Gentoo Archives: gentoo-dev

From: Wolfram Schlich <lists@×××××××××××××××.org>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] openssh sftplogging patch
Date: Wed, 15 Nov 2006 00:04:54
Message-Id: 20061115000110.ALLYOURBASEAREBELONGTOUS.L27375@bla.fasel.org
In Reply to: Re: [gentoo-dev] openssh sftplogging patch by Rumi Szabolcs
1 * Rumi Szabolcs <rumi_ml@××××.hu> [2006-11-14 07:42]:
2 > On Mon, 13 Nov 2006 13:15:46 +0100
3 > Wolfram Schlich <lists@×××××××××××××××.org> wrote:
4 >
5 > > In what ChangeLog, the portage package ChangeLog?
6 > > Yeah, I also had to look at the OpenSSH ChangeLog to find out that
7 > > SFTP logging has been added as a new feature.
8 >
9 > Yep, of course I meant the openssh package ChangeLog in portage
10 > which IMHO should contain a word about why a USE flag has been
11 > removed.
12
13 Ok. Well, I don't know of any "standard procedure" to notify
14 the user of a reason for a USE flag removal... :(
15
16 > > > To me this doesn't look like as if it would have been integrated...
17 > >
18 > > The sftp-server(8) binary has new command line options that influence
19 > > SFTP logging:
20 > >
21 > > -f log_facility
22 > > -l log_level
23 > >
24 > > The sftplogging also contains functionality to control umask and permit
25 > > chmod and chgrp, which the upstream sftp-server does not provide.
26 >
27 > Hmm... do I understand correctly that the sftplogging patch has not
28 > been integrated but only a part of it's functions has been implemented
29 > in a different way than it is in the patch?
30
31 Yes.
32
33 > Well, the syslog logging is useful but those settings about umask and
34 > chmod/chgrp are essential in managing an sftp-based file repository with
35 > multiuser access which is a great alternative to cleartext FTP access.
36 > Using the settings the sftplogging patch provides I can set up an sftp
37 > server in a usable and secure way which would otherwise be impossible.
38 >
39 > So here is a big PLEASE to keep/put back the sftplogging patch and
40 > the use flag in the openssh ebuild!
41
42 Well, the patch was called "sftplogging". umask+chmod/chgrp has
43 absolutely *nothing* to do with "SFTP logging".
44 I believe this code was misplaced in a patch called "sftplogging".
45
46 So, I see it in a similar way as vapier does:
47 Get the OpenSSH developers to include such functionality -OR-
48 produce a patch that doesn't touch upstream SFTP logging but
49 just adds umask+chmod/chgrp control features, maybe we can
50 think about adding such a small patch as long as upstream does
51 not provide such features. Just an idea.
52 --
53 Regards,
54 Wolfram Schlich <wschlich@g.o>
55 Gentoo Linux * http://dev.gentoo.org/~wschlich/
56 --
57 gentoo-dev@g.o mailing list