[Git][debian-proftpd-team/proftpd][trixie] Remove patches, which do not apply and are superseeded.

Hilmar Preuße (@hilmar) gitlab at salsa.debian.org
Sun Jul 26 17:49:07 BST 2026



Hilmar Preuße pushed to branch trixie at Debian ProFTPD Team / proftpd


Commits:
8154f542 by Hilmar Preuße at 2026-07-26T18:48:56+02:00
Remove patches, which do not apply and are superseeded.

- - - - -


6 changed files:

- − debian/patches/226c85b97aa75cef4bdd74e7012b313a801796b5.diff
- − debian/patches/8685930f5e2e448563ef31d8871553308b954785.diff
- − debian/patches/8ccd66576da8c3e4ca678335268905e00bc71bdb.diff
- − debian/patches/a237fa62341bf882c7edc4e5e8cc492cec851d0b.diff
- − debian/patches/ce13286900a7e25f1e3403620496868d73292f6b.diff
- debian/patches/series


Changes:

=====================================
debian/patches/226c85b97aa75cef4bdd74e7012b313a801796b5.diff deleted
=====================================
@@ -1,45 +0,0 @@
-From 226c85b97aa75cef4bdd74e7012b313a801796b5 Mon Sep 17 00:00:00 2001
-From: TJ Saunders <tj at castaglia.org>
-Date: Sun, 31 May 2026 11:36:01 -0700
-Subject: [PATCH] Issue #2115: Move our check for excessive SFTP request length
- earlier, to avoid another vector to underflow.
-
-Bankde Eakasit rightly pointed out this avenue.
----
- contrib/mod_sftp/fxp.c | 16 +++++++---------
- 1 file changed, 7 insertions(+), 9 deletions(-)
-
-diff --git a/contrib/mod_sftp/fxp.c b/contrib/mod_sftp/fxp.c
-index dec6f37e9..ef9a1c391 100644
---- a/contrib/mod_sftp/fxp.c
-+++ b/contrib/mod_sftp/fxp.c
-@@ -3422,6 +3422,13 @@ static struct fxp_packet *fxp_packet_read(uint32_t channel_id,
-       SFTP_DISCONNECT_CONN(SFTP_SSH2_DISCONNECT_BY_APPLICATION, NULL);
-     }
- 
-+    if (fxp->packet_len > FXP_MAX_PACKET_LEN) {
-+      (void) pr_log_writefile(sftp_logfd, MOD_SFTP_VERSION,
-+        "received excessive SFTP packet (len %lu > max %lu bytes), rejecting",
-+        (unsigned long) fxp->packet_len, (unsigned long) FXP_MAX_PACKET_LEN);
-+      SFTP_DISCONNECT_CONN(SFTP_SSH2_DISCONNECT_BY_APPLICATION, NULL);
-+    }
-+
-     if (buflen == 0) {
-       fxp_packet_set_packet(fxp);
-       fxp_packet_clear_cache_data();
-@@ -14125,15 +14132,6 @@ int sftp_fxp_handle_packet(pool *p, void *ssh2, uint32_t channel_id,
-         (unsigned long) channel_id);
-     }
- 
--    if (fxp->packet_len > FXP_MAX_PACKET_LEN) {
--      (void) pr_log_writefile(sftp_logfd, MOD_SFTP_VERSION,
--        "received excessive SFTP packet (len %lu > max %lu bytes), rejecting",
--        (unsigned long) fxp->packet_len, (unsigned long) FXP_MAX_PACKET_LEN);
--      destroy_pool(fxp->pool);
--      errno = EPERM;
--      return -1;
--    }
--
-     fxp_session = fxp_get_session(channel_id);
-     if (fxp_session == NULL) {
-       (void) pr_log_writefile(sftp_logfd, MOD_SFTP_VERSION,


