I found a small bug in QoS handling in the OpenSSH client under specific conditions. It had a big impact on my workflow but wasn’t a complete showstopper and might not have had an obvious impact on the broader user base. I raised an issue on the tracker and within a day I had a test build, a confirmed fix and a note of which release would carry the fix. It was one of the most positive experiences I’ve had reporting a bug, especially for a non-security issue.
I know this comment doesn’t add much to the conversation about this release, but I’m very grateful to Damien (who handled the issue) and the team for the wonderful job they’re doing on such a core piece of software.
iw2rmb [3 hidden]5 mins ago
Had the same experience with the OpenRewrite lately.
kuekacang [3 hidden]5 mins ago
Link or didn't hapen
/s
But seriously if feasible, share the issue link. Especially when there's conversation involved, it's different kind of nice (and learning opportunity) reading such thread
tiffanyh [3 hidden]5 mins ago
> I raised an issue on the tracker
I thought OpenBSD / OpenSSH operate without a tracker and it’s all email distro based.
"Updated sandbox for privilege-separated pre-authorization sshd process" is listed as a modification to the open-source project, but I suspect this is out-of-date.
saagarjha [3 hidden]5 mins ago
I’m confused why they can’t just write a sandbox profile that does the equivalent
jmclnx [3 hidden]5 mins ago
Who is "they" ? AFAIK the OpenSSH team focuses on the OpenBSD version and others people/teams use the new releases to create/update a portable version.
So I think it would be up to the team that ports it to Apple, so I think the "Apple Team" is the ones who would worry about sandboxing.
brynet [3 hidden]5 mins ago
OpenSSH -portable is maintained by the OpenSSH developers, who are also OpenBSD developers.
tptacek [3 hidden]5 mins ago
The big ticket thing here seems to be mitigation of "Crossing The Streams", a CRIME-style compression side channel that relies on the fact that different sessions share LZ77 state:
"
* We have seen a number of cases where a security bug identified
* by AI tools is subsequently independently discovered by a
* different researcher. This suggests that adversaries who do not
* report bugs to OSS projects are likely to be able to discover
* these bugs too. Given this, the OpenSSH team will, for now, be
* making more frequent releases to get bugfixes into users' hands
* more quickly rather than batching them until the next planned
* release."
Now I am going to call out IBM. Last I checked, IBM uses OpenSSH on AIX, but gives a big fat 0. Microsoft has been consistent in donating a decent amount. And a surprise to me, Meta showed up donating last year, nice. I wish IBM would join the list too. Based upon:
I know this comment doesn’t add much to the conversation about this release, but I’m very grateful to Damien (who handled the issue) and the team for the wonderful job they’re doing on such a core piece of software.
But seriously if feasible, share the issue link. Especially when there's conversation involved, it's different kind of nice (and learning opportunity) reading such thread
I thought OpenBSD / OpenSSH operate without a tracker and it’s all email distro based.
* https://www.openssh.org/report.html
https://github.com/openssh/openssh-portable/commit/d4b4c304a...
It’s what Apple experimented with before they came up with the current entitlements system.
"Updated sandbox for privilege-separated pre-authorization sshd process" is listed as a modification to the open-source project, but I suspect this is out-of-date.
So I think it would be up to the team that ports it to Apple, so I think the "Apple Team" is the ones who would worry about sandboxing.
https://arxiv.org/pdf/2609.07709
I wonder what their funding is like.
https://www.openbsdfoundation.org/campaign2025.html
Now I am going to call out IBM. Last I checked, IBM uses OpenSSH on AIX, but gives a big fat 0. Microsoft has been consistent in donating a decent amount. And a surprise to me, Meta showed up donating last year, nice. I wish IBM would join the list too. Based upon:
https://www.openbsdfoundation.org/contributors.html