git: d79050a0916b - main - security/opkssh: Update to 0.16.0

From: Jesús Daniel Colmenares Oviedo <dtxdf_at_FreeBSD.org>
Date: Sat, 26 Sep 2026 06:24:04 UTC
The branch main has been updated by dtxdf:

URL: https://cgit.FreeBSD.org/ports/commit/?id=d79050a0916bfadfb592003b39f5fde46ecb8757

commit d79050a0916bfadfb592003b39f5fde46ecb8757
Author:     Jesús Daniel Colmenares Oviedo <dtxdf@FreeBSD.org>
AuthorDate: 2026-09-26 00:04:07 +0000
Commit:     Jesús Daniel Colmenares Oviedo <dtxdf@FreeBSD.org>
CommitDate: 2026-09-26 06:23:10 +0000

    security/opkssh: Update to 0.16.0
    
    ChangeLogs:
    
    - https://github.com/openpubkey/opkssh/releases/tag/v0.11.0
    - https://github.com/openpubkey/opkssh/releases/tag/v0.12.0
    - https://github.com/openpubkey/opkssh/releases/tag/v0.13.0
    - https://github.com/openpubkey/opkssh/releases/tag/v0.14.0
    - https://github.com/openpubkey/opkssh/releases/tag/v0.15.0
    - https://github.com/openpubkey/opkssh/releases/tag/v0.16.0
---
 security/opkssh/Makefile                           |  7 +--
 security/opkssh/distinfo                           | 10 +--
 security/opkssh/files/patch-main.go                | 72 ++--------------------
 security/opkssh/files/patch-policy_enforcer.go     | 16 ++---
 .../files/patch-policy_files_perminfo__unix.go     | 26 ++++++++
 .../patch-policy_files_permschecker__common.go     | 11 ++++
 security/opkssh/files/patch-policy_paths__unix.go  | 12 ++++
 security/opkssh/files/patch-policy_policyloader.go | 14 ++---
 security/opkssh/files/patch-policy_validator.go    | 20 ++++++
 ...om_shirou_gopsutil_v4_internal_common_common.go | 20 ++++++
 ...ch-vendor_github.com_spf13_cobra_completions.go | 16 +++++
 11 files changed, 134 insertions(+), 90 deletions(-)

diff --git a/security/opkssh/Makefile b/security/opkssh/Makefile
index 7cdee7f34c41..6251fc057753 100644
--- a/security/opkssh/Makefile
+++ b/security/opkssh/Makefile
@@ -1,12 +1,11 @@
 PORTNAME=	opkssh
 DISTVERSIONPREFIX=	v
-DISTVERSION=	0.10.0
-PORTREVISION=	11
+DISTVERSION=	0.16.0
 CATEGORIES=	security
-MASTER_SITES=	LOCAL/dtxdf/${PORTNAME}/
+MASTER_SITES=	LOCAL/dtxdf/${PORTNAME}/:assets
 # For instructions on how to create assets:
 #   https://github.com/DtxdF/port-assets-makejails/tree/main/opkssh
-DISTFILES=	${PORTNAME}-${DISTVERSIONPREFIX}${DISTVERSION}.vendor${EXTRACT_SUFX}
+DISTFILES=	${PORTNAME}-${DISTVERSIONPREFIX}${DISTVERSION}.vendor${EXTRACT_SUFX}:assets
 
