| Summary: | Do not configure sftp for the ssh daemon by default | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Laszlo Papp <lpapp> | ||||||||
| Component: | connectivity | Assignee: | Unassigned <unassigned> | ||||||||
| Status: | RESOLVED WONTFIX | QA Contact: | |||||||||
| Severity: | minor | ||||||||||
| Priority: | Low | CC: | jefro, mcrapet, meta.mr.watcher, meta.watcher, richard.purdie, roxana.ciobanu, sgw | ||||||||
| Version: | unspecified | ||||||||||
| Target Milestone: | Future | ||||||||||
| Hardware: | x86 | ||||||||||
| OS: | Multiple | ||||||||||
| Whiteboard: | Roxanna is no longer at Intel | ||||||||||
| OS type for building Yocto: | --- | Type of Regression: | --- | ||||||||
| Verified: | Documentation change: | Don't know | |||||||||
| Attachments: |
|
||||||||||
|
Description
Laszlo Papp
2014-01-31 18:21:24 UTC
That configuration line does no harm as it is today and it allows for one package to deliver the configuration file. The requested fix would require some addition post processing to either comment out or un-comment that line based on the installation of the various packages, which is likely to be more error prone then just leaving the line in. If you wish to submit a patch for this, you are more than welcome to, I can assign it to you if you wish. Created attachment 1781 [details]
proposition number one
Matthieu, this is one part, but I think it would be nice to have the second part, too, which adds this back for the corresponding package installed. That would be handy for sftp users. Hi,
You'd like a dynamic behavior (using pkg_postinst_${PN}-ssh) and checking if /usr/libexec/sftp-server exists?
Not sure that it is a good idea.
No, I would like the post-install script of the sftp-server package to add this entry back. Basically, when an end user installs the package, it would also be configured without further work required. Created attachment 1782 [details]
proposition number two
This patch discards the first one.
Thanks for your work. Unfortunately, I am not a bash guru, but it seems you moved the removal into the post install part of the sftp package. I will try to be a bit more verbose because it seems I cannot communicate properly; apologies. 1) Your removal is good, and it could be part of the basic openssh installation. 2) You could insert this line back once someone installs the sftp package. The use case would go along these lines: a) there is user `A` who would like to get the openssh package, but without the additional size (~70 KB) and complexity constraint of the sftp package. This is all fine, user `A` will get a basic openssh installation without the SFTP enabled inside the ssh configuration. b) there is user `B` who would like to get the openssh package, but with the additional sftp feature because the advantage in that case would outweight the detriments of the size and complexity. That is all fine, user `B` would get a config with the SFTP enabled inside the ssh configuration. Hope, it is a bit more clear. Any questions or concerns, please let me know. Created attachment 1784 [details]
v3
My assumption, hooks for openssh-sftp-server only.
But indeed, there is no package dependency with openssh-sshd package.
So there is a potential issue if openssh-sftp-server is installed before openssh-sshd.
Is is worth adding a check (-x /usr/libexec/sftp-server) in openssh-sshd postinst?
Let's be safe and keep sshd_config untouched.
Let's keep snippets for:
pkg_postinst_${PN}-sftp-server & pkg_postrm_${PN}-sftp-server,
even if it doesn't cover all cases..
(In reply to comment #1) > That configuration line does no harm as it is today and it allows for one > package to deliver the configuration file. > > The requested fix would require some addition post processing to either > comment out or un-comment that line based on the installation of the various > packages, which is likely to be more error prone then just leaving the line > in. Looking at the complexity of the solutions proposed, I agree with Saul here, this is harmless and we can leave it as is. |