2026-10-05 15:21:25 by Adam Ciarcinski | Files touched by this commit (2) |  |
Log message:
py-asyncssh: updated to 2.24.1
2.24.1 (3 Oct 2026)
* Fixed a potential "short read/write" issue in SFTP, potentially
requiring multiple calls to successfully read or write all the data
an application requests. Thanks go to Landon Peng for reporting
this issue.
* Added protection against unreasonable packet lengths when parsing
SSH and SFTP packets, avoiding a potential denial of service attack.
Thanks go to zhangph (GitHub user afldl) for suggesting this change.
* Added restrictions on which SSH channel requests are allowed to be
sent more than once on a channel. Thanks go to zhangph (GitHub user
afldl) for reporting this issue for shell/exec/subsystem requests.
* Improved error reporting of a client trying to set multiple attributes
on a file, when some of the operations aren't supported. Thanks go to
Kevin O'Neil for reporting this issue and helping to test this fix.
* Improved path sanitizaation for SCP, to protect against additional
"path traversal" attacks. Thanks go to GitHub user jankesec for
reporting the issue and providing a proposed fix.
* Fixed a race condition in server authentication that could result
in the wrong username being set as the authenticated user.
* Fixed a possible leak of options across authentication attempts when
multiple authentication requests are attempted on a connection.
Thanks go to GitHub user 0xW41th for reporting this issue and
providing a suggested fix.
* Fixed multiple SFTP "path traversal" issues, where a malicious SFTP
server could trick an SFTP client into writing outside of the
requested target directory. Thanks go to Youjoon Yoon, Khizar
Ali Shah, and GitHub user L1nq0 for reporting these issues and
suggesting possible fixes.
* Fixed multiple SFTP chroot escape issues, where a client could read
and write files outside of a chroot'd AsyncSSH SFTP server. Thanks
go to GitHub user LorenzMap, Arpit Jain, and Mario Madersbacher for
reporting these issues and suggesting possible fixes.
* Fixed revocation checking to handle the case where a host certificate
is sent with a trusted CA but where the host key within the
certificate is marked as revoked. Thanks go to Mohammad Thabet Hassan
for reporting this issue.
* Fixed SSH channels receive window updates to be properly tracked
when reading on the channel is paused. Thanks go to GitHub user
Sumit-2004 for reporting this issue.
* Changed SSH config file username token substitution to disallow
the username from being an empty string, avoiding a possible
vulnerability. Thanks go to GitHub user L1nq0 for reporting this
issue and proposing possible fixes.
* Fixed deprecation errors on des-cbc and des2-cbc ciphers.
* Added pre-commit hooks, including spell checking, and fixed various
errors found by that. Thanks go to Waket Zheng for providing an
initial versiosn of this.
|
2026-07-01 15:06:33 by Adam Ciarcinski | Files touched by this commit (3) |  |
Log message:
py-asyncssh: updated to 2.24.0
2.24.0 (27 Jun 2026)
* Added support for creating and validating SSHSIG signatures, as well
as OpenSSH "allowed signers" files.
* Added support for ML-KEM key exchange from the PyCA cryptography
package when it is available. This avoids the need to have the
liboqs library installed to use ML-KEM. However, liboqs is still
required to support SNTRUP kex exchange.
* Fixed an issue with handling of SSH maximum packet size when opening
a new SSH channel, aborting with a protocol error if a peer attempts
to set this size to 0. Thanks go to GitHub user afldl for reporting
this issue and providing analysis and reproduction code.
* Fixed an issue with include directives in OpenSSH config files.
Thanks go to GitHub users sethholmes and tazle for reporting this
issue and providing analysis and a proposed fix.
|
| 2026-06-28 17:41:51 by Thomas Klausner | Files touched by this commit (364) |
Log message:
*: limit Python versions due to py-numpy dropping Python 3.11 support
|
2026-06-10 15:00:35 by Adam Ciarcinski | Files touched by this commit (2) |  |
Log message:
py-asyncssh: updated to 2.23.1
2.23.1 (6 Jun 2026)
* Fixed an SCP path traversal issue. Thanks go to Jaden Furtado for
reporting this issue.
* Expanded previous fix to block unsafe user substitutions in server
config. Thanks go to GitHub user cesabici-bit for reporting this
issue.
