The README gains the child mnemonic that `keyfunc mnemonic` prints for
the abandon ... about mnemonic at index 0, asserted by the README
vectors test, and says that `ssh install` needs the host key already
known, with the two ways round it.
`ssh install` now also lists `.ssh/.` before fetching. A `.ssh` that can
be read but not entered lists as empty, so the fetch read it as holding
no file and tried an upload that could only fail. The listing of
`.ssh/.` fails instead, and the tool refuses before any upload, saying
the directory cannot be entered. The test that failed the put with a
file where `.ssh` belongs now uses a `.ssh` of mode 500.
Model: opus-5-5
The first sftp session now lists .ssh before fetching authorized_keys. The file reads as empty only when sftp reports .ssh itself as missing, or the listing succeeded and the file is reported missing. A directory or file that is there but cannot be read fails the run and nothing is written, so no existing authorized_keys is replaced by content that was not built from what was read. An .ssh that already exists keeps its mode; the directory is made and set to 0700 only when none was found. The README describes the rule and states batch mode's limit: a key or an agent must authenticate.
Model: opus-4-8 (implementation); fable-5-1 (summary)
ssh install no longer runs a command on the host. It reads .ssh/authorized_keys over sftp, takes the empty reading only from sftp's own message about that path, appends the derived key locally when it is not already present, uploads the result beside the file with mode 0600 and renames it over the original. Any other failure prints what sftp said, writes nothing and exits 1. sftp batch mode disables password prompts, so a key or agent is required; a directory the owner cannot enter reads as a host with no file, which README.md states.
Model: opus-5 (implementation); fable-5-1 (landing)