=====================================
debian/patches/8685930f5e2e448563ef31d8871553308b954785.diff deleted
=====================================
@@ -1,29 +0,0 @@
-From 8685930f5e2e448563ef31d8871553308b954785 Mon Sep 17 00:00:00 2001
-From: TJ Saunders <tj at castaglia.org>
-Date: Sat, 30 May 2026 11:25:33 -0700
-Subject: [PATCH] Issue #2115: Ensure that the SFTP request payload length
- computation does not underflow.
-
----
- contrib/mod_sftp/fxp.c | 10 ++++++++++
- 1 file changed, 10 insertions(+)
-
---- proftpd.orig/contrib/mod_sftp/fxp.c
-+++ proftpd/contrib/mod_sftp/fxp.c
-@@ -3389,6 +3389,16 @@
-       return NULL;
-     }
- 
-+    /* We require 5 bytes of SFTP request data at a minimum: 1 byte for the
-+     * request type, and 4 bytes for the payload length (Issue #2115).
-+     */
-+    if (fxp->packet_len < 5) {
-+      (void) pr_log_writefile(sftp_logfd, MOD_SFTP_VERSION,
-+        "illegal SFTP request length (%lu bytes, require at least 5 bytes), "
-+        "rejecting", (unsigned long) fxp->packet_len);
-+      SFTP_DISCONNECT_CONN(SFTP_SSH2_DISCONNECT_BY_APPLICATION, NULL);
-+    }
-+
-   } else {
-     pr_trace_msg(trace_channel, 19,
-       "already have SFTP request packet len %lu from previous buffer data",


=====================================
debian/patches/8ccd66576da8c3e4ca678335268905e00bc71bdb.diff deleted
=====================================
@@ -1,188 +0,0 @@
-From 8ccd66576da8c3e4ca678335268905e00bc71bdb Mon Sep 17 00:00:00 2001
-From: TJ Saunders <tj at castaglia.org>
-Date: Sat, 30 May 2026 13:48:58 -0700
-Subject: [PATCH] Implement some sanity checks on the length of extended
- attributes (xattrs) that can be requested via custom SFTP extensions.
-
-Bankde Eakasit posited that this could be another vector to triggering excessive memory allocations.
----
- contrib/mod_sftp/fxp.c | 85 ++++++++++++++++++++++++++++++++++++------
- 1 file changed, 74 insertions(+), 11 deletions(-)
-
-diff --git a/contrib/mod_sftp/fxp.c b/contrib/mod_sftp/fxp.c
-index 9a31cc722..dec6f37e9 100644
---- a/contrib/mod_sftp/fxp.c
-+++ b/contrib/mod_sftp/fxp.c
-@@ -281,12 +281,14 @@ static size_t fxp_packet_data_allocsz = 0;
- #define FXP_PACKET_DATA_DEFAULT_SZ		(1024 * 16)
- #define FXP_RESPONSE_DATA_DEFAULT_SZ		512
- 
--#ifdef PR_USE_XATTR
-+#if defined(PR_USE_XATTR)
-+/* Impose limits on the xattr value length we are willing to process. */
-+# define FXP_XATTR_VALUE_MAX_LEN		(1024 * 64)
- /* Allocate larger buffers for extended attributes */
- # define FXP_RESPONSE_NAME_DEFAULT_SZ		(1024 * 4)
- #endif /* PR_USE_XATTR */
- 
--#ifndef FXP_RESPONSE_NAME_DEFAULT_SZ
-+#if !defined(FXP_RESPONSE_NAME_DEFAULT_SZ)
- # define FXP_RESPONSE_NAME_DEFAULT_SZ		FXP_RESPONSE_DATA_DEFAULT_SZ
- #endif
- 
-@@ -1893,7 +1895,7 @@ static char *fxp_strattrs(pool *p, struct stat *st, uint32_t *attr_flags) {
- 
-       if (fxp_session->client_version >= 6) {
-         flags |= SSH2_FX_ATTR_LINK_COUNT;
--#ifdef PR_USE_XATTR
-+#if defined(PR_USE_XATTR)
-         flags |= SSH2_FX_ATTR_EXTENDED;
- #endif /* PR_USE_XATTR */
-       }
-@@ -2572,7 +2574,7 @@ static uint32_t fxp_xattrs_write(pool *p, struct fxp_buffer *fxb,
-     const char *path) {
-   uint32_t len = 0;
- 
--#ifdef PR_USE_XATTR
-+#if defined(PR_USE_XATTR)
-   int res;
-   array_header *names = NULL;
- 
-@@ -5964,7 +5966,7 @@ static int fxp_handle_ext_statvfs(struct fxp_packet *fxp, const char *path) {
- }
- #endif /* !HAVE_SYS_STATVFS_H */
- 
--#ifdef PR_USE_XATTR
-+#if defined(PR_USE_XATTR)
- static int fxp_handle_ext_getxattr(struct fxp_packet *fxp, const char *path,
-     const char *name, uint32_t valsz) {
-   ssize_t res;
-@@ -5974,6 +5976,36 @@ static int fxp_handle_ext_getxattr(struct fxp_packet *fxp, const char *path,
-   const char *reason;
-   struct fxp_packet *resp;
- 
-+  buflen = bufsz = FXP_RESPONSE_DATA_DEFAULT_SZ;
-+  buf = ptr = palloc(fxp->pool, bufsz);
-+
-+  if (valsz > FXP_XATTR_VALUE_MAX_LEN) {
-+    int xerrno = EINVAL;
-+
-+    (void) pr_log_writefile(sftp_logfd, MOD_SFTP_VERSION,
-+      "getxattr(2) on '%s' for attribute '%s' (%lu bytes) exceeds maximum "
-+      "value size (%lu bytes), denying", path, name, (unsigned long) valsz,
-+      (unsigned long) FXP_XATTR_VALUE_MAX_LEN);
-+
-+    status_code = fxp_errno2status(xerrno, &reason);
-+
-+    pr_trace_msg(trace_channel, 8, "sending response: STATUS %lu '%s' "
-+      "('%s' [%d])", (unsigned long) status_code, reason, strerror(xerrno),
-+      xerrno);
-+
-+    fxp_status_write(fxp->pool, &buf, &buflen, fxp->request_id, status_code,
-+      reason, NULL);
-+
-+    resp = fxp_packet_create(fxp->pool, fxp->channel_id);
-+    resp->payload = ptr;
-+    resp->payload_sz = (bufsz - buflen);
-+
-+    return fxp_packet_write(resp);
-+  }
-+
-+  /* Now that the value size has been checked, we allocate a new, larger
-+   * buffer for that size.
-+   */
-   val = pcalloc(fxp->pool, (size_t) valsz+1);
- 
-   buflen = bufsz = FXP_RESPONSE_DATA_DEFAULT_SZ + valsz;
-@@ -6027,7 +6059,7 @@ static int fxp_handle_ext_fgetxattr(struct fxp_packet *fxp, const char *handle,
-   struct fxp_handle *fxh;
-   struct fxp_packet *resp;
- 
--  buflen = bufsz = FXP_RESPONSE_DATA_DEFAULT_SZ + valsz;
-+  buflen = bufsz = FXP_RESPONSE_DATA_DEFAULT_SZ;
-   buf = ptr = palloc(fxp->pool, bufsz);
- 
-   fxh = fxp_handle_get(handle);
-@@ -6076,6 +6108,37 @@ static int fxp_handle_ext_fgetxattr(struct fxp_packet *fxp, const char *handle,
-   }
- 
-   path = fxh->fh->fh_path;
-+
-+  if (valsz > FXP_XATTR_VALUE_MAX_LEN) {
-+    int xerrno = EINVAL;
-+
-+    (void) pr_log_writefile(sftp_logfd, MOD_SFTP_VERSION,
-+      "fgetxattr(2) on '%s' for attribute '%s' (%lu bytes) exceeds maximum "
-+      "value size (%lu bytes), denying", path, name, (unsigned long) valsz,
-+      (unsigned long) FXP_XATTR_VALUE_MAX_LEN);
-+
-+    status_code = fxp_errno2status(xerrno, &reason);
-+
-+    pr_trace_msg(trace_channel, 8, "sending response: STATUS %lu '%s' "
-+      "('%s' [%d])", (unsigned long) status_code, reason, strerror(xerrno),
-+      xerrno);
-+
-+    fxp_status_write(fxp->pool, &buf, &buflen, fxp->request_id, status_code,
-+      reason, NULL);
-+
-+    resp = fxp_packet_create(fxp->pool, fxp->channel_id);
-+    resp->payload = ptr;
-+    resp->payload_sz = (bufsz - buflen);
-+
-+    return fxp_packet_write(resp);
-+  }
-+
-+  /* Now that the value size has been checked, we allocate a new, larger
-+   * buffer for that size.
-+   */
-+  buflen = bufsz = FXP_RESPONSE_DATA_DEFAULT_SZ + valsz;
-+  buf = ptr = palloc(fxp->pool, bufsz);
-+
-   val = pcalloc(fxp->pool, (size_t) valsz+1);
- 
-   res = pr_fsio_fgetxattr(fxp->pool, fxh->fh, name, val, (size_t) valsz);
-@@ -8064,7 +8127,7 @@ static int fxp_handle_fstat(struct fxp_packet *fxp) {
-     pr_trace_msg(trace_channel, 7, "received request: FSTAT %s", name);
-     attr_flags = SSH2_FX_ATTR_SIZE|SSH2_FX_ATTR_UIDGID|SSH2_FX_ATTR_PERMISSIONS|
-       SSH2_FX_ATTR_ACMODTIME;
--#ifdef PR_USE_XATTR
-+#if defined(PR_USE_XATTR)
-     if (!(fxp_fsio_opts & PR_FSIO_OPT_IGNORE_XATTR)) {
-       attr_flags |= SSH2_FX_ATTR_EXTENDED;
-     }
-@@ -8797,7 +8860,7 @@ static int fxp_handle_lstat(struct fxp_packet *fxp) {
-     pr_trace_msg(trace_channel, 7, "received request: LSTAT %s", path);
-     attr_flags = SSH2_FX_ATTR_SIZE|SSH2_FX_ATTR_UIDGID|SSH2_FX_ATTR_PERMISSIONS|
-       SSH2_FX_ATTR_ACMODTIME;
--#ifdef PR_USE_XATTR
-+#if defined(PR_USE_XATTR)
-     if (!(fxp_fsio_opts & PR_FSIO_OPT_IGNORE_XATTR)) {
-       attr_flags |= SSH2_FX_ATTR_EXTENDED;
-     }
-@@ -10854,7 +10917,7 @@ static int fxp_handle_readdir(struct fxp_packet *fxp) {
-     pr_signals_handle();
- 
-     /* How much non-path data do we expect to be associated with this entry? */
--#ifdef PR_USE_XATTR
-+#if defined(PR_USE_XATTR)
-     /* Note that the "extra space" to allocate for extended attributes is
-      * currently a bit of a guess.  Initially, this was 4K; that was causing
-      * slower directory listings due to the need for more READDIR requests,
-@@ -11006,7 +11069,7 @@ static int fxp_handle_readdir(struct fxp_packet *fxp) {
-      * Thus we CHOOSE to only provide these extended attributes, if supported,
-      * to protocol version 6 clients.
-      */
--#ifdef PR_USE_XATTR
-+#if defined(PR_USE_XATTR)
-     if (!(fxp_fsio_opts & PR_FSIO_OPT_IGNORE_XATTR)) {
-       attr_flags |= SSH2_FX_ATTR_EXTENDED;
-     }
-@@ -12883,7 +12946,7 @@ static int fxp_handle_stat(struct fxp_packet *fxp) {
-     pr_trace_msg(trace_channel, 7, "received request: STAT %s", path);
-     attr_flags = SSH2_FX_ATTR_SIZE|SSH2_FX_ATTR_UIDGID|SSH2_FX_ATTR_PERMISSIONS|
-       SSH2_FX_ATTR_ACMODTIME;
--#ifdef PR_USE_XATTR
-+#if defined(PR_USE_XATTR)
-     if (!(fxp_fsio_opts & PR_FSIO_OPT_IGNORE_XATTR)) {
-       attr_flags |= SSH2_FX_ATTR_EXTENDED;
-     }


