The ssh install and ssh to commands (closes #2)
All checks were successful
check / check (push) Successful in 21s

install runs the system ssh and hands the host a short shell script to
run, with the public key line on the connection's standard input rather
than on a command line, where anyone else on the host could read it out
of the process list. The script makes ~/.ssh and authorized_keys if
they are missing, adds the line unless the same line is already there,
and says which of the two it did.

to serves the key from an agent inside the tool, on a unix socket in a
temporary directory only its owner can enter, and points ssh at it with
-o IdentityAgent. The socket and directory go when the command ends and
the private key is never written to disk. Only this command hands back
the status ssh ended with instead of ending with status 1.

The tests put a stand-in ssh on the path: for install it runs the
script the tool sends against a directory standing in for the host's
home directory, so the file, the modes and the second run that changes
nothing are all watched happening.

Model: opus-5
This commit is contained in:
2026-09-07 15:52:12 +00:00
parent 279cba6bcf
commit 05d67708ec
7 changed files with 612 additions and 12 deletions

View File

@@ -2,6 +2,7 @@
package cli
import (
"errors"
"fmt"
"os"
@@ -35,14 +36,22 @@ func Root() *cobra.Command {
}
// Main runs the tool and returns the status the process should exit
// with.
// with. An error ends the tool with status 1, except when it carries a
// status of its own, which "ssh to" uses to hand on the status ssh
// ended with. ssh has already said whatever it had to say in that
// case, so nothing more is printed.
func Main() int {
err := Root().Execute()
if err != nil {
fmt.Fprintln(os.Stderr, "keyfunc: "+err.Error())
return 1
if err == nil {
return 0
}
return 0
var passed ssh.StatusError
if errors.As(err, &passed) {
return passed.Status
}
fmt.Fprintln(os.Stderr, "keyfunc: "+err.Error())
return 1
}