ssh install refuses stray arguments before -- and a symlinked authorized_keys #61

Closed
opened 2026-10-04 17:42:56 +02:00 by clawbot · 1 comment
Collaborator

From the third whole-branch review of #28 (#28 (comment)), findings 1 and 2:

  1. ssh install gives sftp every word after the host, whether or not it follows -- (internal/cli/ssh/install.go, install: add(cmd, args[0], args[1:], line)). keyfunc ssh install alice@host frank@host puts frank@host in front of the host in sftp's arguments, so the key is installed for frank@host and the tool prints added; keyfunc ssh install host 2222 connects to a host called 2222. The README documents only install <[user@]host> [-- sftp options...].
  2. ssh install turns a symlinked ~/.ssh/authorized_keys into a regular file (upload): the rename replaces the link itself, so the host ends up with a regular file holding the old lines plus the key, and the file the link pointed at never gets the key.

Work, on a branch cut from next, PR to next:

  • An argument between the host and --, or any second argument when there is no --, is refused before any connection (cobra's ArgsLenAtDash), with a message that says options for sftp go after --.
  • A ~/.ssh/authorized_keys on the host that is a symlink is refused before any upload, with a message that says so; the listing the tool already makes of ~/.ssh shows it. The README, under keyfunc ssh install, says so in one sentence.

Definition of done

  • Tests cover both refusals, and that nothing is uploaded in either case.
  • Checked by hand against a throwaway sshd container: a symlinked authorized_keys is refused and left as it was.
  • make check passes.

Model: opus-5-5

From the third whole-branch review of https://git.eeqj.de/sneak/keyfunc/pulls/28 (https://git.eeqj.de/sneak/keyfunc/pulls/28#issuecomment-124435), findings 1 and 2: 1. `ssh install` gives `sftp` every word after the host, whether or not it follows `--` (`internal/cli/ssh/install.go`, `install`: `add(cmd, args[0], args[1:], line)`). `keyfunc ssh install alice@host frank@host` puts `frank@host` in front of the host in `sftp`'s arguments, so the key is installed for `frank@host` and the tool prints `added`; `keyfunc ssh install host 2222` connects to a host called `2222`. The README documents only `install <[user@]host> [-- sftp options...]`. 2. `ssh install` turns a symlinked `~/.ssh/authorized_keys` into a regular file (`upload`): the rename replaces the link itself, so the host ends up with a regular file holding the old lines plus the key, and the file the link pointed at never gets the key. Work, on a branch cut from `next`, PR to `next`: - An argument between the host and `--`, or any second argument when there is no `--`, is refused before any connection (cobra's `ArgsLenAtDash`), with a message that says options for `sftp` go after `--`. - A `~/.ssh/authorized_keys` on the host that is a symlink is refused before any upload, with a message that says so; the listing the tool already makes of `~/.ssh` shows it. The README, under `keyfunc ssh install`, says so in one sentence. ## Definition of done - Tests cover both refusals, and that nothing is uploaded in either case. - Checked by hand against a throwaway `sshd` container: a symlinked `authorized_keys` is refused and left as it was. - `make check` passes. Model: opus-5-5
clawbot self-assigned this 2026-10-04 17:42:56 +02:00
Author
Collaborator

Built in #62: ssh install refuses anything but the host before -- before any connection, and refuses an authorized_keys that the first listing of ~/.ssh (now ls -n) shows to be a symlink, before any upload.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/keyfunc/pulls/62: `ssh install` refuses anything but the host before `--` before any connection, and refuses an `authorized_keys` that the first listing of `~/.ssh` (now `ls -n`) shows to be a symlink, before any upload. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/keyfunc#61