=====================================
debian/patches/a237fa62341bf882c7edc4e5e8cc492cec851d0b.diff deleted
=====================================
@@ -1,43 +0,0 @@
-From a237fa62341bf882c7edc4e5e8cc492cec851d0b Mon Sep 17 00:00:00 2001
-From: TJ Saunders <tj at castaglia.org>
-Date: Sat, 30 May 2026 13:12:51 -0700
-Subject: [PATCH] Issue #2115: The minimum packet length enforcement for SFTP
- requests needs to occur slightly earlier, to prevent other means of
- circumvention.
-
----
- contrib/mod_sftp/fxp.c | 14 +++++++-------
- 1 file changed, 7 insertions(+), 7 deletions(-)
-
-diff --git a/contrib/mod_sftp/fxp.c b/contrib/mod_sftp/fxp.c
-index a4fe5bc25..9a31cc722 100644
---- a/contrib/mod_sftp/fxp.c
-+++ b/contrib/mod_sftp/fxp.c
-@@ -3410,13 +3410,6 @@ static struct fxp_packet *fxp_packet_read(uint32_t channel_id,
-       "(%lu bytes remaining in buffer)", (unsigned long) fxp->packet_len,
-       (unsigned long) buflen);
- 
--    if (buflen == 0) {
--      fxp_packet_set_packet(fxp);
--      fxp_packet_clear_cache_data();
--
--      return NULL;
--    }
--
-     /* We require 5 bytes of SFTP request data at a minimum: 1 byte for the
-      * request type, and 4 bytes for the payload length (Issue #2115).
-      */
-@@ -3427,6 +3420,13 @@ static struct fxp_packet *fxp_packet_read(uint32_t channel_id,
-       SFTP_DISCONNECT_CONN(SFTP_SSH2_DISCONNECT_BY_APPLICATION, NULL);
-     }
- 
-+    if (buflen == 0) {
-+      fxp_packet_set_packet(fxp);
-+      fxp_packet_clear_cache_data();
-+
-+      return NULL;
-+    }
-+
-   } else {
-     pr_trace_msg(trace_channel, 19,
-       "already have SFTP request packet len %lu from previous buffer data",


