Bug 5782 - Do not configure sftp for the ssh daemon by default
Summary: Do not configure sftp for the ssh daemon by default
Status: RESOLVED WONTFIX
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: connectivity (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Low minor
Target Milestone: Future
Assignee: Unassigned
QA Contact:
URL:
Whiteboard: Roxanna is no longer at Intel
Depends on:
Blocks:
 
Reported: 2014-01-31 18:21 UTC by Laszlo Papp
Modified: 2017-06-13 11:00 UTC (History)
7 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: Don't know


Attachments
proposition number one (2.62 KB, patch)
2014-02-20 13:54 UTC, Matthieu Crapet
no flags Details | Diff
proposition number two (3.15 KB, patch)
2014-02-20 18:10 UTC, Matthieu Crapet
no flags Details | Diff
v3 (3.60 KB, patch)
2014-02-21 09:01 UTC, Matthieu Crapet
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Laszlo Papp 2014-01-31 18:21:24 UTC
If I use the IMAGE_FEATURES += "ssh-server-openssh" statement in my image recipe, I will get the "packagegroup-core-ssh-openssh" group installed which currently only has the "openssh" inside.

Note that there is no sftp server installed by default, yet the openssh daemon configuration file generated contains this line:

# override default of no subsystems                 
Subsystem       sftp    /usr/lib/openssh/sftp-server

I think it would make more sense to leave this out since there is no sftp-server installed. It is misleading at the least.
Comment 1 Saul Wold 2014-02-07 04:25:36 UTC
That configuration line does no harm as it is today and it allows for one package to deliver the configuration file.

The requested fix would require some addition post processing to either comment out or un-comment that line based on the installation of the various packages, which is likely to be more error prone then just leaving the line in.

If you wish to submit a patch for this, you are more than welcome to, I can assign it to you if you wish.
Comment 2 Matthieu Crapet 2014-02-20 13:54:44 UTC
Created attachment 1781 [details]
proposition number one
Comment 3 Laszlo Papp 2014-02-20 13:56:41 UTC
Matthieu, this is one part, but I think it would be nice to have the second part, too, which adds this back for the corresponding package installed. That would be handy for sftp users.
Comment 4 Matthieu Crapet 2014-02-20 14:46:12 UTC
Hi,
You'd like a dynamic behavior (using pkg_postinst_${PN}-ssh) and checking if /usr/libexec/sftp-server exists?
Not sure that it is a good idea.
Comment 5 Laszlo Papp 2014-02-20 14:48:07 UTC
No, I would like the post-install script of the sftp-server package to add this entry back.

Basically, when an end user installs the package, it would also be configured without further work required.
Comment 6 Matthieu Crapet 2014-02-20 18:10:30 UTC
Created attachment 1782 [details]
proposition number two

This patch discards the first one.
Comment 7 Laszlo Papp 2014-02-20 18:17:57 UTC
Thanks for your work.

Unfortunately, I am not a bash guru, but it seems you moved the removal into the post install part of the sftp package.

I will try to be a bit more verbose because it seems I cannot communicate properly; apologies.

1) Your removal is good, and it could be part of the basic openssh installation.

2) You could insert this line back once someone installs the sftp package.

The use case would go along these lines:

a) there is user `A` who would like to get the openssh package, but without the additional size (~70 KB) and complexity constraint of the sftp package. This is all fine, user `A` will get a basic openssh installation without the SFTP enabled inside the ssh configuration.

b) there is user `B` who would like to get the openssh package, but with the additional sftp feature because the advantage in that case would outweight the detriments of the size and complexity. That is all fine, user `B` would get a config with the SFTP enabled inside the ssh configuration.

Hope, it is a bit more clear. Any questions or concerns, please let me know.
Comment 8 Matthieu Crapet 2014-02-21 09:01:08 UTC
Created attachment 1784 [details]
v3

My assumption, hooks for openssh-sftp-server only.

But indeed, there is no package dependency with openssh-sshd package.
So there is a potential issue if openssh-sftp-server is installed before openssh-sshd.

Is is worth adding a check (-x /usr/libexec/sftp-server) in openssh-sshd postinst?
Comment 9 Matthieu Crapet 2014-03-07 09:11:35 UTC
Let's be safe and keep sshd_config untouched.
Let's keep snippets for:
pkg_postinst_${PN}-sftp-server & pkg_postrm_${PN}-sftp-server,
even if it doesn't cover all cases..
Comment 10 Richard Purdie 2017-06-13 11:00:26 UTC
(In reply to comment #1)
> That configuration line does no harm as it is today and it allows for one
> package to deliver the configuration file.
> 
> The requested fix would require some addition post processing to either
> comment out or un-comment that line based on the installation of the various
> packages, which is likely to be more error prone then just leaving the line
> in.

Looking at the complexity of the solutions proposed, I agree with Saul here, this is harmless and we can leave it as is.