); > > ++} > > ++ > > ++void > > ++ssh_systemd_notify_ready(void) > > ++{ > > ++=C2=A0 =C2=A0 =C2=A0 ssh_systemd_notify("READY=3D1"); > > ++} > > ++ > > ++void > > ++ssh_systemd_notify_reload(void) > > ++{ > > ++=C2=A0 =C2=A0 =C2=A0 struct timespec now; > > ++ > > ++=C2=A0 =C2=A0 =C2=A0 monotime_ts(&now); > > ++=C2=A0 =C2=A0 =C2=A0 if (now.tv_sec < 0 || now.tv_nsec < 0) { > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 error_f("monot= ime returned negative value"); > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 ssh_systemd_no= tify("RELOADING=3D1"); > > ++=C2=A0 =C2=A0 =C2=A0 } else { > > ++ ssh_systemd_notify("RELOADING=3D1\nMONOTONIC_USEC=3D%llu", > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = ((uint64_t)now.tv_sec * 1000000ULL) + > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = ((uint64_t)now.tv_nsec / 1000ULL)); > > ++=C2=A0 =C2=A0 =C2=A0 } > > ++} > > ++#endif /* SYSTEMD_NOTIFY */ > > ++ > > ++#endif /* WITH_SELINUX || LINUX_OOM_ADJUST || SYSTEMD_NOTIFY */ > > +diff --git a/openbsd-compat/port-linux.h > b/openbsd-compat/port-linux.h > > +index 3c22a854d..14064f87d 100644 > > +--- a/openbsd-compat/port-linux.h > > ++++ b/openbsd-compat/port-linux.h > > +@@ -30,4 +30,9 @@ void oom_adjust_restore(void); > > + void oom_adjust_setup(void); > > + #endif > > + > > ++#ifdef SYSTEMD_NOTIFY > > ++void ssh_systemd_notify_ready(void); > > ++void ssh_systemd_notify_reload(void); > > ++#endif > > ++ > > + #endif /* ! _PORT_LINUX_H */ > > +diff --git a/platform.c b/platform.c > > +index 4fe8744ee..9cf818153 100644 > > +--- a/platform.c > > ++++ b/platform.c > > +@@ -44,6 +44,14 @@ platform_pre_listen(void) > > + #endif > > + } > > + > > ++void > > ++platform_post_listen(void) > > ++{ > > ++#ifdef SYSTEMD_NOTIFY > > ++=C2=A0 =C2=A0 =C2=A0 ssh_systemd_notify_ready(); > > ++#endif > > ++} > > ++ > > + void > > + platform_pre_fork(void) > > + { > > +@@ -55,6 +63,9 @@ platform_pre_fork(void) > > + void > > + platform_pre_restart(void) > > + { > > ++#ifdef SYSTEMD_NOTIFY > > ++=C2=A0 =C2=A0 =C2=A0 ssh_systemd_notify_reload(); > > ++#endif > > + #ifdef LINUX_OOM_ADJUST > > +=C2=A0 =C2=A0 =C2=A0 =C2=A0oom_adjust_restore(); > > + #endif > > +diff --git a/platform.h b/platform.h > > +index 7fef8c983..5dec23276 100644 > > +--- a/platform.h > > ++++ b/platform.h > > +@@ -21,6 +21,7 @@ > > + void platform_pre_listen(void); > > + void platform_pre_fork(void); > > + void platform_pre_restart(void); > > ++void platform_post_listen(void); > > + void platform_post_fork_parent(pid_t child_pid); > > + void platform_post_fork_child(void); > > + int=C2=A0 platform_privileged_uidswap(void); > > +diff --git a/sshd.c b/sshd.c > > +index b4f2b9742..865331b46 100644 > > +--- a/sshd.c > > ++++ b/sshd.c > > +@@ -2077,6 +2077,8 @@ main(int ac, char **av) > > +=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0ssh_signa= l(SIGTERM, sigterm_handler); > > +=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0ssh_signa= l(SIGQUIT, sigterm_handler); > > + > > ++=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 platform_post_= listen(); > > ++ > > +=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0/* > > +=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 * Write = out the pid file after the sigterm handler > > +=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 * is set= up and the listen sockets are bound > > +-- > > +2.45.2 > > + > > diff --git > a/meta/recipes-connectivity/openssh/openssh/0001-systemd-Add-option= al-support-for-systemd-sd_notify.patch > b/meta/recipes-connectivity/openssh/openssh/0001-systemd-Add-option= al-support-for-systemd-sd_notify.patch > > deleted file mode 100644 > > index f079d936a4..0000000000 > > --- > a/meta/recipes-connectivity/openssh/openssh/0001-systemd-Add-option= al-support-for-systemd-sd_notify.patch > > +++ /dev/null > > @@ -1,96 +0,0 @@ > > -From b02ef7621758f06eb686ef4f620636dbad086eda Mon Sep 17 > 00:00:00 2001 > > -From: Matt Jolly > > -Date: Thu, 2 Feb 2023 21:05:40 +1100 > > -Subject: [PATCH] systemd: Add optional support for systemd > `sd_notify` > > - > > -This is a rebase of Dennis Lamm's > > -patch based on Jakub Jelen's original patch > > - > > -Upstream-Status: Submitted > [https://github.com/openssh/openssh-portable/pull/375/commits/be187= 435911cde6cc3cef6982a508261074f1e56 > ] > > - > > -Signed-off-by: Xiangyu Chen > > ---- > > - configure.ac > > | 24 ++++++++++++++++++++++++ > > - sshd.c=C2=A0 =C2=A0 =C2=A0 =C2=A0| 13 +++++++++++++ > > - 2 files changed, 37 insertions(+) > > - > > -diff --git a/configure.ac > > b/configure.ac > > > -index 82e8bb7..d1145d3 100644 > > ---- a/configure.ac > > > -+++ b/configure.ac > > > -@@ -4870,6 +4870,29 @@ AC_SUBST([GSSLIBS]) > > - AC_SUBST([K5LIBS]) > > - AC_SUBST([CHANNELLIBS]) > > - > > -+# Check whether user wants systemd support > > -+SYSTEMD_MSG=3D"no" > > -+AC_ARG_WITH(systemd, > > -+=C2=A0 =C2=A0 =C2=A0 [=C2=A0 --with-systemd=C2=A0 =C2=A0 =C2=A0= =C2=A0 =C2=A0 Enable systemd support], > > -+=C2=A0 =C2=A0 =C2=A0 [ if test "x$withval" !=3D "xno" ; then > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 AC_PATH_TOOL([= PKGCONFIG], [pkg-config], [no]) > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 if test "$PKGC= ONFIG" !=3D "no"; then > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 AC_MSG_CHECKING([for libsystemd]) > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 if $PKGCONFIG --exists libsystemd; then > > -+ SYSTEMD_CFLAGS=3D`$PKGCONFIG --cflags libsystemd` > > -+ SYSTEMD_LIBS=3D`$PKGCONFIG --libs libsystemd` > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 CPPFLAGS=3D"$CPPFLAGS $SYSTEMD_= CFLAGS" > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 SSHDLIBS=3D"$SSHDLIBS $SYSTEMD_= LIBS" > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 AC_MSG_RESULT([yes]) > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 AC_DEFINE(HAVE_SYSTEMD, 1, > [Define if you want systemd support.]) > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 SYSTEMD_MSG=3D"yes" > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 else > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 AC_MSG_RESULT([no]) > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 fi > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 fi > > -+=C2=A0 =C2=A0 =C2=A0 fi ] > > -+) > > -+ > > - # Looking for programs, paths and files > > - > > - PRIVSEP_PATH=3D/var/empty > > -@@ -5688,6 +5711,7 @@ echo "=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0libldns support: > $LDNS_MSG" > > - echo "=C2=A0 Solaris process contract support: $SPC_MSG" > > - echo "=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Solaris project = support: $SP_MSG" > > - echo "=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Solaris privilege suppo= rt: $SPP_MSG" > > -+echo "=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0systemd support: $SYSTEMD_MSG" > > - echo "=C2=A0 =C2=A0 =C2=A0 =C2=A0IP address in \$DISPLAY hack: = $DISPLAY_HACK_MSG" > > - echo "=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Translate v4 in = v6 hack: $IPV4_IN6_HACK_MSG" > > - echo "=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 BSD Auth support: $BSD_AUTH_MSG" > > -diff --git a/sshd.c b/sshd.c > > -index b4f2b97..6820a41 100644 > > ---- a/sshd.c > > -+++ b/sshd.c > > -@@ -88,6 +88,10 @@ > > - #include > > - #endif > > - > > -+#ifdef HAVE_SYSTEMD > > -+#include > > -+#endif > > -+ > > - #include "xmalloc.h" > > - #include "ssh.h" > > - #include "ssh2.h" > > -@@ -308,6 +312,10 @@ static void > > - sighup_restart(void) > > - { > > -=C2=A0 =C2=A0 =C2=A0 =C2=A0logit("Received SIGHUP; restarting.")= ; > > -+#ifdef HAVE_SYSTEMD > > -+=C2=A0 =C2=A0 =C2=A0 /* Signal systemd that we are reloading */ > > -+=C2=A0 =C2=A0 =C2=A0 sd_notify(0, "RELOADING=3D1"); > > -+#endif > > -=C2=A0 =C2=A0 =C2=A0 =C2=A0if (options.pid_file !=3D NULL) > > -=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0unlink(op= tions.pid_file); > > -=C2=A0 =C2=A0 =C2=A0 =C2=A0platform_pre_restart(); > > -@@ -2093,6 +2101,11 @@ main(int ac, char **av) > > -=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0} > > -=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0} > > - > > -+#ifdef HAVE_SYSTEMD > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 /* Signal syst= emd that we are ready to accept > connections */ > > -+=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 sd_notify(0, "= READY=3D1"); > > -+#endif > > -+ > > -=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0/* Accept= a connection and return in a forked > child */ > > -=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0server_ac= cept_loop(&sock_in, &sock_out, > > -=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0&newsock, config_s); > > diff --git > a/meta/recipes-connectivity/openssh/openssh/sshd.service > b/meta/recipes-connectivity/openssh/openssh/sshd.service > > index 3e570ab1e5..c71fff1cc1 100644 > > --- a/meta/recipes-connectivity/openssh/openssh/sshd.service > > +++ b/meta/recipes-connectivity/openssh/openssh/sshd.service > > @@ -5,11 +5,11 @@ After=3Dsshdgenkeys.service > >=C2=A0 After=3Dnss-user-lookup.target > > > > >=C2=A0 [Service] > > +Type=3Dnotify-reload > >=C2=A0 Environment=3D"SSHD_OPTS=3D" > >=C2=A0 EnvironmentFile=3D-/etc/default/ssh > >=C2=A0 ExecStartPre=3D@BASE_BINDIR@/mkdir -p /var/run/sshd > >=C2=A0 ExecStart=3D-@SBINDIR@/sshd -D $SSHD_OPTS > > -ExecReload=3D@BASE_BINDIR@/kill -HUP $MAINPID > >=C2=A0 KillMode=3Dprocess > >=C2=A0 Restart=3Don-failure > >=C2=A0 RestartSec=3D42s > > diff --git > a/meta/recipes-connectivity/openssh/openssh/sshd@.service > b/meta/recipes-connectivity/openssh/openssh/sshd@.service > > index 9d9965e624..dcfec8f054 100644 > > --- a/meta/recipes-connectivity/openssh/openssh/sshd@.service > > +++ b/meta/recipes-connectivity/openssh/openssh/sshd@.service > > @@ -3,6 +3,7 @@ Description=3DOpenSSH Per-Connection Daemon > >=C2=A0 After=3Dsshdgenkeys.service > > > >=C2=A0 [Service] > > +Type=3Dnotify-reload > >=C2=A0 Environment=3D"SSHD_OPTS=3D" > >=C2=A0 EnvironmentFile=3D-/etc/default/ssh > >=C2=A0 ExecStart=3D-@SBINDIR@/sshd -i $SSHD_OPTS > > diff --git a/meta/recipes-connectivity/openssh/openssh_9.7p1.bb > > b/meta/recipes-connectivity/openssh/openssh_9.7p1.bb > > > index 4f20616295..4680d12be5 100644 > > --- a/meta/recipes-connectivity/openssh/openssh_9.7p1.bb > > > +++ b/meta/recipes-connectivity/openssh/openssh_9.7p1.bb > > > @@ -24,7 +24,7 @@ SRC_URI =3D > "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.= tar > > > file://run-ptest \ > > file://sshd_check_keys \ > > > file://0001-regress-banner.sh-log-input-and-output-files-on-erro.pa= tch > \ > > - > file://0001-systemd-Add-optional-support-for-systemd-sd_notify.patc= h \ > > + file://0001-notify-systemd-on-listen-and-reload.patch \ > > file://CVE-2024-6387.patch \ > >=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0" > >=C2=A0 SRC_URI[sha256sum] =3D > "490426f766d82a2763fcacd8d83ea3d70798750c7bd2aff2e57dc5660f773ffd" > > @@ -52,7 +52,6 @@ SYSTEMD_PACKAGES =3D "${PN}-sshd" > >=C2=A0 SYSTEMD_SERVICE:${PN}-sshd =3D > "${@bb.utils.contains('PACKAGECONFIG','systemd-sshd-socket-mode','s= shd.socket', > '', d)} > ${@bb.utils.contains('PACKAGECONFIG','systemd-sshd-service-mode','s= shd.service', > '', d)}" > > > >=C2=A0 inherit autotools-brokensep ptest pkgconfig > > -DEPENDS +=3D "${@bb.utils.contains('DISTRO_FEATURES', 'systemd', > 'systemd', '', d)}" > > > >=C2=A0 # systemd-sshd-socket-mode means installing sshd.socket > >=C2=A0 # and systemd-sshd-service-mode corresponding to sshd.servi= ce > > @@ -78,7 +77,6 @@ EXTRA_OECONF =3D > "'LOGIN_PROGRAM=3D${base_bindir}/login' \ > >=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 --s= ysconfdir=3D${sysconfdir}/ssh \ > >=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 --w= ith-xauth=3D${bindir}/xauth \ > >=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 --d= isable-strip \ > > - ${@bb.utils.contains('DISTRO_FEATURES', 'systemd', > '--with-systemd', '--without-systemd', d)} \ > >=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 " > > > >=C2=A0 # musl doesn't implement wtmp/utmp and logwtmp > > -- > > 2.45.2 > > > > > > > > > > > > --=20 > Best regards, > > Jos=C3=A9 Quaresma > > -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- > Links: You receive all messages sent to this group. > View/Reply Online (#202144):https://lists.openembedded.org/g/openembedd= ed-core/message/202144 > Mute This Topic:https://lists.openembedded.org/mt/107252588/7304865 > Group Owner:openembedded-core+owner@lists.openembedded.org > Unsubscribe:https://lists.openembedded.org/g/openembedded-core/unsub [= Qi.Chen@eng.windriver.com] > -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- > --------------Pxf8tph81NE98HgK2Imn5nbA Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-MIME-Autoconverted: from 8bit to quoted-printable by mx0a-0064b401.pphosted.com id 46H4eHar016568
I think the problem might be related t= o the "+Type=3Dnotify-reload" change in sshd@.service. It's = in inetd mode so the upstream change about SYSTEMD_NOTIFY should have nothing to do with it.