 MAINTAINER=	dtxdf@FreeBSD.org
 COMMENT=	Tool which enables SSH to be used with OpenID Connect
diff --git a/security/opkssh/distinfo b/security/opkssh/distinfo
index 1569d7666eb9..538568c5686e 100644
--- a/security/opkssh/distinfo
+++ b/security/opkssh/distinfo
@@ -1,5 +1,5 @@
-TIMESTAMP = 1763233259
-SHA256 (opkssh-v0.10.0.vendor.tar.gz) = 038566589aa4db1bd890b20e074d0b9b995a2b766b30c72f97b35dd2afa4168e
-SIZE (opkssh-v0.10.0.vendor.tar.gz) = 5490704
-SHA256 (openpubkey-opkssh-v0.10.0_GH0.tar.gz) = 71796c060705411e98fc7d11d944c531cea1d09df14cc1331c5647a31483de41
-SIZE (openpubkey-opkssh-v0.10.0_GH0.tar.gz) = 573801
+TIMESTAMP = 1790228499
+SHA256 (opkssh-v0.16.0.vendor.tar.gz) = 41e85586b2d029df6c1fcf36a4dbd1543c7e2263c232df260547994cd77de848
+SIZE (opkssh-v0.16.0.vendor.tar.gz) = 5442961
+SHA256 (openpubkey-opkssh-v0.16.0_GH0.tar.gz) = b7c326b24d6fe97056d459f2d5ef7eafb25890b70279537746a368467fe2dc3b
+SIZE (openpubkey-opkssh-v0.16.0_GH0.tar.gz) = 3129764
diff --git a/security/opkssh/files/patch-main.go b/security/opkssh/files/patch-main.go
index 9f8d47b12023..0d18f1ec40b6 100644
--- a/security/opkssh/files/patch-main.go
+++ b/security/opkssh/files/patch-main.go
@@ -1,6 +1,6 @@
---- main.go.orig	2025-09-11 18:38:37 UTC
+--- main.go.orig	2026-09-25 23:46:47 UTC
 +++ main.go
-@@ -80,7 +80,7 @@ This program allows users to:
+@@ -81,7 +81,7 @@ This program allows users to:
  		Short:        "Appends new rule to the policy file",
  		Long: `Add appends a new policy entry in the auth_id policy file granting SSH access to the specified email or subscriber ID (sub) or group.
  
@@ -8,17 +8,17 @@
 +It first attempts to write to the system-wide file (%%PREFIX%%/etc/opk/auth_id). If it lacks permissions to update this file it falls back to writing to the user-specific file (~/.opk/auth_id).
  
  Arguments:
-   PRINCIPAL            The target user account (requested principal).
-@@ -217,7 +217,7 @@ You should not call this command directly. It is calle
+   principal            The target user account (requested principal).
+@@ -283,7 +283,7 @@ You should not call this command directly. It is calle
  		SilenceUsage: true,
- 		Use:          "verify <PRINCIPAL> <CERT> <KEY_TYPE>",
+ 		Use:          "verify <principal> <cert> <key_type>",
  		Short:        "Verify an SSH key (used by sshd AuthorizedKeysCommand)",
 -		Long: `Verify extracts a PK token from a base64-encoded SSH certificate and verifies it against policy. It expects an allowed provider file at /etc/opk/providers and a user policy file at either /etc/opk/auth_id or ~/.opk/auth_id.
 +		Long: `Verify extracts a PK token from a base64-encoded SSH certificate and verifies it against policy. It expects an allowed provider file at %%PREFIX%%/etc/opk/providers and a user policy file at either %%PREFIX%%/etc/opk/auth_id or ~/.opk/auth_id.
  
  This command is intended to be called by sshd as an AuthorizedKeysCommand:
    https://man.openbsd.org/sshd_config#AuthorizedKeysCommand
-@@ -233,8 +233,8 @@ Verification checks performed:
+@@ -299,8 +299,8 @@ Verification checks performed:
  
  Verification checks performed:
    1. Ensures the PK token is properly formed, signed, and issued by the specified OpenID Provider (OP).
@@ -29,63 +29,3 @@
  
  If all checks pass, Verify authorizes the SSH connection.
  
