Milestone for the ssh install rework you asked for on #10, on top of the 0.1.0 work already on main.
What is on next: one squashed commit. keyfunc ssh install runs no command on the host: it reads .ssh/authorized_keys over sftp, appends the derived key locally only when an identical line is absent, uploads the result beside the file with mode 0600 and renames it over the original. Absence is taken only from sftp's own message about that path; any other failure prints what sftp said, writes nothing and exits 1. Three full review rounds; the first two caught a real defect (an unreadable file treated as absent) that is now closed.
What you need to know to merge or tag:
sftp batch mode disables password prompts, so install needs a key or an agent for its connections; the README says so.
A ~/.ssh the owner cannot enter still reads as a host with no file and gets replaced; sftp could tell the two apart and this change does not. The README states it; a follow-up is filed on the tracker.
Options after -- go to sftp unchanged, so the port flag is -P.
Waiting on you: merge, then tag 0.1.0 on main.
Model: fable-5-1
Milestone for the `ssh install` rework you asked for on https://git.eeqj.de/sneak/keyfunc/issues/10, on top of the 0.1.0 work already on `main`.
What is on `next`: one squashed commit. `keyfunc ssh install` runs no command on the host: it reads `.ssh/authorized_keys` over sftp, appends the derived key locally only when an identical line is absent, uploads the result beside the file with mode 0600 and renames it over the original. Absence is taken only from sftp's own message about that path; any other failure prints what sftp said, writes nothing and exits 1. Three full review rounds; the first two caught a real defect (an unreadable file treated as absent) that is now closed.
What you need to know to merge or tag:
- sftp batch mode disables password prompts, so `install` needs a key or an agent for its connections; the README says so.
- A `~/.ssh` the owner cannot enter still reads as a host with no file and gets replaced; sftp could tell the two apart and this change does not. The README states it; a follow-up is filed on the tracker.
- Options after `--` go to sftp unchanged, so the port flag is `-P`.
Waiting on you: merge, then tag `0.1.0` on `main`.
Model: fable-5-1
clawbot
self-assigned this 2026-09-08 08:20:19 +02:00
ssh install no longer runs a command on the host. It reads .ssh/authorized_keys over sftp, takes the empty reading only from sftp's own message about that path, appends the derived key locally when it is not already present, uploads the result beside the file with mode 0600 and renames it over the original. Any other failure prints what sftp said, writes nothing and exits 1. sftp batch mode disables password prompts, so a key or agent is required; a directory the owner cannot enter reads as a host with no file, which README.md states.
Model: opus-5 (implementation); fable-5-1 (landing)
ssh install no longer runs a command on the host. It reads .ssh/authorized_keys over sftp, takes the empty reading only from sftp's own message about that path, appends the derived key locally when it is not already present, uploads the result beside the file with mode 0600 and renames it over the original. Any other failure prints what sftp said, writes nothing and exits 1. sftp batch mode disables password prompts, so a key or agent is required; a directory the owner cannot enter reads as a host with no file, which README.md states.
Model: opus-5 (implementation); fable-5-1 (landing)
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Milestone for the
ssh installrework you asked for on #10, on top of the 0.1.0 work already onmain.What is on
next: one squashed commit.keyfunc ssh installruns no command on the host: it reads.ssh/authorized_keysover sftp, appends the derived key locally only when an identical line is absent, uploads the result beside the file with mode 0600 and renames it over the original. Absence is taken only from sftp's own message about that path; any other failure prints what sftp said, writes nothing and exits 1. Three full review rounds; the first two caught a real defect (an unreadable file treated as absent) that is now closed.What you need to know to merge or tag:
installneeds a key or an agent for its connections; the README says so.~/.sshthe owner cannot enter still reads as a host with no file and gets replaced; sftp could tell the two apart and this change does not. The README states it; a follow-up is filed on the tracker.--go to sftp unchanged, so the port flag is-P.Waiting on you: merge, then tag
0.1.0onmain.Model: fable-5-1
batch mode is thus unacceptable for this purpose if the user can’t enter a password.
Pull request closed