Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 929191 - net-misc/openssh-9.6: ObscureKeystrokeTiming make remote X11 apps very slow
Summary: net-misc/openssh-9.6: ObscureKeystrokeTiming make remote X11 apps very slow
Status: UNCONFIRMED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-04-11 16:46 UTC by Joakim Tjernlund
Modified: 2024-04-12 16:23 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Joakim Tjernlund 2024-04-11 16:46:24 UTC
In above openssh ObscureKeystroke default to on and that make apps like emacs/xterm very slow to start(take 5-7 secs before window appear) over an remote
ssh connection with X11 forwarding.
Even kill-line in emacs takes seconds to complete 

Setting "ObscureKeystrokeTiming no" makes these normal again.

I suggest Gentoo makes "ObscureKeystrokeTiming no" default or at least
warn somehow about this.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2024-04-11 16:54:01 UTC
We're not going to disable a security mitigation by default.

Have you tried speaking to upstream to see if they have any input on it?
Comment 2 Joakim Tjernlund 2024-04-11 20:27:27 UTC
(In reply to Sam James from comment #1)
> We're not going to disable a security mitigation by default.
> 
> Have you tried speaking to upstream to see if they have any input on it?

I have not, they think this is a good feature or they would not have enabled it
by default.
Comment 3 Joakim Tjernlund 2024-04-11 20:28:38 UTC
(In reply to Joakim Tjernlund from comment #2)
> (In reply to Sam James from comment #1)
> > We're not going to disable a security mitigation by default.
> > 
> > Have you tried speaking to upstream to see if they have any input on it?
> 
> I have not, they think this is a good feature or they would not have enabled
> it
> by default.

Ir maybe it is just my systems that have some odd tweak somewhere that makes
this very slow.
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2024-04-11 20:49:40 UTC
(In reply to Joakim Tjernlund from comment #2)
> (In reply to Sam James from comment #1)
> > We're not going to disable a security mitigation by default.
> > 
> > Have you tried speaking to upstream to see if they have any input on it?
> 
> I have not, they think this is a good feature or they would not have enabled
> it
> by default.

Or maybe they're not aware of the impact on X11 forwarding? Just speak to them? At worst, they say it's an unfortunate but unavoidable side-effect.