Bug 5782

Summary: Do not configure sftp for the ssh daemon by default
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Laszlo Papp <lpapp>
Component: connectivityAssignee: Unassigned <unassigned>
Status: RESOLVED WONTFIX QA Contact:
Severity: minor    
Priority: Low CC: jefro, mcrapet, meta.mr.watcher, meta.watcher, richard.purdie, roxana.ciobanu, sgw
Version: unspecified   
Target Milestone: Future   
Hardware: x86   
OS: Multiple   
Whiteboard: Roxanna is no longer at Intel
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Don't know
Attachments:
Description Flags
proposition number one
none
proposition number two
none
v3 none

Description Laszlo Papp 2014-01-31 18:21:24 UTC
If I use the IMAGE_FEATURES += "ssh-server-openssh" statement in my image recipe, I will get the "packagegroup-core-ssh-openssh" group installed which currently only has the "openssh" inside.

Note that there is no sftp server installed by default, yet the openssh daemon configuration file generated contains this line:

# override default of no subsystems                 
Subsystem       sftp    /usr/lib/openssh/sftp-server

I think it would make more sense to leave this out since there is no sftp-server installed. It is misleading at the least.
Comment 1 Saul Wold 2014-02-07 04:25:36 UTC
That configuration line does no harm as it is today and it allows for one package to deliver the configuration file.

The requested fix would require some addition post processing to either comment out or un-comment that line based on the installation of the various packages, which is likely to be more error prone then just leaving the line in.

If you wish to submit a patch for this, you are more than welcome to, I can assign it to you if you wish.
Comment 2 Matthieu Crapet 2014-02-20 13:54:44 UTC
Created attachment 1781 [details]
proposition number one
Comment 3 Laszlo Papp 2014-02-20 13:56:41 UTC
Matthieu, this is one part, but I think it would be nice to have the second part, too, which adds this back for the corresponding package installed. That would be handy for sftp users.
Comment 4 Matthieu Crapet 2014-02-20 14:46:12 UTC
Hi,
You'd like a dynamic behavior (using pkg_postinst_${PN}-ssh) and checking if /usr/libexec/sftp-server exists?
Not sure that it is a good idea.
Comment 5 Laszlo Papp 2014-02-20 14:48:07 UTC
No, I would like the post-install script of the sftp-server package to add this entry back.

Basically, when an end user installs the package, it would also be configured without further work required.
Comment 6 Matthieu Crapet 2014-02-20 18:10:30 UTC
Created attachment 1782 [details]
proposition number two

This patch discards the first one.
Comment 7 Laszlo Papp 2014-02-20 18:17:57 UTC
Thanks for your work.

Unfortunately, I am not a bash guru, but it seems you moved the removal into the post install part of the sftp package.

I will try to be a bit more verbose because it seems I cannot communicate properly; apologies.

1) Your removal is good, and it could be part of the basic openssh installation.

2) You could insert this line back once someone installs the sftp package.

The use case would go along these lines:

a) there is user `A` who would like to get the openssh package, but without the additional size (~70 KB) and complexity constraint of the sftp package. This is all fine, user `A` will get a basic openssh installation without the SFTP enabled inside the ssh configuration.

b) there is user `B` who would like to get the openssh package, but with the additional sftp feature because the advantage in that case would outweight the detriments of the size and complexity. That is all fine, user `B` would get a config with the SFTP enabled inside the ssh configuration.

Hope, it is a bit more clear. Any questions or concerns, please let me know.
Comment 8 Matthieu Crapet 2014-02-21 09:01:08 UTC
Created attachment 1784 [details]
v3

My assumption, hooks for openssh-sftp-server only.

But indeed, there is no package dependency with openssh-sshd package.
So there is a potential issue if openssh-sftp-server is installed before openssh-sshd.

Is is worth adding a check (-x /usr/libexec/sftp-server) in openssh-sshd postinst?
Comment 9 Matthieu Crapet 2014-03-07 09:11:35 UTC
Let's be safe and keep sshd_config untouched.
Let's keep snippets for:
pkg_postinst_${PN}-sftp-server & pkg_postrm_${PN}-sftp-server,
even if it doesn't cover all cases..
Comment 10 Richard Purdie 2017-06-13 11:00:26 UTC
(In reply to comment #1)
> That configuration line does no harm as it is today and it allows for one
> package to deliver the configuration file.
> 
> The requested fix would require some addition post processing to either
> comment out or un-comment that line based on the installation of the various
> packages, which is likely to be more error prone then just leaving the line
> in.

Looking at the complexity of the solutions proposed, I agree with Saul here, this is harmless and we can leave it as is.