I also doubt if the following line should be removed from sshd.service.
-ExecReload=3D@BASE_BINDIR@/=
kill -HUP $MAINPID
Regards,
Qi

On 7/17/24 16:46, Jose Quaresma wrote:=
=20

Khem Raj <raj.khem@gmail.com> escreveu (quarta, 17/07/2024 =C3=A0(s) 07:38):
actually I narrowed down my problem of disconnection to this patch in
the series. Earlier I thought it might be related to the openssh
upgrade patch
but reverting that still causes the problem but this patch when
reverted, the problem is gone.

I will jump on this today and try to find the root cause.<= /div>
The ptest goes well in my local tests but I didn't do anything with testimage.
I'll see if the testimage picks up something.

Thanks for the feedback.

Jose
 

On Tue, Jul 16, 2024 at 7:17=E2=80=AFAM Jose Quaresma via
lists.openembedded.org
<quaresma.jose=3Dgmail.com@lists.openembedded.org> wrote:
>
> Still side effects of the XZ backdoor. The systemd sd-notify patch
> was rejected [1] upstream and was chosen a standalone implementation
> that does not depend on libsystemd [2].
>
> Racional [1]:
>
> License incompatibility and library bloatedness were the reasons.
> Given recent events we're never going to take a dependency on libsystemd,
> though we might implement the notification protocol ourselves if it isn't too much work.
>
> [1] https://github.com/openssh/openssh-portable/pull/375#= issuecomment-2027749729
> [2] https://github.com/openssh/openssh-porta= ble/commit/08f579231cd38a1c657aaa6ddeb8ab57a1fd4f5c
>
> Signed-off-by: Jose Quaresma <jose.quaresma@foundries.io>
> ---
>
> v4:
>  - split update of Upstream-Status in new patches i= n the serie
>
> v5:
>  - use the upstream solution
>
>  ...-notify-systemd-on-listen-and-reload.patch | 22= 5 ++++++++++++++++++
>  ...tional-support-for-systemd-sd_notify.patch |&nb= sp; 96 --------
>  .../openssh/openssh/sshd.service    &nbs= p;         |   2 +-
>  .../openssh/openssh/sshd@.service    &nb= sp;        |   1 +
>  .../openssh/openssh_9.7p1.bb&= nbsp;                 |&nbs= p;  4 +-
>  5 files changed, 228 insertions(+), 100 deletions(= -)
>  create mode 100644 meta/recipes-connectivity/openssh/openssh/0001-notify-systemd-on-listen-a= nd-reload.patch
>  delete mode 100644 meta/recipes-connectivity/openssh/openssh/0001-systemd-Add-optional-suppo= rt-for-systemd-sd_notify.patch
>
> diff --git a/meta/recipes-connectivity/openssh/openssh/0001-notify-systemd-on-listen= -and-reload.patch b/meta/recipes-connectivity/openssh/openssh/0001-notify-systemd-on-listen= -and-reload.patch
> new file mode 100644
> index 0000000000..4925c969fe
> --- /dev/null
> +++ b/meta/recipes-connectivity/openssh/openssh/0001-notify-systemd-on-listen= -and-reload.patch
> @@ -0,0 +1,225 @@
> +From fc73e2405a8ca928465580b74a4d76112919367b Mon Sep 17 00:00:00 2001
> +From: Damien Miller <djm@mindrot.org>
> +Date: Wed, 3 Apr 2024 14:40:32 +1100
> +Subject: [PATCH] notify systemd on listen and reload > +
> +Standalone implementation that does not depend on libsystemd.