=====================================
debian/patches/ce13286900a7e25f1e3403620496868d73292f6b.diff deleted
=====================================
@@ -1,92 +0,0 @@
-From ce13286900a7e25f1e3403620496868d73292f6b Mon Sep 17 00:00:00 2001
-From: TJ Saunders <tj at castaglia.org>
-Date: Fri, 26 Jun 2026 12:12:25 -0700
-Subject: [PATCH] Issue #2190: When assembling fragmented SFTP request chunks,
- make sure we always allocate sufficient space for the assembled data.
-
-In addition, add a sanity check for cases where the assembled chunks far exceed our allowed SFTP request packet sizes.
----
- contrib/mod_sftp/fxp.c | 46 +++++++++++++++++++++++++-----------------
- 1 file changed, 27 insertions(+), 19 deletions(-)
-
-diff --git a/contrib/mod_sftp/fxp.c b/contrib/mod_sftp/fxp.c
-index 409159a05..6bcbf2995 100644
---- a/contrib/mod_sftp/fxp.c
-+++ b/contrib/mod_sftp/fxp.c
-@@ -271,11 +271,11 @@ struct fxp_buffer {
- #define	FXP_PACKET_HAVE_PAYLOAD_SIZE	0x0008
- #define	FXP_PACKET_HAVE_PAYLOAD		0x0010
- 
--/* After 32K of allocation from the scratch SFTP payload pool, destroy the
-+/* After 64K of allocation from the scratch SFTP payload pool, destroy the
-  * pool and create a new one.  This will prevent unbounded allocation
-  * from the pool.
-  */
--#define FXP_PACKET_DATA_ALLOC_MAX_SZ		(1024 * 32)
-+#define FXP_PACKET_DATA_ALLOC_MAX_SZ		(1024 * 64)
- static size_t fxp_packet_data_allocsz = 0;
- 
- #define FXP_PACKET_DATA_DEFAULT_SZ		(1024 * 16)
-@@ -3311,37 +3311,45 @@ static void fxp_packet_add_cache_data(unsigned char *data, uint32_t datalen) {
- 
-     } else {
-       /* We need a larger buffer.  Round up to the nearest 1K size. */
-+      pool *tmp_pool;
-+      char *cached_data;
-+      uint32_t cached_datalen;
-       size_t sz;
- 
--      sz = sftp_crypto_get_size(curr_buflen + datalen + 1, 1024);
-+      if (curr_buflen + datalen > FXP_MAX_PACKET_LEN) {
-+        (void) pr_log_writefile(sftp_logfd, MOD_SFTP_VERSION,
-+          "received excessive SFTP data (len %lu > max %lu bytes), rejecting",
-+          (unsigned long) curr_buflen + datalen,
-+          (unsigned long) FXP_MAX_PACKET_LEN);
-+        SFTP_DISCONNECT_CONN(SFTP_SSH2_DISCONNECT_BY_APPLICATION, NULL);
-+      }
- 
--      if (fxp_packet_data_allocsz > FXP_PACKET_DATA_ALLOC_MAX_SZ) {
--        pool *tmp_pool;
--        char *tmp_data;
--        uint32_t tmp_datalen;
-+      /* Get the existing cached data before allocating a larger buffer. */
-+      tmp_pool = make_sub_pool(fxp_pool);
- 
-+      cached_datalen = curr_buflen;
-+      cached_data = palloc(tmp_pool, cached_datalen);
-+      memcpy(cached_data, curr_buf, cached_datalen);
-+
-+      if (fxp_packet_data_allocsz > FXP_PACKET_DATA_ALLOC_MAX_SZ) {
-         (void) pr_log_writefile(sftp_logfd, MOD_SFTP_VERSION,
-           "renewing SFTP packet data pool");
- 
--        tmp_pool = make_sub_pool(fxp_pool);
--        tmp_datalen = curr_buflen;
--        tmp_data = palloc(tmp_pool, tmp_datalen);
--        memcpy(tmp_data, curr_buf, tmp_datalen);
--
-         destroy_pool(curr_buf_pool);
- 
-         curr_buf_pool = make_sub_pool(fxp_pool);
-         pr_pool_tag(curr_buf_pool, "SFTP packet buffer pool");
-+      }
- 
--        curr_bufsz = sz;
--        curr_buf = palloc(curr_buf_pool, curr_bufsz);
--        fxp_packet_data_allocsz += sz;
-+      sz = sftp_crypto_get_size(curr_buflen + datalen + 1, 1024);
-+      curr_bufsz = sz;
-+      curr_buf = palloc(curr_buf_pool, curr_bufsz);
-+      fxp_packet_data_allocsz += sz;
- 
--        memcpy(curr_buf, tmp_data, tmp_datalen);
--        curr_buflen = tmp_datalen;
-+      memcpy(curr_buf, cached_data, cached_datalen);
-+      curr_buflen = cached_datalen;
- 
--        destroy_pool(tmp_pool);
--      }
-+      destroy_pool(tmp_pool);
-     }
- 
-     /* Append the SSH2 data to the current unconsumed buffer.


