README child-mnemonic vector and host-key note; ssh install refuses a ~/.ssh it cannot enter (closes #51) #55

Merged
clawbot merged 1 commits from issue-51-readme-vectors-ssh-dir into next 2026-10-04 07:25:50 +02:00
Collaborator

Implements #51, from findings 4 and 5 of #28 (comment).

  • README, Derived mnemonics: the child mnemonic keyfunc mnemonic prints for the abandon … about mnemonic at index 0, asserted in the README vectors test. The BIP-85 specification vector stays, marked as starting from a master key keyfunc cannot take.
  • README, keyfunc ssh install: the host key must already be in known_hosts; connect once with ssh, or pass -o StrictHostKeyChecking=accept-new after --.
  • ssh install: the first connection also lists ~/.ssh/.. A ~/.ssh that can be read but not entered lists as empty (OpenSSH's server drops every name it cannot look up), so its authorized_keys read as missing. Listing ~/.ssh/. fails for it, and the tool now refuses there, before any upload, saying ~/.ssh cannot be entered.

Not visible in the diff: a file where ~/.ssh belongs is now refused the same way, since sftp sees it exactly as such a directory. The test that used one to make the put fail now uses a ~/.ssh of mode 500, which the sftp stand-in reads off the mode, as it already does for mode 000.

  • Judgement call: the refusal is tested with a file where ~/.ssh belongs, not a directory of mode 400, which the stand-in cannot tell from an enterable one when the tests run as root.
  • Partially verified: the sftp wordings for a ~/.ssh of mode 400 and the unknown-host-key failure were seen by hand against OpenSSH's own sftp-server and a real host; the tests only imitate them.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/keyfunc/issues/51, from findings 4 and 5 of https://git.eeqj.de/sneak/keyfunc/pulls/28#issuecomment-120217. - README, Derived mnemonics: the child mnemonic `keyfunc mnemonic` prints for the `abandon … about` mnemonic at index 0, asserted in the README vectors test. The BIP-85 specification vector stays, marked as starting from a master key `keyfunc` cannot take. - README, `keyfunc ssh install`: the host key must already be in `known_hosts`; connect once with `ssh`, or pass `-o StrictHostKeyChecking=accept-new` after `--`. - `ssh install`: the first connection also lists `~/.ssh/.`. A `~/.ssh` that can be read but not entered lists as empty (OpenSSH's server drops every name it cannot look up), so its `authorized_keys` read as missing. Listing `~/.ssh/.` fails for it, and the tool now refuses there, before any upload, saying `~/.ssh` cannot be entered. Not visible in the diff: a file where `~/.ssh` belongs is now refused the same way, since `sftp` sees it exactly as such a directory. The test that used one to make the put fail now uses a `~/.ssh` of mode 500, which the `sftp` stand-in reads off the mode, as it already does for mode 000. - Judgement call: the refusal is tested with a file where `~/.ssh` belongs, not a directory of mode 400, which the stand-in cannot tell from an enterable one when the tests run as root. - Partially verified: the `sftp` wordings for a `~/.ssh` of mode 400 and the unknown-host-key failure were seen by hand against OpenSSH's own `sftp-server` and a real host; the tests only imitate them. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 06:59:25 +02:00
clawbot self-assigned this 2026-10-04 06:59:25 +02:00
clawbot added 1 commit 2026-10-04 06:59:26 +02:00
The README gains the child mnemonic that `keyfunc mnemonic` prints for
the abandon ... about mnemonic at index 0, asserted by the README
vectors test, and says that `ssh install` needs the host key already
known, with the two ways round it.

`ssh install` now also lists `.ssh/.` before fetching. A `.ssh` that can
be read but not entered lists as empty, so the fetch read it as holding
no file and tried an upload that could only fail. The listing of
`.ssh/.` fails instead, and the tool refuses before any upload, saying
the directory cannot be entered. The test that failed the put with a
file where `.ssh` belongs now uses a `.ssh` of mode 500.

Model: opus-5-5
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit d4fbcbc83d into next 2026-10-04 07:25:50 +02:00
clawbot deleted branch issue-51-readme-vectors-ssh-dir 2026-10-04 07:25:51 +02:00
Sign in to join this conversation.