> +With assistance from Luca Boccassi, and feedback/testing from Colin
> +Watson. bz2641
> +
> +Upstream-Status: Backport [https://github.co= m/openssh/openssh-portable/commit/08f579231cd38a1c657aaa6ddeb8ab57a1fd4f5= c]
> +
> +Signed-off-by: Jose Quaresma <jose.quaresma@foundries.io>
> +---
> + configure.ac                |  1 +<= br> > + openbsd-compat/port-linux.c | 97 ++++++++++++++++++++++++++++++++++++-
> + openbsd-compat/port-linux.h |  5 ++
> + platform.c            &n= bsp;     | 11 +++++
> + platform.h            &n= bsp;     |  1 +
> + sshd.c             =         |  2 +
> + 6 files changed, 115 insertions(+), 2 deletions(-)
> +
> +diff --git a/configure.ac b/configure.ac
> +index 82e8bb7c1..854f92b5b 100644
> +--- a/configure.ac
> ++++ b/configure.ac
> +@@ -915,6 +915,7 @@ int main(void) { if (NSVersionOfRunTimeLibrary("System") >=3D (60 &l= t;< 16))
> +       AC_DEFINE([_PATH_BTMP], [&qu= ot;/var/log/btmp"], [log for bad login attempts])
> +       AC_DEFINE([USE_BTMP])
> +       AC_DEFINE([LINUX_OOM_ADJUST]= , [1], [Adjust Linux out-of-memory killer])
> ++      AC_DEFINE([SYSTEMD_NOTIFY], [1], = [Have sshd notify systemd on start/reload])
> +       inet6_default_4in6=3Dyes
> +       case `uname -r` in
> +       1.*|2.0.*)
> +diff --git a/openbsd-compat/port-linux.c b/openbsd-compat/port-linux.c
> +index 0457e28d0..df7290246 100644
> +--- a/openbsd-compat/port-linux.c
> ++++ b/openbsd-compat/port-linux.c
> +@@ -21,16 +21,23 @@
> +
> + #include "includes.h"
> +
> +-#if defined(WITH_SELINUX) || defined(LINUX_OOM_ADJUST)
> ++#if defined(WITH_SELINUX) || defined(LINUX_OOM_ADJUST) || \
> ++    defined(SYSTEMD_NOTIFY)
> ++#include <sys/socket.h>
> ++#include <sys/un.h>
> ++
> + #include <errno.h>
> ++#include <inttypes.h>
> + #include <stdarg.h>
> + #include <string.h>
> + #include <stdio.h>
> + #include <stdlib.h>
> ++#include <time.h>
> +
> + #include "log.h"
> + #include "xmalloc.h"
> + #include "port-linux.h"
> ++#include "misc.h"
> +
> + #ifdef WITH_SELINUX
> + #include <selinux/selinux.h>
> +@@ -310,4 +317,90 @@ oom_adjust_restore(void)
> +       return;
> + }
> + #endif /* LINUX_OOM_ADJUST */
> +-#endif /* WITH_SELINUX || LINUX_OOM_ADJUST */
> ++
> ++#ifdef SYSTEMD_NOTIFY
> ++
> ++static void ssh_systemd_notify(const char *, ...)
> ++    __attribute__((__format__ (printf, 1, 2)= )) __attribute__((__nonnull__ (1)));
> ++
> ++static void
> ++ssh_systemd_notify(const char *fmt, ...)
