upstream commit

add a sIgnore opcode that silently ignores options and
use it to suppress noisy deprecation warnings for the Protocol directive.

req henning, ok markus

Upstream-ID: 9fe040aca3d6ff393f6f7e60045cdd821dc4cbe0
This commit is contained in:
djm@openbsd.org 2016-08-25 23:57:54 +00:00 committed by Damien Miller
parent a94c603066
commit ae363d74cc

View File

@ -1,5 +1,5 @@
/* $OpenBSD: servconf.c,v 1.294 2016/08/19 03:18:06 djm Exp $ */ /* $OpenBSD: servconf.c,v 1.295 2016/08/25 23:57:54 djm Exp $ */
/* /*
* Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
* All rights reserved * All rights reserved
@ -415,7 +415,7 @@ typedef enum {
sAuthenticationMethods, sHostKeyAgent, sPermitUserRC, sAuthenticationMethods, sHostKeyAgent, sPermitUserRC,
sStreamLocalBindMask, sStreamLocalBindUnlink, sStreamLocalBindMask, sStreamLocalBindUnlink,
sAllowStreamLocalForwarding, sFingerprintHash, sAllowStreamLocalForwarding, sFingerprintHash,
sDeprecated, sUnsupported sDeprecated, sIgnore, sUnsupported
} ServerOpCodes; } ServerOpCodes;
#define SSHCFG_GLOBAL 0x01 /* allowed in main section of sshd_config */ #define SSHCFG_GLOBAL 0x01 /* allowed in main section of sshd_config */
@ -518,7 +518,7 @@ static struct {
{ "denygroups", sDenyGroups, SSHCFG_ALL }, { "denygroups", sDenyGroups, SSHCFG_ALL },
{ "ciphers", sCiphers, SSHCFG_GLOBAL }, { "ciphers", sCiphers, SSHCFG_GLOBAL },
{ "macs", sMacs, SSHCFG_GLOBAL }, { "macs", sMacs, SSHCFG_GLOBAL },
{ "protocol", sDeprecated, SSHCFG_GLOBAL }, { "protocol", sIgnore, SSHCFG_GLOBAL },
{ "gatewayports", sGatewayPorts, SSHCFG_ALL }, { "gatewayports", sGatewayPorts, SSHCFG_ALL },
{ "subsystem", sSubsystem, SSHCFG_GLOBAL }, { "subsystem", sSubsystem, SSHCFG_GLOBAL },
{ "maxstartups", sMaxStartups, SSHCFG_GLOBAL }, { "maxstartups", sMaxStartups, SSHCFG_GLOBAL },
@ -719,7 +719,7 @@ get_connection_info(int populate, int use_dns)
* options set are copied into the main server config. * options set are copied into the main server config.
* *
* Potential additions/improvements: * Potential additions/improvements:
* - Add Match support for pre-kex directives, eg Protocol, Ciphers. * - Add Match support for pre-kex directives, eg. Ciphers.
* *
* - Add a Tag directive (idea from David Leonard) ala pf, eg: * - Add a Tag directive (idea from David Leonard) ala pf, eg:
* Match Address 192.168.0.* * Match Address 192.168.0.*
@ -1824,15 +1824,12 @@ process_server_config_line(ServerOptions *options, char *line,
break; break;
case sDeprecated: case sDeprecated:
logit("%s line %d: Deprecated option %s", case sIgnore:
filename, linenum, arg);
while (arg)
arg = strdelim(&cp);
break;
case sUnsupported: case sUnsupported:
logit("%s line %d: Unsupported option %s", do_log2(opcode == sIgnore ?
filename, linenum, arg); SYSLOG_LEVEL_DEBUG2 : SYSLOG_LEVEL_INFO,
"%s line %d: %s option %s", filename, linenum,
opcode == sUnsupported ? "Unsupported" : "Deprecated", arg);
while (arg) while (arg)
arg = strdelim(&cp); arg = strdelim(&cp);
break; break;