This new option allows to disable leak detective to reduce the runtime
during development. Either only for the command line (swanctl, pki etc.)
or optionally also for the daemon(s).
Disabling leak detective only for the CLI tools already brings a
considerable reduction in runtime (from 48m to 38m on my dev host) as
there are many such calls in the post-test stage. Any leaks in those
tools are also a lot less of an issue than leaks in the daemon. So using
this during development should be fine as long as a full test run is done
regularly (in particular before releases). Disabling leak detective
completely further reduces the runtime (to 30m on my dev host). But that
should probably only be used for functional regression tests after
verifying new code didn't introduce new leaks.
This also fixes the service script which is used for charon-tkm since
16fcdb460a ("charon-tkm: Don't use starter/stroke with charon-tkm anymore").
18 lines
405 B
Plaintext
18 lines
405 B
Plaintext
Port 22
|
|
Protocol 2
|
|
Ciphers aes128-gcm@openssh.com
|
|
KexAlgorithms curve25519-sha256
|
|
HostKey /etc/ssh/ssh_host_rsa_key
|
|
HostKey /etc/ssh/ssh_host_ecdsa_key
|
|
PermitRootLogin yes
|
|
StrictModes no
|
|
PubkeyAuthentication no
|
|
PermitEmptyPasswords yes
|
|
PrintMotd no
|
|
PrintLastLog no
|
|
UsePAM no
|
|
AcceptEnv LANG LC_*
|
|
AcceptEnv LEAK_DETECTIVE_*
|
|
SetEnv LEAK_DETECTIVE_IGNORE_UNKNOWN=1
|
|
Subsystem sftp /usr/lib/openssh/sftp-server
|