> ++{
> ++      char *s =3D NULL;
> ++      const char *path;
> ++      struct stat sb;
> ++      struct sockaddr_un addr;
> ++      int fd =3D -1;
> ++      va_list ap;
> ++
> ++      if ((path =3D getenv("NOTIFY= _SOCKET")) =3D=3D NULL || strlen(path) =3D=3D 0)
> ++              retur= n;
> ++
> ++      va_start(ap, fmt);
> ++      xvasprintf(&s, fmt, ap);
> ++      va_end(ap);
> ++
> ++      /* Only AF_UNIX is supported, wit= h path or abstract sockets */
> ++      if (path[0] !=3D '/' && p= ath[0] !=3D '@') {
> ++              error= _f("socket \"%s\" is not compatible with AF_UNIX", path);
> ++              goto = out;
> ++      }
> ++
> ++      if (path[0] =3D=3D '/' &&= stat(path, &sb) !=3D 0) {
> ++              error= _f("socket \"%s\" stat: %s", path, strerror(errno));
> ++              goto = out;
> ++      }
> ++
> ++      memset(&addr, 0, sizeof(addr)= );
> ++      addr.sun_family =3D AF_UNIX;
> ++      if (strlcpy(addr.sun_path, path,<= br> > ++          sizeof(addr.sun_pat= h)) >=3D sizeof(addr.sun_path)) {
> ++              error= _f("socket path \"%s\" too long", path);
> ++              goto = out;
> ++      }
> ++      /* Support for abstract socket */=
> ++      if (addr.sun_path[0] =3D=3D '@')<= br> > ++              addr.= sun_path[0] =3D 0;
> ++      if ((fd =3D socket(PF_UNIX, SOCK_= DGRAM, 0)) =3D=3D -1) {
> ++              error= _f("socket \"%s\": %s", path, strerror(errno));
> ++              goto = out;
> ++      }
> ++      if (connect(fd, &addr, sizeof= (addr)) !=3D 0) {
> ++              error= _f("socket \"%s\" connect: %s", path, strerror(errno));
> ++              goto = out;
> ++      }
> ++      if (write(fd, s, strlen(s)) !=3D (ssize_t)strlen(s)) {
> ++              error= _f("socket \"%s\" write: %s", path, strerror(errno));
> ++              goto = out;
> ++      }
> ++      debug_f("socket \"%s\&q= uot; notified %s", path, s);
> ++ out:
> ++      if (fd !=3D -1)
> ++              close= (fd);
> ++      free(s);
> ++}
> ++
> ++void
> ++ssh_systemd_notify_ready(void)
> ++{
> ++      ssh_systemd_notify("READY=3D= 1");
> ++}
> ++
> ++void
> ++ssh_systemd_notify_reload(void)
> ++{
> ++      struct timespec now;
> ++
> ++      monotime_ts(&now);
> ++      if (now.tv_sec < 0 || now.tv_n= sec < 0) {
> ++              error= _f("monotime returned negative value");
> ++              ssh_s= ystemd_notify("RELOADING=3D1");
> ++      } else {
> ++              ssh_systemd_notify("RELOADING=3D1\nMONOTONIC_USEC=3D%llu= ",
> ++               = ;   ((uint64_t)now.tv_sec * 1000000ULL) +
> ++               = ;   ((uint64_t)now.tv_nsec / 1000ULL));
> ++      }
> ++}
> ++#endif /* SYSTEMD_NOTIFY */
> ++
> ++#endif /* WITH_SELINUX || LINUX_OOM_ADJUST || SYSTEMD_NOTIFY */
> +diff --git a/openbsd-compat/port-linux.h b/openbsd-compat/port-linux.h
> +index 3c22a854d..14064f87d 100644
> +--- a/openbsd-compat/port-linux.h
> ++++ b/openbsd-compat/port-linux.h
> +@@ -30,4 +30,9 @@ void oom_adjust_restore(void);
> + void oom_adjust_setup(void);
> + #endif
> +
> ++#ifdef SYSTEMD_NOTIFY
> ++void ssh_systemd_notify_ready(void);
> ++void ssh_systemd_notify_reload(void);
> ++#endif
> ++
> + #endif /* ! _PORT_LINUX_H */
> +diff --git a/platform.c b/platform.c
> +index 4fe8744ee..9cf818153 100644
> +--- a/platform.c
> ++++ b/platform.c
> +@@ -44,6 +44,14 @@ platform_pre_listen(void)
> + #endif
> + }
> +
> ++void
> ++platform_post_listen(void)
> ++{
> ++#ifdef SYSTEMD_NOTIFY
> ++      ssh_systemd_notify_ready();
> ++#endif
> ++}
> ++
> + void
> + platform_pre_fork(void)
> + {
> +@@ -55,6 +63,9 @@ platform_pre_fork(void)
> + void
> + platform_pre_restart(void)
> + {
> ++#ifdef SYSTEMD_NOTIFY
> ++      ssh_systemd_notify_reload();
> ++#endif
> + #ifdef LINUX_OOM_ADJUST
> +       oom_adjust_restore();
> + #endif
> +diff --git a/platform.h b/platform.h
> +index 7fef8c983..5dec23276 100644
> +--- a/platform.h
> ++++ b/platform.h
> +@@ -21,6 +21,7 @@
> + void platform_pre_listen(void);
> + void platform_pre_fork(void);
> + void platform_pre_restart(void);
