README child-mnemonic vector and host-key note; ssh install refuses a ~/.ssh it cannot enter #51

Closed
opened 2026-10-04 06:27:14 +02:00 by clawbot · 1 comment
Collaborator

From the whole-branch review of #28 (#28 (comment)), findings 4 and 5, and one point the reviewer left to the manager:

  • The README's only child-mnemonic vector starts from the BIP-85 specification's master key, which keyfunc cannot take, and no test pins what keyfunc mnemonic prints for a given mnemonic.
  • sftp batch mode refuses a host key not yet in known_hosts, so a first keyfunc ssh install against a new host fails with Host key verification failed; the README names only the key-or-agent limit.
  • When ~/.ssh on the host can be listed but not entered, ssh install treats authorized_keys as missing and makes a second connection; the upload fails and nothing is written, but the error wrongly says a file may be left on the host.

Work, on a branch cut from next, PR to next:

  • README, Derived mnemonics: the child mnemonic for the abandon … about test mnemonic at index 0, next to the SSH and age vectors, with a test that runs the command and asserts it.
  • README, keyfunc ssh install: the host key must already be known, and the way round it (connect once with ssh, or -o StrictHostKeyChecking=accept-new after --).
  • ssh install: a ~/.ssh that cannot be entered is refused before any upload, with an error that says so, the way an unreadable one already is; a test covers it if the existing tests can reach it.

Definition of done

  • The new vector is in the README and asserted by a test; the README states the host-key requirement.
  • ssh install writes nothing and says plainly why when ~/.ssh cannot be entered.
  • make check passes.

Model: opus-5-5

From the whole-branch review of https://git.eeqj.de/sneak/keyfunc/pulls/28 (https://git.eeqj.de/sneak/keyfunc/pulls/28#issuecomment-120217), findings 4 and 5, and one point the reviewer left to the manager: - The README's only child-mnemonic vector starts from the BIP-85 specification's master key, which keyfunc cannot take, and no test pins what `keyfunc mnemonic` prints for a given mnemonic. - `sftp` batch mode refuses a host key not yet in `known_hosts`, so a first `keyfunc ssh install` against a new host fails with `Host key verification failed`; the README names only the key-or-agent limit. - When `~/.ssh` on the host can be listed but not entered, `ssh install` treats `authorized_keys` as missing and makes a second connection; the upload fails and nothing is written, but the error wrongly says a file may be left on the host. Work, on a branch cut from `next`, PR to `next`: - README, Derived mnemonics: the child mnemonic for the `abandon … about` test mnemonic at index 0, next to the SSH and age vectors, with a test that runs the command and asserts it. - README, `keyfunc ssh install`: the host key must already be known, and the way round it (connect once with `ssh`, or `-o StrictHostKeyChecking=accept-new` after `--`). - `ssh install`: a `~/.ssh` that cannot be entered is refused before any upload, with an error that says so, the way an unreadable one already is; a test covers it if the existing tests can reach it. ## Definition of done - The new vector is in the README and asserted by a test; the README states the host-key requirement. - `ssh install` writes nothing and says plainly why when `~/.ssh` cannot be entered. - `make check` passes. Model: opus-5-5
clawbot self-assigned this 2026-10-04 06:27:14 +02:00
Author
Collaborator

Implemented in #55: the README child-mnemonic vector with its test, the host-key note for keyfunc ssh install, and ssh install refusing a ~/.ssh it cannot enter before any upload.

Model: opus-5-5

Implemented in https://git.eeqj.de/sneak/keyfunc/pulls/55: the README child-mnemonic vector with its test, the host-key note for `keyfunc ssh install`, and `ssh install` refusing a `~/.ssh` it cannot enter before any upload. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/keyfunc#51