README child-mnemonic vector and host-key note; ssh install refuses a ~/.ssh it cannot enter (closes #51)
check / check (push) Successful in 2m4s
check / check (push) Successful in 2m4s
The README now gives the child mnemonic keyfunc prints for the abandon ... about test mnemonic at index 0, checked by the README vectors test; the BIP-85 specification vector stays, marked as starting from a master key keyfunc cannot take. It also says ssh install needs the host key in known_hosts already, and how to get round that. ssh install now also lists ~/.ssh/. on its first connection and refuses, before any upload, a ~/.ssh it can read but not enter, which sftp shows as empty; a file where ~/.ssh belongs is refused the same way. Model: opus-5-5 Co-authored-by: clawbot <sneak+clawbot@sneak.cloud>
This commit was merged in pull request #55.
This commit is contained in:
@@ -163,21 +163,23 @@ Adds the `pub` line to `~/.ssh/authorized_keys` on the host. No command is run
|
||||
on the host: the file is fetched, changed here, and written back with the system
|
||||
`sftp` client in batch mode.
|
||||
|
||||
The first connection lists `~/.ssh` and then fetches `~/.ssh/authorized_keys`
|
||||
from it. The file reads as empty in two cases only: `sftp` reported `~/.ssh`
|
||||
itself as not being there, or the listing came up and the file was not in it.
|
||||
Any other outcome of that connection fails the run — a `~/.ssh` that is there
|
||||
but cannot be entered, an `authorized_keys` that is there but cannot be read, or
|
||||
a connection that did not come up — and the tool prints what `sftp` said and
|
||||
exits with status 1 without writing anything, rather than put a file back
|
||||
holding the new key alone. The listing is what tells a missing directory from
|
||||
one shut to the user, which `sftp` reports on a fetch the same way; the wording
|
||||
of a missing file elsewhere does not count either, since `ssh` writes
|
||||
`No such file or directory` about an `-i` it cannot find on a session that then
|
||||
authenticates through the agent. If an identical line is already in the file,
|
||||
the tool prints `already present` and connects no further. Otherwise the line is
|
||||
added (after a newline, if the file did not end with one) and a second
|
||||
connection:
|
||||
The first connection lists `~/.ssh`, then `~/.ssh/.`, and then fetches
|
||||
`~/.ssh/authorized_keys`. The file reads as empty in two cases only: `sftp`
|
||||
reported `~/.ssh` itself as not being there, or both listings came up and the
|
||||
file was not found. Any other outcome of that connection fails the run — a
|
||||
`~/.ssh` that is there but cannot be read or entered, an `authorized_keys` that
|
||||
is there but cannot be read, or a connection that did not come up — and the tool
|
||||
prints what `sftp` said and exits with status 1 without writing anything, rather
|
||||
than put a file back holding the new key alone. The listings are what tell a
|
||||
missing directory from one shut to the user, which `sftp` reports on a fetch the
|
||||
same way: one that cannot be read fails the first listing, and one that can be
|
||||
read but not entered fails the second, after which the tool says that `~/.ssh`
|
||||
cannot be entered. The wording of a missing file elsewhere does not count
|
||||
either, since `ssh` writes `No such file or directory` about an `-i` it cannot
|
||||
find on a session that then authenticates through the agent. If an identical
|
||||
line is already in the file, the tool prints `already present` and connects no
|
||||
further. Otherwise the line is added (after a newline, if the file did not end
|
||||
with one) and a second connection:
|
||||
|
||||
- makes `~/.ssh` and sets it to mode `0700`, but only when the first connection
|
||||
found none; a `~/.ssh` that was already there keeps the mode it had;
|
||||
@@ -200,7 +202,10 @@ error, so the tool's own standard output is only `added` or `already present`.
|
||||
Anything after `--` is passed to `sftp` unchanged, which is where the port goes
|
||||
(`-P 2222`, not `-p`). How the connection authenticates is up to the user's
|
||||
normal `ssh` setup, except that batch mode does not prompt: a key or an agent
|
||||
has to do it, not a typed password.
|
||||
has to do it, not a typed password. Nor does it ask whether to trust a host key
|
||||
it has not seen, so the host has to be in `known_hosts` already, or the run
|
||||
fails with `Host key verification failed`. Connect to the host once with `ssh`
|
||||
first, or pass `-o StrictHostKeyChecking=accept-new` after `--`.
|
||||
|
||||
### `keyfunc ssh to <host> [ssh arguments...]`
|
||||
|
||||
@@ -261,10 +266,18 @@ A child mnemonic is a full mnemonic in its own right: it can seed another
|
||||
`keyfunc`, another wallet, or `secret`, and it never has to be written down,
|
||||
since it can be derived again.
|
||||
|
||||
Test vector: the child-mnemonic step is checked against BIP-85's own published
|
||||
vectors, which derive from the specification's master key
|
||||
`xprv9s21ZrQH143K2LBWUUQRFXhucrQqBpKdRRxNVq2zBqsx8HVqFk2uYo8kmbaLLHRdqtQpUm98uKfu3vca1LqdGhUtyoFnCNkfmXRyPXLjbKb`.
|
||||
At key index 0 the 12-word English child mnemonic is:
|
||||
Test vector, mnemonic
|
||||
`abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon about`:
|
||||
|
||||
```
|
||||
index 0: prosper short ramp prepare exchange stove life snack client enough purpose fold
|
||||
```
|
||||
|
||||
The child-mnemonic step is also checked against BIP-85's own published vectors.
|
||||
Those start from the specification's master key
|
||||
`xprv9s21ZrQH143K2LBWUUQRFXhucrQqBpKdRRxNVq2zBqsx8HVqFk2uYo8kmbaLLHRdqtQpUm98uKfu3vca1LqdGhUtyoFnCNkfmXRyPXLjbKb`
|
||||
rather than from a mnemonic, so they cannot be given to `keyfunc`; at key index
|
||||
0 the 12-word English child mnemonic of that key is:
|
||||
|
||||
```
|
||||
girl mad pet galaxy egg matter matrix prison refuse sense ordinary nose
|
||||
|
||||
Reference in New Issue
Block a user