-@@ -269,10 +269,10 @@ Arguments:
- 			certB64Arg := args[1]
- 			typArg := args[2]
- 
--			providerPolicyPath := "/etc/opk/providers"
-+			providerPolicyPath := "%%PREFIX%%/etc/opk/providers"
- 			providerPolicy, err := policy.NewProviderFileLoader().LoadProviderPolicy(providerPolicyPath)
- 			if err != nil {
--				log.Println("Failed to open /etc/opk/providers:", err)
-+				log.Println("Failed to open %%PREFIX%%/etc/opk/providers:", err)
- 				return err
- 			}
- 
-@@ -301,7 +301,7 @@ Arguments:
- 			}
- 		},
- 	}
--	verifyCmd.Flags().StringVar(&serverConfigPathArg, "config-path", "/etc/opk/config.yml", "Path to the server config file. Default: /etc/opk/config.yml.")
-+	verifyCmd.Flags().StringVar(&serverConfigPathArg, "config-path", "%%PREFIX%%/etc/opk/config.yml", "Path to the server config file. Default: %%PREFIX%%/etc/opk/config.yml.")
- 	rootCmd.AddCommand(verifyCmd)
- 
- 	clientCmd := &cobra.Command{
-@@ -504,30 +504,30 @@ func detectOS() OSType {
- // detectOS determines the type of operating system.
- func detectOS() OSType {
- 	// Check for RedHat-based systems
--	if _, err := os.Stat("/etc/redhat-release"); err == nil {
-+	if _, err := os.Stat("%%PREFIX%%/etc/redhat-release"); err == nil {
- 		return OSTypeRHEL
- 	}
- 
- 	// Check for Debian-based systems
--	if _, err := os.Stat("/etc/debian_version"); err == nil {
-+	if _, err := os.Stat("%%PREFIX%%/etc/debian_version"); err == nil {
- 		return OSTypeDebian
- 	}
- 
- 	// Check for Arch Linux
--	if _, err := os.Stat("/etc/arch-release"); err == nil {
-+	if _, err := os.Stat("%%PREFIX%%/etc/arch-release"); err == nil {
- 		return OSTypeArch
- 	}
- 
- 	// Check for SUSE Linux
--	if _, err := os.Stat("/etc/SuSE-release"); err == nil {
-+	if _, err := os.Stat("%%PREFIX%%/etc/SuSE-release"); err == nil {
- 		return OSTypeSUSE
- 	}
--	if _, err := os.Stat("/etc/SUSE-brand"); err == nil {
-+	if _, err := os.Stat("%%PREFIX%%/etc/SUSE-brand"); err == nil {
- 		return OSTypeSUSE
- 	}
- 
--	// Check for /etc/os-release which exists on most modern Linux systems
--	if content, err := os.ReadFile("/etc/os-release"); err == nil {
-+	// Check for %%PREFIX%%/etc/os-release which exists on most modern Linux systems
-+	if content, err := os.ReadFile("%%PREFIX%%/etc/os-release"); err == nil {
- 		contentStr := string(content)
- 		if strings.Contains(contentStr, "ID=rhel") ||
- 			strings.Contains(contentStr, "ID=centos") ||
diff --git a/security/opkssh/files/patch-policy_enforcer.go b/security/opkssh/files/patch-policy_enforcer.go
index 0330f82a4251..87722f676f49 100644
--- a/security/opkssh/files/patch-policy_enforcer.go
+++ b/security/opkssh/files/patch-policy_enforcer.go
@@ -1,11 +1,11 @@
---- policy/enforcer.go.orig	2025-11-15 20:20:44 UTC
+--- policy/enforcer.go.orig	2026-09-25 23:41:01 UTC
 +++ policy/enforcer.go
-@@ -54,7 +54,7 @@ type checkedClaims struct {
+@@ -106,7 +106,7 @@ func (s *checkedClaims) UnmarshalJSON(data []byte) err
  }
  