=====================================
debian/patches/series
=====================================
@@ -25,12 +25,7 @@ e7539bd772ca6e12d3e05fb56da274cf78ee1edf.diff
 07797aba88dca902da7eaf1dfe262c8896943de7.diff
 # issue 2115, CVE-2026-53994
 mod_sftp-1.3.8d-issue2115.diff
-#8685930f5e2e448563ef31d8871553308b954785.diff
-#a237fa62341bf882c7edc4e5e8cc492cec851d0b.diff
-#8ccd66576da8c3e4ca678335268905e00bc71bdb.diff
-#226c85b97aa75cef4bdd74e7012b313a801796b5.diff
 # issue 2201, CVE-2026-63091
 baf4b7929758c72cdb6cf16325fa25f435d23db6.diff
 # issue 2190, CVE-2026-63090
 mod_sftp-1.3.8d-issue2190.diff
-# ce13286900a7e25f1e3403620496868d73292f6b.diff



View it on GitLab: https://salsa.debian.org/debian-proftpd-team/proftpd/-/commit/8154f542de484d02f842ce39e891ea40e6887f40

-- 
View it on GitLab: https://salsa.debian.org/debian-proftpd-team/proftpd/-/commit/8154f542de484d02f842ce39e891ea40e6887f40
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help




More information about the Pkg-proftpd-maintainers mailing list