how on earth does openssh not only have incredibly fucked versioning but is the only package i've ever seen to mention a "privilege separation" chroot path which actively breaks non-root builds. are you fucking kidding me bruh. "privilege separation chroot" defaulting to /var/empty and it immediately errors if it can't create it????? why are your version strings like that bruh?????
ok so they decided to reinvent sudo for sshd root https://github.com/openssh/openssh-portable/blob/master/README.privsep if i cannot disable the sshd build (reading ./configure --help in a crazed demented rage did not see the flag for it) i'm going to commit several murders
how do you spend 8kb of text and provide multiple detailed ASCII art diagrams regarding your privilege separation methodology and oh my god wait does it really require sshd to be root too yes it literally does are you fucking kidding me
this is so fucked
sshd is the main entry-point binary for the server. This binary retains privilege but performs a very limited set of tasks: loading and checking the configuration, listening for incoming connections
and monitoring the status of connections through the pre-authentication phase of their lifecycle to implement the MaxStartups and PerSourcePenalties features.
NONE OF THESE THINGS REQUIRE ROOT WHAT THE FUCK
@hipsterelectron Maybe I'm VASTLY missing the point here, but doesn't listening on port 22 require root, because 22 is a privileged port? Isn't there a tradition of servers being forced to use root on linux for this reason even if they don't need it for other reasons?
how is anyone ok with this????? it takes half the document and two fork/execs before it gets to why sshd-auth would need root:
All operations that require privilege, such as looking up user information, private key signatures, checking passwords, etc are performed by RPC to the parent sshd-session process.
- looking up user information????????
- i think you can calculate cryptographic signatures without root????
- the fuck do you mean """"checking passwords"""""
i have been informed that even looking up the list of users requires root and have concluded that the unix user model is well-designed to suit the bell labs HR system from the 1970s and was never a serious general permissions model
https://github.com/openssh/openssh-portable/blob/master/LICENCE
i have never seen a stranger license file in my entire life. they also spell the filename in a way i have never seen before
Some code is licensed under a MIT-style license to the following
copyright holders:Free Software Foundation, Inc.
that's not even legally binding and obviously intended as an insult. they also mixed spaces and tabs in indentation???
https://github.com/openssh/openssh-portable/commit/7294baaf6ab389fd206899d68a1ad400ba2f4508
- (djm) Forgot to cvs add LICENSE file
first of all, what a remarkably specific commit description. second of all, that's not worth a ChangeLog entry. third, it's not named LICENSE?
i didn't peruse the whole contents of the LICENCE file because the file being 300 pages long and under a nonstandard filename without symlinks tells me that this is an incredibly politically motivated project. i wonder if that means they're left-wing!
it takes a certain kind of person to use "portable" while using fucking autoconf and then stuffing the LICENCE file with actively contradictory statements
oh and there is a single very clear and absolutely legally actionable statement at the beginning of the LICENSE
Any derived versions of this
* software must be clearly marked as such, and if the derived work is
* incompatible with the protocol description in the RFC file, it must be
* called by a name other than "ssh" or "Secure Shell".
"Any derived versions of this software must be clearly marked as such" is completely incompatible with publishing it via git, but i think that's intentional and it just serves to sound vaguely legal so the line after it sounds legally actionable
that is fucking bizarre. it's also incredibly strange to assign copyright to a single person in the first place. who the fuck is tatu ylonen
https://fi.wikipedia.org/wiki/Tatu_Yl%C3%B6nen english wikipedia has no page on him but i believe finnish wikipedia says he invented ssh. however his own website https://ylonen.org/ then clarifies he wrote "the original ssh" but not openssh which should be sufficient evidence to void his copyright claim over any of the code at all
@hipsterelectron changing user to the target user after login requires root