Skip to content

vfs/sftpfs: Fix keyboard-interactive auth to FreeBSD OpenSSH server with UsePAM - #5160

Closed
tuffnatty wants to merge 1 commit into
MidnightCommander:masterfrom
tuffnatty:sftp-fix-keyboard-interactive-pam-prompt
Closed

tuffnatty wants to merge 1 commit into
MidnightCommander:masterfrom
tuffnatty:sftp-fix-keyboard-interactive-pam-prompt

Conversation

@tuffnatty

@tuffnatty tuffnatty commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Proposed changes

I tried to use the SFTP vfs. I couldn't connect to any of my SFTP servers. First of all, one has to add an entry to ~/.ssh/config to be able to use publickey auth, and it's not documented anywhere (added #5161). After publickey auth fails, MC asks for a password. On a recent FreeBSD with default sshd settings, PasswordAuthentication is disabled, KbdInteractiveAuthentication is enabled, and UsePAM is enabled. So the password authentication fails, and MC starts performing keyboard-interactive auth. The first thing it does is potentially dereference a NULL pointer by passing it to strncmp for an unknown purpose. Then, it checks if one of the prompts passed by keyboard-interactive auth is "Password: " and answers to that. Unfortunately, in the described configuration the prompt string looks like "Password for user@hostname:", so auth fails.

This patch is a quick fix to make the default configuration work. However, the whole procedure is quite fragile, as the password prompt may be customized by user in PAM configuration.

I think the symptoms are very much alike the problem report #4585. Although it's missing details, I believe it would be hard to collect them without gdb at hand, as there is nothing special in this configuration and it should "just work".

Checklist

  • I have referenced the issue(s) resolved by this PR (if any)
  • I have signed-off my contribution with git commit --amend -s
  • Lint and unit tests pass locally with my changes (make indent && make check)
  • I have added tests that prove my fix is effective or that my feature works
  • I have added the necessary documentation (if appropriate)

…ith UsePAM

Signed-off-by: Phil Krylov <phil@krylov.eu>
@github-actions github-actions Bot added needs triage Needs triage by maintainers prio: medium Has the potential to affect progress labels Sep 19, 2026
@github-actions github-actions Bot added this to the Future Releases milestone Sep 19, 2026
@ossilator

Copy link
Copy Markdown
Contributor

yes, this looks incredibly fragile.

if mc is using a pty to talk to ssh, then password prompts could be detected by querying the tty state - echo off means password.

the second though is: given that this is using libssh2, isn't there a more structured way to obtain the prompt and know the type of it?

the last though would be: why try so hard to interpret things, rather than just present them verbatim, like pam and sasl ask for (though these do tell the user what type of prompt it is)?

the commit message is again a bit on the short side. always try to answer the question "why?", in all variations that seem relevant.

@tuffnatty

Copy link
Copy Markdown
Contributor Author

Probably the right way to implement this would be not asking the user for a password in advance and presenting them the literal prompts from the remote side. It could enable various 2FA schemes as a side effect. Overall, it would require more research on the matter and potentially more disrupting changes, while this patch is a quick bug fix which could probably make it into the next release.

@tuffnatty

Copy link
Copy Markdown
Contributor Author

Closing in favour of #5162.

@tuffnatty tuffnatty closed this Sep 24, 2026
@github-actions github-actions Bot removed this from the Future Releases milestone Sep 24, 2026
@zyv zyv added area: vfs Virtual File System support and removed needs triage Needs triage by maintainers labels Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: vfs Virtual File System support prio: medium Has the potential to affect progress

Development

Successfully merging this pull request may close these issues.

ftp /sftp does not work

3 participants