[illumos-Developer] Webrev for bug 1102: Resource exhaustion in sftp client

Gary Mills mills at cc.umanitoba.ca
Fri Jun 24 05:53:36 PDT 2011


On Thu, Jun 23, 2011 at 04:03:18PM -0400, Albert Lee wrote:
> On Thu, Jun 23, 2011 at 3:50 PM, Bayard Bell
> <buffer.g.overflow at googlemail.com> wrote:
> > On 23 Jun 2011, at 20:42, Gary Mills wrote:
> >>
> >> According to the changelog for portable openssh, they're already
> >> there:
> >>
> >> 20110112
> >>  - OpenBSD CVS Sync
> >>    - nicm at cvs.openbsd.org 2010/10/08 21:48:42
> >>      [openbsd-compat/glob.c]
> >>      Extend GLOB_LIMIT to cover readdir and stat and bump the malloc limit
> >>      from ARG_MAX to 64K.
> >>      Fixes glob-using programs (notably ftp) able to be triggered to hit
> >>      resource limits.
> >>      Idea from a similar NetBSD change, original problem reported by jasper at .
> >>      ok millert tedu jasper
> >>
> >> So, once the ssh product is updated from upstream, their resource
> >> limit fixes will be present.
> >
> > There isn't any simple pull from upstream for ssh, as SUNWssh is a
> > somewhat different creature than openssh-portable.
> 
> Trying to sync with openssh-portable will be a much larger endeavour
> than the scope of this issue.

I wonder if the SUNWssh changes could be submitted upstream.  That might
be a way to get us in sync again.

> I'm happy with Gary's additional info,
> are there any remaining concerns?

The RTI was submitted last week.

-- 
-Gary Mills-        -Unix Group-        -Computer and Network Services-



More information about the Developer mailing list