From a0476a7e9c169e7c13902cbaba6ce5c7c786fc41 Mon Sep 17 00:00:00 2001 From: Yasin Demir Date: Wed, 16 Sep 2026 06:23:10 +0300 Subject: [PATCH] Keep sshd_config.d drop-ins working and resolve sftp-server per distro The wholesale sshd_config replacement is intentional, but two side effects were not: - The template had no Include line, so reinstalling dropped the `Include /etc/ssh/sshd_config.d/*.conf` that update_ssh_banners_config appends, leaving the per-user banner drop-in on disk but inert. Add it as the last line: OpenSSH uses the first value it obtains for a keyword, so the template's own settings still take precedence over any drop-in and only the Match blocks become effective. - The template hardcoded the Debian path for sftp-server. sshd -t does not verify that the binary exists, so SFTP broke silently on distributions that ship it elsewhere. install.sh now probes the common locations and rewrites the Subsystem line. Co-Authored-By: Claude Opus 5 (1M context) --- install.sh | 21 +++++++++++++++++++++ ssh | 5 +++++ 2 files changed, 26 insertions(+) diff --git a/install.sh b/install.sh index b9f6fbd..698566d 100644 --- a/install.sh +++ b/install.sh @@ -99,6 +99,27 @@ cp "$SSHD_CONFIG" "$BACKUP" cp "$SCRIPT_DIR/ssh" "$SSHD_CONFIG" chmod 600 "$SSHD_CONFIG" +# The template carries the Debian path for sftp-server. sshd -t does not check +# that the binary exists, so on other distributions SFTP would silently break. +SFTP_SERVER="" +for candidate in \ + /usr/lib/openssh/sftp-server \ + /usr/libexec/openssh/sftp-server \ + /usr/lib/ssh/sftp-server \ + /usr/libexec/sftp-server +do + if [[ -x "$candidate" ]]; then + SFTP_SERVER="$candidate" + break + fi +done +if [[ -n "$SFTP_SERVER" ]]; then + sed -i "s|^Subsystem sftp .*|Subsystem sftp $SFTP_SERVER|" "$SSHD_CONFIG" + echo "Using sftp-server: $SFTP_SERVER" +else + echo "WARNING: no sftp-server binary found; leaving the Subsystem line unchanged." +fi + # Validate SSH config (silent) if ! sshd -t 2>/dev/null; then echo "ERROR: SSH configuration is invalid!" diff --git a/ssh b/ssh index d1abcad..a79bc05 100644 --- a/ssh +++ b/ssh @@ -28,3 +28,8 @@ AcceptEnv LANG LC_* Subsystem sftp /usr/lib/openssh/sftp-server UsePAM yes Banner /etc/bannerssh + +# Kept last on purpose. OpenSSH uses the first value it obtains for a keyword, +# so everything above still wins over any drop-in; this only lets the Match +# blocks that menu.sh writes to sshd_config.d (per-user banners) take effect. +Include /etc/ssh/sshd_config.d/*.conf