* Fixed default value for reuse_address and reuse_port, matching
the behaavior of asyncio.create_server(). Thanks go to Alexander
Shlemin for reporting the inconsistency.
|
2026-05-11 14:47:04 by Adam Ciarcinski | Files touched by this commit (2) |  |
Log message:
py-asyncssh: updated to 2.23.0
Release 2.23.0 (8 Feb 2026)
* Added support for "Match localnetwork". Thanks go to Théophile Bastian
for reporting this new match type, added in OpenSSH 9.4.
* Enabled support for RSA with SHA-2 signatures in ssh-agent and Pageant.
Thanks go to GitHub user Netzvamp for reporting this.
* Changed MAC algorithm negotation to be skipped when using AEAD ciphers.
Thanks go to GitHub user LilleCarl for reporting this issue and
suggesting a potential fix.
* Improved graceful termination when using ProxyCommand, waiting for
the ProxyCommand tunnel to close when cleaning up a connection. Thanks
go to Simon Liétar for reporting this issue and helping to investigate
possible solutions.
* Blocked unsafe user substitutions from being used in server config.
Thanks go to GitHub user 0xHunSec for reporting this problem and
providing reproduction code.
* Fixed an issue with config evaluation when "Match final" was combined
with Hostname directives. Thanks go to GitHub user commonism for
reporting this issue and coming up with a reproducible test case and a
potential fix.
* Fixed a resource leak in xauth support. Thanks go to GitHub user
taovinci0 for reporting this problem and providing an initial version
of a fix.
* Fixed issue with multi-hop ProxyJump directives in a config file
not working correctly. Thanks go to Rémi Benoit for reporting this
problem and providing a detailed root cause analysis.
* Fixed string encoding in SFTPName objects returned by realpath().
Thanks go to GitHub user vivodi for reporting this and providing
reproduction code.
|
2025-12-26 10:00:03 by Adam Ciarcinski | Files touched by this commit (2) |  |
Log message:
py-asyncssh: updated to 2.22.0
Release 2.22.0 (21 Dec 2025)
* Added a new config option `utf8_decode_errors` for handling UTF-8
decode errors when parsing certain fields in SSH packets (disconnect
error, debug message, userauth banner, channel open failure reason,
channel exit signal reason, and SFTP error reason). The default
continues to behave as before, raising a ProtocolError exception,
but this option allows invalid bytes to be removed or replaced.
Thanks go to GitHub user Le-Syl21 for suggesting this.
* Changed config parser to Ignore subdirectories and parse only plain
files matching a glob pattern in include directives, better matching
the behavior of other SSH implementations. Thanks go to Jacopo Nespolo
for contributing this change.
* Improved a previous fix for a race condition which sometimes triggered
assertion errors in SSHForwarder. Thanks go to Mike Barry for reporting
the issue and helping to test the improved fix.
* Removed optional dependency on libnacl/libsodium for chacha20 and
Edwrds curves, now that these are available in all supported
versions of the cryptography package.
* Updated asyncssh to use version 2 of the fido2 package, and update
minimum Python version to 3.10, required by that updated package.
* Fixed issue with the OpenSSL legacy provider on Windows and
re-enabled OpenSSL use in unit tests on Windows.
* Inproved "run multiple clients" example to show the hostname being
accessed by each task.
* Added unit testing for Python 3.14 and dropped 3.8 and 3.9.
|
| 2025-10-09 09:58:14 by Thomas Klausner | Files touched by this commit (442) |
Log message:
*: remove reference to (removed) Python 3.9
|
2025-09-30 10:11:40 by Adam Ciarcinski | Files touched by this commit (2) |  |
Log message:
py-asyncssh: updated to 2.21.1
Release 2.21.1 (28 Sep 2025)
* Added the capability to defer invoking passphrase callback until
an encrypted private key is actually used in a signing operation,
rather than triggering the callback when keys are loaded. This
will only work when a public key is provided with an encrypted
private key either explicitly or as part of the key format (such
as in OpenSSH's private key format).
* Improved handling of KeyboardInterrupt and task cancellation in
SCP. Thanks go to Viktor Kertesz for reporting this issue and
helping to understand the behavior in various versions of Python.
* Fixed the env option to support mappings other than dict. Thanks
go to Boris Pavlovic for reporting this issue.
* Fixed a potential race condition in SSHForwarder cleanup. Thanks
go to GitHub user misa-hase for reporting this issue and helping
to test the fix.
|