From nobody Mon Sep 07 04:20:39 2026 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hdYlX0GDHz6rMPt for ; Mon, 07 Sep 2026 04:20:40 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hdYlW4JlCz3SCt for ; Mon, 07 Sep 2026 04:20:39 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788754839; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=B5wDJ4msqzWCuQrMgnFFfyqa85SeezCJYX7tEXbC4xw=; b=uIUhuStMSjIE8uuh5Xl6a4UpfbE9famH5S/fK+9kf6XEcdJsK0KT7uhRoFAmlzum8Gjek+ XQLeJ1bPrlA5fdOKA4wtBJSWdRAPy5MvWFXZThyAYs7PdhRy5CjWTTt2kCzhjiBczRRlDn dM1jrZLkGTsNuDjSsiFR5o6IR+P1YWCP/8XOohQgZFkVt45CmfHpsBYwNvSaAbwVgi7Fd+ +ePv98yYr9lo+5D4G4OEsnVrMZX7p6yJO3x14eCu/WSVWKd/TbonhTNMu+/BNy91WRh9nz g6LSCHSKf2sLlB3n11FBwlAyc+nHOoqrJVOxwWxo/mfjeLJX/6RdepHbivrEuA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1788754839; a=rsa-sha256; cv=none; b=HSLz0A4ysJKD69tZHviCgcjfGU8Gw5le0IlWN5n336/8her3oEd2kUVca1zrL2FbeAX4QT aa/KOEqHBZMwYFy6Ox2KRSSk2yCnzRQsQJ2Jxz2I+Mz6H/OxxkC21LugN+gl2kgEQe+sDi BFR+sKDGdLWHK3fRXxGbOZRH413DWjE1L1ShJLNz0VimepkwFFoAlbmqnv/rOS7Tg5grKN gWKoSiw8nv3O3vEaeYuJym6h3ARoJJsuowYYCblSKFkK87sCRmNBN8Q/ZG7GhGuE2AXLHC 0M0wWC5TULIccxT5ketfp8Kd67dS5zKYPzroNJI20XD+qtMcCxDaViLcmFAcog== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788754839; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=B5wDJ4msqzWCuQrMgnFFfyqa85SeezCJYX7tEXbC4xw=; b=XuJavXS0gwgu+DxsSiK4xq/ekZjrmmx1fbS0HOOzUe1Z3PMyDo6t4z9Bpy6brU584eE9sx VVwkO/4L2aV+AYKlrAGvIoy9u5LVYA/SW9sX7fn4Tggh2NX5HYfyKCb7OqKAOWgn5DibF8 eZaykrPS/e6zFvP18SaKy/YNaInFCKDc9X04qDMwailsVPFaPVS6YnsPHAKBVercHIghUn sNRQeNF1PJp/DQ+fHjhuf2MIKIpFov912W8ozj9xhnvyCgS9FcSRcoBw1rWLYyw9w4IM6f eqYU3H8DtuH/GdFViT9GHlIIIIxKUD20yn5o9b07bpdoLXcoKXY9/feHEcMD/Q== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hdYlW2DCwz12gL for ; Mon, 07 Sep 2026 04:20:39 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 1cc7c by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Mon, 07 Sep 2026 04:20:39 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Baptiste Daroussin Subject: git: 540f9ca5599f - stable/15 - nuageinit: fix ssh_pwauth string handling List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: bapt X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: 540f9ca5599f880204eccd8ea2ef3854f98dddc8 Auto-Submitted: auto-generated Date: Mon, 07 Sep 2026 04:20:39 +0000 Message-Id: <6a9e3b97.1cc7c.75863b46@gitrepo.freebsd.org> The branch stable/15 has been updated by bapt: URL: https://cgit.FreeBSD.org/src/commit/?id=540f9ca5599f880204eccd8ea2ef3854f98dddc8 commit 540f9ca5599f880204eccd8ea2ef3854f98dddc8 Author: Baptiste Daroussin AuthorDate: 2026-08-11 09:07:37 +0000 Commit: Baptiste Daroussin CommitDate: 2026-09-07 04:19:01 +0000 nuageinit: fix ssh_pwauth string handling Treat "no"/"unchanged" correctly instead of any non-nil value as yes. (cherry picked from commit 8d4d5f2e8e56e7b24b50706acbdc0c8c750c6fed) --- libexec/nuageinit/nuageinit | 22 +++++++++++++++++++--- libexec/nuageinit/tests/nuageinit.sh | 18 ++++++++++++++++++ 2 files changed, 37 insertions(+), 3 deletions(-) diff --git a/libexec/nuageinit/nuageinit b/libexec/nuageinit/nuageinit index d67ac6ce4229..536739c8a0bf 100755 --- a/libexec/nuageinit/nuageinit +++ b/libexec/nuageinit/nuageinit @@ -478,9 +478,25 @@ end local function ssh_pwauth(obj) if obj.ssh_pwauth == nil then return end - local value = "no" - if obj.ssh_pwauth then - value = "yes" + local value + if type(obj.ssh_pwauth) == "boolean" then + value = obj.ssh_pwauth and "yes" or "no" + elseif type(obj.ssh_pwauth) == "string" then + local s = obj.ssh_pwauth:lower() + if s == "yes" or s == "true" or s == "1" or s == "on" then + value = "yes" + elseif s == "no" or s == "false" or s == "0" or s == "off" then + value = "no" + elseif s == "unchanged" then + return + else + nuage.warn("ssh_pwauth: unrecognized value '" .. + obj.ssh_pwauth .. "', leaving unchanged") + return + end + else + nuage.warn("ssh_pwauth: invalid type " .. type(obj.ssh_pwauth)) + return end nuage.update_sshd_config("PasswordAuthentication", value) end diff --git a/libexec/nuageinit/tests/nuageinit.sh b/libexec/nuageinit/tests/nuageinit.sh index 1fb5f7b4c967..a4b0def48a86 100644 --- a/libexec/nuageinit/tests/nuageinit.sh +++ b/libexec/nuageinit/tests/nuageinit.sh @@ -632,6 +632,24 @@ EOF printf " PasswordAuthentication yes # Should change\n" > etc/ssh/sshd_config atf_check -o empty -e empty /usr/libexec/nuageinit "${PWD}"/media/nuageinit nocloud atf_check -o inline:"PasswordAuthentication no\n" cat etc/ssh/sshd_config + + cat > media/nuageinit/user-data << 'EOF' +#cloud-config +ssh_pwauth: "no" +EOF + + printf " PasswordAuthentication yes # Should change\n" > etc/ssh/sshd_config + atf_check -o empty -e empty /usr/libexec/nuageinit "${PWD}"/media/nuageinit nocloud + atf_check -o inline:"PasswordAuthentication no\n" cat etc/ssh/sshd_config + + cat > media/nuageinit/user-data << 'EOF' +#cloud-config +ssh_pwauth: "unchanged" +EOF + + printf " PasswordAuthentication yes # keep\n" > etc/ssh/sshd_config + atf_check -o empty -e empty /usr/libexec/nuageinit "${PWD}"/media/nuageinit nocloud + atf_check -o inline:" PasswordAuthentication yes # keep\n" cat etc/ssh/sshd_config } nocloud_userdata_cloudconfig_chpasswd_head()