- // The default location for policy plugins
--const pluginPolicyDir = "/etc/opk/policy.d"
-+const pluginPolicyDir = "%%PREFIX%%/etc/opk/policy.d"
- 
- // Validates that the server defined identity attribute matches the
- // respective claim from the identity token
+ // GetPluginPolicyDir returns the default location for policy plugins.
+-// On Unix: /etc/opk/policy.d, On Windows: %ProgramData%\opk\policy.d
++// On Unix: %%PREFIX%%/etc/opk/policy.d, On Windows: %ProgramData%\opk\policy.d
+ func GetPluginPolicyDir() string {
+ 	return filepath.Join(GetSystemConfigBasePath(), "policy.d")
+ }
diff --git a/security/opkssh/files/patch-policy_files_perminfo__unix.go b/security/opkssh/files/patch-policy_files_perminfo__unix.go
new file mode 100644
index 000000000000..af3333954963
--- /dev/null
+++ b/security/opkssh/files/patch-policy_files_perminfo__unix.go
@@ -0,0 +1,26 @@
+--- policy/files/perminfo_unix.go.orig	2026-09-25 23:41:01 UTC
++++ policy/files/perminfo_unix.go
+@@ -23,19 +23,19 @@ var RequiredPerms = struct {
+ // on Unix/Linux systems.
+ var RequiredPerms = struct {
+ 	// SystemPolicy is the system-wide policy file
+-	// (e.g. /etc/opk/auth_id).
++	// (e.g. %%PREFIX%%/etc/opk/auth_id).
+ 	SystemPolicy PermInfo
+ 	// HomePolicy is the per-user policy file
+ 	// (e.g. ~/.opk/auth_id).
+ 	HomePolicy PermInfo
+ 	// Providers is the provider configuration file
+-	// (e.g. /etc/opk/providers).
++	// (e.g. %%PREFIX%%/etc/opk/providers).
+ 	Providers PermInfo
+ 	// Config is the server configuration file
+-	// (e.g. /etc/opk/config.yml).
++	// (e.g. %%PREFIX%%/etc/opk/config.yml).
+ 	Config PermInfo
+ 	// PluginsDir is the directory containing policy plugin definitions
+-	// (e.g. /etc/opk/policy.d).
++	// (e.g. %%PREFIX%%/etc/opk/policy.d).
+ 	PluginsDir PermInfo
+ 	// PluginFile is an individual plugin YAML file inside the plugins
+ 	// directory.
diff --git a/security/opkssh/files/patch-policy_files_permschecker__common.go b/security/opkssh/files/patch-policy_files_permschecker__common.go
new file mode 100644
index 000000000000..21caaac1a511
--- /dev/null
+++ b/security/opkssh/files/patch-policy_files_permschecker__common.go
@@ -0,0 +1,11 @@
+--- policy/files/permschecker_common.go.orig	2026-09-25 23:41:01 UTC
++++ policy/files/permschecker_common.go
+@@ -24,7 +24,7 @@ import (
+ )
+ 
+ // ModeSystemPerms is the expected permission bits that should be set for opkssh
+-// system policy files (on Unix: /etc/opk/auth_id, /etc/opk/providers; on Windows: %ProgramData%\opk\auth_id, %ProgramData%\opk\providers).
++// system policy files (on Unix: %%PREFIX%%/etc/opk/auth_id, %%PREFIX%%/etc/opk/providers; on Windows: %ProgramData%\opk\auth_id, %ProgramData%\opk\providers).
+ // This mode means that only the owner of the file can write/read to the file, but the group which
+ // should be opksshuser can read the file.
+ const ModeSystemPerms = fs.FileMode(0o640)
diff --git a/security/opkssh/files/patch-policy_paths__unix.go b/security/opkssh/files/patch-policy_paths__unix.go
new file mode 100644
index 000000000000..97103543ec5f
--- /dev/null
+++ b/security/opkssh/files/patch-policy_paths__unix.go
@@ -0,0 +1,12 @@
+--- policy/paths_unix.go.orig	2026-09-25 23:41:01 UTC
++++ policy/paths_unix.go
+@@ -20,7 +20,7 @@ package policy
+ package policy
+ 
+ // GetSystemConfigBasePath returns the base path for system opkssh configuration.
+-// On Unix-like systems, this is /etc/opk
++// On Unix-like systems, this is %%PREFIX%%/etc/opk
+ func GetSystemConfigBasePath() string {
+-	return "/etc/opk"
++	return "%%PREFIX%%/etc/opk"
+ }
diff --git a/security/opkssh/files/patch-policy_policyloader.go b/security/opkssh/files/patch-policy_policyloader.go
index e32d18134c99..c3aa94ac5987 100644
--- a/security/opkssh/files/patch-policy_policyloader.go
+++ b/security/opkssh/files/patch-policy_policyloader.go
@@ -1,11 +1,11 @@
---- policy/policyloader.go.orig	2025-11-15 20:20:44 UTC
+--- policy/policyloader.go.orig	2026-09-25 23:41:01 UTC
 +++ policy/policyloader.go
-@@ -29,7 +29,7 @@ import (
+@@ -27,7 +27,7 @@ import (
+ )
  
  // SystemDefaultPolicyPath is the default filepath where opkssh policy is
- // defined
--var SystemDefaultPolicyPath = filepath.FromSlash("/etc/opk/auth_id")
-+var SystemDefaultPolicyPath = filepath.FromSlash("%%PREFIX%%/etc/opk/auth_id")
+-// defined. On Unix: /etc/opk/auth_id, On Windows: %ProgramData%\opk\auth_id
++// defined. On Unix: %%PREFIX%%/etc/opk/auth_id, On Windows: %ProgramData%\opk\auth_id
+ var SystemDefaultPolicyPath = filepath.Join(GetSystemConfigBasePath(), "auth_id")
  
