Bug#1103418: openssh-server irregularly crashing since 10.0p1 upgrade
- To: Michel Casabona <michel.casabona@free.fr>
- Cc: 1103418@bugs.debian.org, Liam Stitt <stittl@cuug.ab.ca>, Lucio Crusca <lucio@sulweb.org>
- Subject: Bug#1103418: openssh-server irregularly crashing since 10.0p1 upgrade
- From: Colin Watson <cjwatson@debian.org>
- Date: Wed, 7 May 2025 15:58:51 +0100
- Message-id: <[🔎] aBt1K569HVOIttp_@riva.ucam.org>
- Reply-to: Colin Watson <cjwatson@debian.org>, 1103418@bugs.debian.org
- In-reply-to: <e7561202-302b-4c6c-b86e-ccbe526b3c74@free.fr>
- References: <aA60qrUJSTpf1cHx@riva.ucam.org> <174488545822.190650.3770948559333575292.reportbug@solid-state-entity.juffo-wup.net> <153a5beb-b733-4897-9615-e5068455c26f@free.fr> <aBIMuJuMJkDoyy5r@riva.ucam.org> <f8fa0b16-04af-4189-a26e-e3272688fa38@free.fr> <aBIcKbAZjFrFKg01@riva.ucam.org> <8d9b5cc3-5f6a-4d03-ba5c-409679dda6ea@free.fr> <aBKNgcjmTtnhoLRR@riva.ucam.org> <aBKc9VNADgqwj0eL@riva.ucam.org> <e7561202-302b-4c6c-b86e-ccbe526b3c74@free.fr> <174488545822.190650.3770948559333575292.reportbug@solid-state-entity.juffo-wup.net>
Control: forwarded -1 https://bugzilla.mindrot.org/show_bug.cgi?id=3822
On Tue, May 06, 2025 at 07:28:59PM +0200, Michel Casabona wrote:
Sorry for the delay. Here are the results from some testing.
It seems that the problem may be related to pam_ecryptfs, after all
[...]
* To exclude any local things and remnants from years of experiments
on my desktop machine, I've setup new virtual machines
(using libvirt / virt-manager, AMD64, UEFI if that matters) as follows:
- install trixie with the Debian installer Trixie Alpha 1 (netinst)
- no desktop, only ssh server
- add a few convenience packages (sudo mc vim)
- add debugging packages (systemd-coredump, gdb, debuginfod, valgrind)
at this point ssh seems to work correctly
- add ecryptfs-utils (+ cryptsetup / rsync)
then ssh-session starts to crash most of the time
Thanks, this was extremely helpful! I was finally able to reproduce
this bug, and tracked it down to the --with-linux-memlock-onfault
configure option. I forwarded this to
https://bugzilla.mindrot.org/show_bug.cgi?id=3822.
I'm going to disable this option again for now, as it's a recent
addition and isn't security-critical.
--
Colin Watson (he/him) [cjwatson@debian.org]
Reply to: