Keep the mnemonic out of the ssh and sftp children (closes #16)
check / check (push) Failing after 1s
check / check (push) Failing after 1s
ssh to and ssh install started the system ssh and sftp with the tool's whole environment, so a mnemonic taken from KEYFUNC_MNEMONIC stayed in the child's environment for as long as it ran, readable by the same user and forwardable to the host through a SendEnv line. ssh to keeps the private key inside the tool; the mnemonic must not leave it either. A shared helper in the ssh cli package hands both children the tool's environment with KEYFUNC_MNEMONIC and KEYFUNC_MNEMONIC_COMMAND removed. The mnemonic command itself still runs with the full environment. The stand-in ssh and sftp in the tests now record their environment, and two tests show neither variable reaches them while another one does. Model: opus-4-8
This commit is contained in:
@@ -54,6 +54,11 @@ If none of these is available and standard input is not a terminal, the tool
|
||||
refuses and exits with status 1. A mnemonic that fails the BIP-39 checksum is
|
||||
refused with a message saying so.
|
||||
|
||||
`KEYFUNC_MNEMONIC` and `KEYFUNC_MNEMONIC_COMMAND` are removed from the
|
||||
environment before the system `ssh` (`keyfunc ssh to`) and `sftp`
|
||||
(`keyfunc ssh install`) are started, so the mnemonic is never handed on to
|
||||
them.
|
||||
|
||||
Every command takes `--index` / `-n` and `--mnemonic-command`, and has `--help`.
|
||||
`keyfunc --version` prints the version. `make build` stamps it; a binary
|
||||
installed with `go install` reports the module version instead.
|
||||
|
||||
Reference in New Issue
Block a user