- // UserLookup defines the minimal interface to lookup users on the current
- // system
+ // SystemDefaultProvidersPath is the default filepath where opkssh provider
diff --git a/security/opkssh/files/patch-policy_validator.go b/security/opkssh/files/patch-policy_validator.go
new file mode 100644
index 000000000000..a861b2800c4d
--- /dev/null
+++ b/security/opkssh/files/patch-policy_validator.go
@@ -0,0 +1,20 @@
+--- policy/validator.go.orig	2026-09-25 23:41:01 UTC
++++ policy/validator.go
+@@ -79,7 +79,7 @@ func (v *PolicyValidator) ValidateEntry(principal, ide
+ 	_, exists := v.issuerMap[issuer]
+ 	if !exists {
+ 		result.Status = StatusError
+-		result.Reason = "issuer not found in /etc/opk/providers"
++		result.Reason = "issuer not found in %%PREFIX%%/etc/opk/providers"
+ 
+ 		// issuer in policy file has a trailing slash, but issuer in provider file does not have a trailing slash
+ 		if strings.HasSuffix(issuer, "/") {
+@@ -110,7 +110,7 @@ func (v *PolicyValidator) ValidateEntry(principal, ide
+ 		}
+ 
+ 		result.Hints = append(result.Hints,
+-			fmt.Sprintf("Ensure the issuer URL (%s) is correct and matches an entry in /etc/opk/providers", issuer))
++			fmt.Sprintf("Ensure the issuer URL (%s) is correct and matches an entry in %%PREFIX%%/etc/opk/providers", issuer))
+ 		return result
+ 	}
+ 
diff --git a/security/opkssh/files/patch-vendor_github.com_shirou_gopsutil_v4_internal_common_common.go b/security/opkssh/files/patch-vendor_github.com_shirou_gopsutil_v4_internal_common_common.go
new file mode 100644
index 000000000000..d3c855ea5743
--- /dev/null
+++ b/security/opkssh/files/patch-vendor_github.com_shirou_gopsutil_v4_internal_common_common.go
@@ -0,0 +1,20 @@
+--- vendor/github.com/shirou/gopsutil/v4/internal/common/common.go.orig	2026-09-25 23:41:01 UTC
++++ vendor/github.com/shirou/gopsutil/v4/internal/common/common.go
+@@ -397,7 +397,7 @@ func HostEtc(combineWith ...string) string {
+ }
+ 
+ func HostEtc(combineWith ...string) string {
+-	return GetEnv("HOST_ETC", "/etc", combineWith...)
++	return GetEnv("HOST_ETC", "%%PREFIX%%/etc", combineWith...)
+ }
+ 
+ func HostVar(combineWith ...string) string {
+@@ -429,7 +429,7 @@ func HostEtcWithContext(ctx context.Context, combineWi
+ }
+ 
+ func HostEtcWithContext(ctx context.Context, combineWith ...string) string {
+-	return GetEnvWithContext(ctx, "HOST_ETC", "/etc", combineWith...)
++	return GetEnvWithContext(ctx, "HOST_ETC", "%%PREFIX%%/etc", combineWith...)
+ }
+ 
+ func HostVarWithContext(ctx context.Context, combineWith ...string) string {
diff --git a/security/opkssh/files/patch-vendor_github.com_spf13_cobra_completions.go b/security/opkssh/files/patch-vendor_github.com_spf13_cobra_completions.go
new file mode 100644
index 000000000000..e8150cfe7ca9
--- /dev/null
+++ b/security/opkssh/files/patch-vendor_github.com_spf13_cobra_completions.go
@@ -0,0 +1,16 @@
+--- vendor/github.com/spf13/cobra/completions.go.orig	2026-09-25 23:41:01 UTC
++++ vendor/github.com/spf13/cobra/completions.go
+@@ -799,11 +799,11 @@ To load completions for every new session, execute onc
+ 
+ #### Linux:
+ 
+-	%[1]s completion bash > /etc/bash_completion.d/%[1]s
++	%[1]s completion bash > %%PREFIX%%/etc/bash_completion.d/%[1]s
+ 
+ #### macOS:
+ 
+-	%[1]s completion bash > $(brew --prefix)/etc/bash_completion.d/%[1]s
++	%[1]s completion bash > $(brew --prefix)%%PREFIX%%/etc/bash_completion.d/%[1]s
+ 
+ You will need to start a new shell for this setup to take effect.
+ `, c.Root().Name()),