ssh install refuses stray arguments before -- and a symlinked authorized_keys (closes #61)
check / check (push) Failing after 2s

Anything but the host before --, or a second argument when there is no --, used to reach sftp in front of the host; it is now refused before the mnemonic is read or any connection is made. That includes "install -- host", which names no host before --.

The first listing of ~/.ssh is now a long one, ls -n, which the client formats itself whatever the server, so an authorized_keys that is a symlink shows as one. It is refused before any upload, since the rename would have replaced the link and left the file it points at without the key. The README says so.

Model: opus-5-5
This commit is contained in:
2026-10-04 15:58:13 +00:00
parent 5b36e42e4d
commit 11a6050ac7
4 changed files with 128 additions and 11 deletions
+7 -4
View File
@@ -177,10 +177,13 @@ same way: one that cannot be read fails the first listing, and one that can be
read but not entered fails the second, after which the tool says that `~/.ssh`
cannot be entered. The wording of a missing file elsewhere does not count
either, since `ssh` writes `No such file or directory` about an `-i` it cannot
find on a session that then authenticates through the agent. If an identical
line is already in the file, the tool prints `already present` and connects no
further. Otherwise the line is added (after a newline, if the file did not end
with one) and a second connection:
find on a session that then authenticates through the agent. An
`authorized_keys` that the first listing shows to be a symlink is refused and
left as it is, since the rename below would replace the link itself and the file
it points at would never get the key. If an identical line is already in the
file, the tool prints `already present` and connects no further. Otherwise the
line is added (after a newline, if the file did not end with one) and a second
connection:
- makes `~/.ssh` and sets it to mode `0700`, but only when the first connection
found none; a `~/.ssh` that was already there keeps the mode it had;