[arch-dev-public] Urgent news item: sshd needs restarting after upgrading to openssh-8.2p1

Eli Schwartz eschwartz at archlinux.org
Mon Feb 17 01:03:16 UTC 2020


On 2/16/20 7:47 PM, Gaetan Bisson via arch-dev-public wrote:
> And I also regret not being able to diagnose what the exact problem is
> just now.

As was pointed out in the bug:
https://bugs.archlinux.org/task/65517#comment186483

ssh errors with:
kex_exchange_identification: read: Connection reset by peer

sshd logs the error:
fatal: recv_rexec_state: buffer error: incomplete message

It's pretty plausible that this commit is simply incompatible with the
previous version of sshd, therefore it could not reexec:
https://github.com/openssh/openssh-portable/commit/c2bd7f74b0e0f3a3ee9d19ac549e6ba89013abaf

So this is "expected" behavior. There's no way to upgrade this without
triggering the need for a restart. All consumers of openssh on any
operating system will need to restart sshd, possibly via maintenance
scripts provided by the distro.

-- 
Eli Schwartz
Bug Wrangler and Trusted User

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 1601 bytes
Desc: OpenPGP digital signature
URL: <https://lists.archlinux.org/pipermail/arch-dev-public/attachments/20200216/96fb808f/attachment-0001.sig>


More information about the arch-dev-public mailing list