20261001
- Installed daemon signal handlers with explicit
sigaction()semantics. - Rejected invalid or excess subsystem registrations at startup.
- Preserved the initial SSH session identifier length across rekeys that switch between key-exchange hash algorithms of different lengths.
- Sent SSH disconnect messages for unavailable authentication services and unexpected connection-layer messages received before authentication.
- Fixed SSH channel packet size handling and removed the
PACKET_LIMIT/2workaround. - Applied early channel EOF after session startup
- Applied channel close to local state
- Used _SC_OPEN_MAX when closing inherited descriptors
- Fixed user-name bounds checking during authentication
- Removed root directory permission checks when validating the path to
authorized_keys.