> ++void platform_post_listen(void);
> + void platform_post_fork_parent(pid_t child_pid);
> + void platform_post_fork_child(void);
> + int  platform_privileged_uidswap(void);
> +diff --git a/sshd.c b/sshd.c
> +index b4f2b9742..865331b46 100644
> +--- a/sshd.c
> ++++ b/sshd.c
> +@@ -2077,6 +2077,8 @@ main(int ac, char **av)
> +               = ssh_signal(SIGTERM, sigterm_handler);
> +               = ssh_signal(SIGQUIT, sigterm_handler);
> +
> ++              platf= orm_post_listen();
> ++
> +               = /*
> +               = * Write out the pid file after the sigterm handler
> +               = * is setup and the listen sockets are bound
> +--
> +2.45.2
> +
> diff --git a/meta/recipes-connectivity/openssh/openssh/0001-systemd-Add-optional-sup= port-for-systemd-sd_notify.patch b/meta/recipes-connectivity/openssh/openssh/0001-systemd-Add-optional-sup= port-for-systemd-sd_notify.patch
> deleted file mode 100644
> index f079d936a4..0000000000
> --- a/meta/recipes-connectivity/openssh/openssh/0001-systemd-Add-optional-sup= port-for-systemd-sd_notify.patch
> +++ /dev/null
> @@ -1,96 +0,0 @@
> -From b02ef7621758f06eb686ef4f620636dbad086eda Mon Sep 17 00:00:00 2001
> -From: Matt Jolly <Matt.Jolly@footclan.ninja><= /a>
> -Date: Thu, 2 Feb 2023 21:05:40 +1100
> -Subject: [PATCH] systemd: Add optional support for systemd `sd_notify`
> -
> -This is a rebase of Dennis Lamm's <
expeditioneer@gentoo.org>
> -patch based on Jakub Jelen's <jjelen@redhat.com> original patch
> -
> -Upstream-Status: Submitted [https= ://github.com/openssh/openssh-portable/pull/375/commits/be187435911cde6cc= 3cef6982a508261074f1e56]
> -
> -Signed-off-by: Xiangyu Chen <xiangyu.chen@windriver.com>
> ----
> - configure.ac | 24 ++++++++++++++++++++++++
> - sshd.c       | 13 +++++++++++++ > - 2 files changed, 37 insertions(+)
> -
> -diff --git a/configure.ac b/configure.ac
> -index 82e8bb7..d1145d3 100644
> ---- a/configure.ac
> -+++ b/configure.ac
> -@@ -4870,6 +4870,29 @@ AC_SUBST([GSSLIBS])
> - AC_SUBST([K5LIBS])
> - AC_SUBST([CHANNELLIBS])
> -
> -+# Check whether user wants systemd support
> -+SYSTEMD_MSG=3D"no"
> -+AC_ARG_WITH(systemd,
> -+      [  --with-systemd  &nbs= p;       Enable systemd support],
> -+      [ if test "x$withval" != =3D "xno" ; then
> -+              AC_PA= TH_TOOL([PKGCONFIG], [pkg-config], [no])
> -+              if te= st "$PKGCONFIG" !=3D "no"; then
> -+               = ;       AC_MSG_CHECKING([for libsystemd])
> -+               = ;       if $PKGCONFIG --exists libsystemd; then
> -+               = ;               SYSTEMD_CFLAGS=3D`$PKGCONFIG --cflags libsystemd`
> -+               = ;               SYSTEMD_LIBS=3D`$PKGCONFIG --libs libsystemd`
> -+               = ;               CPPFLAGS=3D"$CPPF= LAGS $SYSTEMD_CFLAGS"
> -+               = ;               SSHDLIBS=3D"$SSHD= LIBS $SYSTEMD_LIBS"
> -+               = ;               AC_MSG_RESULT([yes]) > -+               = ;               AC_DEFINE(HAVE_SYSTEMD= , 1, [Define if you want systemd support.])
> -+               = ;               SYSTEMD_MSG=3D"ye= s"
> -+               = ;       else
> -+               = ;               AC_MSG_RESULT([no]) > -+               = ;       fi
> -+              fi > -+      fi ]
> -+)
> -+
> - # Looking for programs, paths and files
> -
> - PRIVSEP_PATH=3D/var/empty
> -@@ -5688,6 +5711,7 @@ echo "      &= nbsp;            libldns support: $LDNS_MSG"
> - echo "  Solaris process contract support: $S= PC_MSG"
> - echo "           So= laris project support: $SP_MSG"
> - echo "         Solaris p= rivilege support: $SPP_MSG"
> -+echo "            &= nbsp;      systemd support: $SYSTEMD_MSG"
> - echo "       IP address in \$= DISPLAY hack: $DISPLAY_HACK_MSG"
> - echo "           Tr= anslate v4 in v6 hack: $IPV4_IN6_HACK_MSG"
> - echo "            &= nbsp;     BSD Auth support: $BSD_AUTH_MSG"
> -diff --git a/sshd.c b/sshd.c
> -index b4f2b97..6820a41 100644
> ---- a/sshd.c
> -+++ b/sshd.c
> -@@ -88,6 +88,10 @@
> - #include <prot.h>
> - #endif
> -
> -+#ifdef HAVE_SYSTEMD
> -+#include <systemd/sd-daemon.h>
> -+#endif
> -+
> - #include "xmalloc.h"
> - #include "ssh.h"
> - #include "ssh2.h"
> -@@ -308,6 +312,10 @@ static void
> - sighup_restart(void)
> - {
> -       logit("Received SIGHUP;= restarting.");
> -+#ifdef HAVE_SYSTEMD
> -+      /* Signal systemd that we are rel= oading */
> -+      sd_notify(0, "RELOADING=3D1&= quot;);
> -+#endif
> -       if (options.pid_file !=3D NU= LL)
> -               = unlink(options.pid_file);
> -       platform_pre_restart();
> -@@ -2093,6 +2101,11 @@ main(int ac, char **av)
> -               =        }
> -               = }
> -
> -+#ifdef HAVE_SYSTEMD
> -+              /* Si= gnal systemd that we are ready to accept connections */
> -+              sd_no= tify(0, "READY=3D1");
> -+#endif
> -+
> -               = /* Accept a connection and return in a forked child */
> -               = server_accept_loop(&sock_in, &sock_out,
> -               =    &newsock, config_s);
> diff --git a/meta/recipes-connectivity/openssh/openssh/sshd.service b/meta/recipes-connectivity/openssh/openssh/sshd.service
> index 3e570ab1e5..c71fff1cc1 100644
> --- a/meta/recipes-connectivity/openssh/openssh/sshd.service
> +++ b/meta/recipes-connectivity/openssh/openssh/sshd.service
> @@ -5,11 +5,11 @@ After=3Dsshdgenkeys.service
>  After=3Dnss-user-lookup.target
>
>  [Service]
> +Type=3Dnotify-reload
>  Environment=3D"SSHD_OPTS=3D"
>  EnvironmentFile=3D-/etc/default/ssh
>  ExecStartPre=3D@BASE_BINDIR@/mkdir -p /var/run/ssh= d
>  ExecStart=3D-@SBINDIR@/sshd -D $SSHD_OPTS
> -ExecReload=3D@BASE_BINDIR@/kill -HUP $MAINPID
>  KillMode=3Dprocess
>  Restart=3Don-failure
>  RestartSec=3D42s
> diff --git a/meta/recipes-connect= ivity/openssh/openssh/sshd@.service b/meta/recipes-connect= ivity/openssh/openssh/sshd@.service
> index 9d9965e624..dcfec8f054 100644
> --- a/meta/recipes-connect= ivity/openssh/openssh/sshd@.service
> +++ b/meta/recipes-connect= ivity/openssh/openssh/sshd@.service
> @@ -3,6 +3,7 @@ Description=3DOpenSSH Per-Connection Daemon
>  After=3Dsshdgenkeys.service
>
>  [Service]
> +Type=3Dnotify-reload
>  Environment=3D"SSHD_OPTS=3D"
>  EnvironmentFile=3D-/etc/default/ssh
>  ExecStart=3D-@SBINDIR@/sshd -i $SSHD_OPTS
> diff --git a/meta/recipes-connectivity/openssh/openssh_9.7p1.bb b/meta/recipes-connectivity/openssh/openssh_= 9.7p1.bb
> index 4f20616295..4680d12be5 100644
> --- a/meta/recipes-connectivity/openssh/openssh_9.7p1.bb
> +++ b/meta/recipes-connectivity/openssh/openssh_9.7p1.bb
> @@ -24,7 +24,7 @@ SRC_URI =3D "http://ftp.openbsd.org/= pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
>             file://run-ptest \<= br> >             file://sshd_check= _keys \
>             file://0001-r= egress-banner.sh-log-input-and-output-files-on-erro.patch \
> -           file://0001-sys= temd-Add-optional-support-for-systemd-sd_notify.patch \
> +           file://0001-notify-systemd-on-= listen-and-reload.patch \
>             file://CVE-20= 24-6387.patch \
>             " >  SRC_URI[sha256sum] =3D "490426f766d82a2763fcacd8d83ea3d70798750c7bd2aff2e57dc56= 60f773ffd"
> @@ -52,7 +52,6 @@ SYSTEMD_PACKAGES =3D "${PN}-sshd&= quot;
>  SYSTEMD_SERVICE:${PN}-sshd =3D "${@bb.utils.contains('PACKAGECONFIG','systemd-sshd-socket-mode',= 'sshd.socket', '', d)} ${@bb.utils.contains('PACKAGECONFIG','systemd-sshd-service-mode','sshd.se= rvice', '', d)}"
>
>  inherit autotools-brokensep ptest pkgconfig
> -DEPENDS +=3D

--
Best regards,

Jos=C3=A9 Quaresma

-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-
Links: You receive all messages sent to this group.
View/Reply Online (#202144): https:/=
/lists.openembedded.org/g/openembedded-core/message/202144
Mute This Topic: https://lists.openembedded.org/mt=
/107252588/7304865
Group Owner: openembedded-core+owner@lists.op=
enembedded.org
Unsubscribe: https://lists.openembedded.org/g=
/openembedded-core/unsub [Qi.Chen@eng.windriver.com]
-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-


--------------Pxf8tph81NE98HgK2Imn5nbA--