how on earth does openssh not only have incredibly fucked versioning but is the only package i've ever seen to mention a "privilege separation" chroot path which actively breaks non-root builds. are you fucking kidding me bruh. "privilege separation chroot" defaulting to /var/empty and it immediately errors if it can't create it????? why are your version strings like that bruh?????
ok so they decided to reinvent sudo for sshd root https://github.com/openssh/openssh-portable/blob/master/README.privsep if i cannot disable the sshd build (reading ./configure --help in a crazed demented rage did not see the flag for it) i'm going to commit several murders
how do you spend 8kb of text and provide multiple detailed ASCII art diagrams regarding your privilege separation methodology and oh my god wait does it really require sshd to be root too yes it literally does are you fucking kidding me
this is so fucked
sshd is the main entry-point binary for the server. This binary retains privilege but performs a very limited set of tasks: loading and checking the configuration, listening for incoming connections
and monitoring the status of connections through the pre-authentication phase of their lifecycle to implement the MaxStartups and PerSourcePenalties features.
NONE OF THESE THINGS REQUIRE ROOT WHAT THE FUCK
@hipsterelectron Maybe I'm VASTLY missing the point here, but doesn't listening on port 22 require root, because 22 is a privileged port? Isn't there a tradition of servers being forced to use root on linux for this reason even if they don't need it for other reasons?
how is anyone ok with this????? it takes half the document and two fork/execs before it gets to why sshd-auth would need root:
All operations that require privilege, such as looking up user information, private key signatures, checking passwords, etc are performed by RPC to the parent sshd-session process.
- looking up user information????????
- i think you can calculate cryptographic signatures without root????
- the fuck do you mean """"checking passwords"""""
i have been informed that even looking up the list of users requires root and have concluded that the unix user model is well-designed to suit the bell labs HR system from the 1970s and was never a serious general permissions model
https://github.com/openssh/openssh-portable/blob/master/LICENCE
i have never seen a stranger license file in my entire life. they also spell the filename in a way i have never seen before
Some code is licensed under a MIT-style license to the following
copyright holders:Free Software Foundation, Inc.
that's not even legally binding and obviously intended as an insult. they also mixed spaces and tabs in indentation???
https://github.com/openssh/openssh-portable/commit/7294baaf6ab389fd206899d68a1ad400ba2f4508
- (djm) Forgot to cvs add LICENSE file
first of all, what a remarkably specific commit description. second of all, that's not worth a ChangeLog entry. third, it's not named LICENSE?
i didn't peruse the whole contents of the LICENCE file because the file being 300 pages long and under a nonstandard filename without symlinks tells me that this is an incredibly politically motivated project. i wonder if that means they're left-wing!
it takes a certain kind of person to use "portable" while using fucking autoconf and then stuffing the LICENCE file with actively contradictory statements
oh and there is a single very clear and absolutely legally actionable statement at the beginning of the LICENSE
Any derived versions of this
* software must be clearly marked as such, and if the derived work is
* incompatible with the protocol description in the RFC file, it must be
* called by a name other than "ssh" or "Secure Shell".
"Any derived versions of this software must be clearly marked as such" is completely incompatible with publishing it via git, but i think that's intentional and it just serves to sound vaguely legal so the line after it sounds legally actionable
that is fucking bizarre. it's also incredibly strange to assign copyright to a single person in the first place. who the fuck is tatu ylonen
https://fi.wikipedia.org/wiki/Tatu_Yl%C3%B6nen english wikipedia has no page on him but i believe finnish wikipedia says he invented ssh. however his own website https://ylonen.org/ then clarifies he wrote "the original ssh" but not openssh which should be sufficient evidence to void his copyright claim over any of the code at all
so the actual ssh guy absolutely does incorporate gnu code (i literally bet it was readline) and then this openssh "portable" fork uses his name to scare people while systematically replacing every single gpl dependency. i wonder if they were motivated by the common good!
I'M SO CONFUSEDDDDDD https://github.com/tatuylonen/tokentree/blob/master/tokentree/ctokentree.pyx
- this would literally be easier to read and fewer lines of code to do in C than in the OG slop python c compiler?????
- the entirety of
_add_{with,no}_extra()is repeated??????
# Increment the count of all nodes (doing this here in between
# seems to improve performance by about 5% - probably due to
# memory latencies)
who is this for. who are you doing this for dude
looked up the OG slop python c compiler to see if it would summarize its theory of operation in the README https://github.com/cython/cython it absolutely does not but it does the exact same fucking thing with the obsequious false deference to the "original author" of a completely separate work
python has one of the nicest build systems and tooling for c extensions i have ever used for any FFI and unlike the python language itself the C ABI has extremely well-defined stability guarantees. furthermore this is one of the many tasks that c is good at and python itself makes inordinately annoying.
his website points to https://www.ssh.com/academy/ssh under the title "original ssh", the one he says he wrote, and then that page says he's on twitter and links to https://x.com/tjssh, which has absolutely zero posts but follows more people than i did when i was on there.
so, this guy clearly doesn't exist, or perhaps he died. let's take a look at his rfc history (????)
i notice he literally has all the standard NSA track publications in database design https://ylonen.org/ but then he describes something called "shadow paging" which seems ridiculously similar to my architecture for i/o scheduling
the last time this happened was when i read about alexia massalin's synthesis kernel who also disappeared suddenly around the year 1995 after developing a more efficient chip fabrication technique
unfortunately for my preconceived notions this 2015 NIST document on ssh security is remarkably well-done https://nvlpubs.nist.gov/nistpubs/ir/2015/nist.ir.7966.pdf this paragraph is a fucking banger
Generally it has been found that the cost of manual labor in a key management project is often as big or
even significantly bigger than the cost of the tools for managing the keys. The choice of tools has a major
impact on the amount of manual labor needed.
@hipsterelectron changing user to the target user after login requires root