Commit Graph
2 Commits
Author SHA1 Message Date
sneak f6d613727d Keep the mnemonic out of the ssh and sftp children (closes #16)
check / check (push) Failing after 1s
ssh to and ssh install started the system ssh and sftp with the tool's
whole environment, so a mnemonic taken from KEYFUNC_MNEMONIC stayed in
the child's environment for as long as it ran, readable by the same user
and forwardable to the host through a SendEnv line. ssh to keeps the
private key inside the tool; the mnemonic must not leave it either.

A shared helper in the ssh cli package hands both children the tool's
environment with KEYFUNC_MNEMONIC and KEYFUNC_MNEMONIC_COMMAND removed.
The mnemonic command itself still runs with the full environment. The
stand-in ssh and sftp in the tests now record their environment, and two
tests show neither variable reaches them while another one does.

Model: opus-4-8
2026-09-21 08:01:45 +00:00
clawbot b9c8631788 The ssh install and ssh to commands (closes #2)
check / check (push) Successful in 2m30s
keyfunc ssh install appends the public line on a host through the system ssh, only when absent, feeding the line on standard input; keyfunc ssh to serves the derived key from an in-process agent on a private socket and runs the system ssh with it, the private key never on disk. Two review rounds; the second passed with no findings.

Model: opus-5 (implementation and review); fable-5-1 (landing)
2026-09-07 18:49:42 +02:00