From nobody Wed Jan 29 18:55:25 2025 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4YjrvL4fZgz5lmty; Wed, 29 Jan 2025 18:55:26 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R11" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4YjrvK67hVz3CYD; Wed, 29 Jan 2025 18:55:25 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1738176926; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=tHQnDegg7e1mpf+8Wpg5NpbrIfkDdEQsVvroVzz8UJs=; b=dtTBSC3mykFTzG38r9PQb9By4S4v8J0V/SFAj8uBNh4GTWHU09rVTRION7TzT+ireFvdAT 9ibu0uxExrqsaoVVO8W4DbgWe8vPZdJE9i8mzSc7we2lDvD20AHrdG5pPOSoNnV7PPHMx6 rT8X7cy0ucJRt60fl4MBgSD2MNEc3MtEEGzih23doC5yjdBEhS1iRD+6nDZIm3nqgQ/g6r riueblIQDdBDO97lJkNnDArwV/i2rytkTu9lcjyAQWugR5coCPOH7NYi9k8dApyiaVNnbV ln0ZG4rixL+hdeTkby8hOQdCOou1TCwOHJ0BRZUURVP5IvzU/huWqc6DJLZw1Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1738176925; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=tHQnDegg7e1mpf+8Wpg5NpbrIfkDdEQsVvroVzz8UJs=; b=ON4gWFhDc+rrXFnYIvQX+V9ybAZV5dVrdLvr8pPZ/jb0vWRbH1ZogM4fHk1doHZZitfTtH 55icuyAn6CqEKIM0Bphoqjny/IWrx/f9XROPRbcqaLksR8qAE7S1MSruhmGI+d8PJUZYwp slTy+Fwaux2OndnMRrwrISqC7rltosnd4wgU+DtD5Q3LTWBrNGNNB7S6u/+HTeIFydsBEE ++Rx5U60EZuqQyo0sbOnoNcXbl9C2IWRPF1iWRZDmVvGDRHfySx8PqpqUcdjcCejrCCf4Y tZycPeMUUI6BTY0lhfIdl6xYS3fhceMvhpo86wIkYHu8XFLJ3TaEE1ktV8uTeA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1738176925; a=rsa-sha256; cv=none; b=Sho3ev6z/npBcqtSRvsphDBW0L7hREdalNzLInviYJVxHnPAfcv8cxTaXbbtp78/g3NedB u72cRH7qba5F1z+CPJzUHhZIX7Gscj4WRDm4vF1+r90FnKiMRiHgJVz1yC2neSm0rpdaKm RymzlDY/jTRfFsDfonwXPZCq3/E4mHZBp7WHNC5og2DL6snAOMsVOgj1rUII8WCOBAfFxq YJDf+CRCFHY5V6fNipV5LHb7rPUY2Pfk60TRESN4k73WkIre+EsjdvS35aMtoXKPYrohGO vv5+bRMJK6gYeyNkMfxc5roa3qFD3HHWP3Hlo/bIw3opeMRUzYY3fKtSUFFChQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4YjrvK4vNYz1Cl7; Wed, 29 Jan 2025 18:55:25 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 50TItPxe064836; Wed, 29 Jan 2025 18:55:25 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 50TItPw0064833; Wed, 29 Jan 2025 18:55:25 GMT (envelope-from git) Date: Wed, 29 Jan 2025 18:55:25 GMT Message-Id: <202501291855.50TItPw0064833@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Mark Johnston Subject: git: 88d5d8108711 - releng/14.1 - OpenSSH: correct logic error in ObscureKeystrokeTiming List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/releng/14.1 X-Git-Reftype: branch X-Git-Commit: 88d5d81087113112fcafff109b14ae21d7e3a687 Auto-Submitted: auto-generated The branch releng/14.1 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=88d5d81087113112fcafff109b14ae21d7e3a687 commit 88d5d81087113112fcafff109b14ae21d7e3a687 Author: Ed Maste AuthorDate: 2024-07-01 13:14:15 +0000 Commit: Mark Johnston CommitDate: 2025-01-29 17:13:08 +0000 OpenSSH: correct logic error in ObscureKeystrokeTiming Cherry-pick fix: upstream: when sending ObscureKeystrokeTiming chaff packets, we can't rely on channel_did_enqueue to tell that there is data to send. This flag indicates that the channels code enqueued a packet on _this_ ppoll() iteration, not that data was enqueued in _any_ ppoll() iteration in the timeslice. ok markus@ OpenBSD-Commit-ID: 009b74fd2769b36b5284a0188ade182f00564136 Approved by: so Security: FreeBSD-SA-25:01.openssh Obtained from: openssh-portable 146c420d29d0 Reviewed by: gordon Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D45823 (cherry picked from commit b81424adf7181d816c10b1345aaa3305ab0ec304) (cherry picked from commit bf9a275b24f6655616cc691555fe1a36ed5e4338) --- crypto/openssh/clientloop.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/crypto/openssh/clientloop.c b/crypto/openssh/clientloop.c index 8ec36af94b3f..6dcd6c8535aa 100644 --- a/crypto/openssh/clientloop.c +++ b/crypto/openssh/clientloop.c @@ -608,8 +608,9 @@ obfuscate_keystroke_timing(struct ssh *ssh, struct timespec *timeout, if (timespeccmp(&now, &chaff_until, >=)) { /* Stop if there have been no keystrokes for a while */ stop_reason = "chaff time expired"; - } else if (timespeccmp(&now, &next_interval, >=)) { - /* Otherwise if we were due to send, then send chaff */ + } else if (timespeccmp(&now, &next_interval, >=) && + !ssh_packet_have_data_to_write(ssh)) { + /* If due to send but have no data, then send chaff */ if (send_chaff(ssh)) nchaff++; }