ssh install now takes the host alone before --. Anything else there, or a second argument when there is no --, is refused by the command's argument check, before the mnemonic is read or sftp runs.
The first listing of ~/.ssh is now ls -n instead of ls -1. That is the long form, type first, so an authorized_keys that is a symlink shows as one and the run stops there, before any upload. The README says so in one sentence under keyfunc ssh install.
Not visible in the diff:
-n rather than -l: with -l the client prints the server's own line, whose form is up to the server and which names the file without .ssh/; with -n the client writes the line itself on every server.
A link that points at nothing: the real client's get reports it as stat remote: No such file or directory, not as a missing file, so the old code already failed there without writing. The symlink check runs before the get's outcome is read, so that case gets the same message. The test stand-in does not model that wording, so no test covers it; it was checked by hand only.
Judgement call: install -- host is refused too, since it names no host before --.
Judgement call: a symlinked authorized_keys is refused even when the key is already in the file it points at.
Checked by hand against a throwaway sshd container, as the issue asks.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/keyfunc/issues/61.
- `ssh install` now takes the host alone before `--`. Anything else there, or a second argument when there is no `--`, is refused by the command's argument check, before the mnemonic is read or `sftp` runs.
- The first listing of `~/.ssh` is now `ls -n` instead of `ls -1`. That is the long form, type first, so an `authorized_keys` that is a symlink shows as one and the run stops there, before any upload. The README says so in one sentence under `keyfunc ssh install`.
Not visible in the diff:
- `-n` rather than `-l`: with `-l` the client prints the server's own line, whose form is up to the server and which names the file without `.ssh/`; with `-n` the client writes the line itself on every server.
- A link that points at nothing: the real client's `get` reports it as `stat remote: No such file or directory`, not as a missing file, so the old code already failed there without writing. The symlink check runs before the get's outcome is read, so that case gets the same message. The test stand-in does not model that wording, so no test covers it; it was checked by hand only.
Judgement call: `install -- host` is refused too, since it names no host before `--`.
Judgement call: a symlinked `authorized_keys` is refused even when the key is already in the file it points at.
Checked by hand against a throwaway `sshd` container, as the issue asks.
Model: opus-5-5
Anything but the host before --, or a second argument when there is no --, used to reach sftp in front of the host; it is now refused before the mnemonic is read or any connection is made. That includes "install -- host", which names no host before --.
The first listing of ~/.ssh is now a long one, ls -n, which the client formats itself whatever the server, so an authorized_keys that is a symlink shows as one. It is refused before any upload, since the rename would have replaced the link and left the file it points at without the key. The README says so.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #61.
ssh installnow takes the host alone before--. Anything else there, or a second argument when there is no--, is refused by the command's argument check, before the mnemonic is read orsftpruns.~/.sshis nowls -ninstead ofls -1. That is the long form, type first, so anauthorized_keysthat is a symlink shows as one and the run stops there, before any upload. The README says so in one sentence underkeyfunc ssh install.Not visible in the diff:
-nrather than-l: with-lthe client prints the server's own line, whose form is up to the server and which names the file without.ssh/; with-nthe client writes the line itself on every server.getreports it asstat remote: No such file or directory, not as a missing file, so the old code already failed there without writing. The symlink check runs before the get's outcome is read, so that case gets the same message. The test stand-in does not model that wording, so no test covers it; it was checked by hand only.Judgement call:
install -- hostis refused too, since it names no host before--.Judgement call: a symlinked
authorized_keysis refused even when the key is already in the file it points at.Checked by hand against a throwaway
sshdcontainer, as the issue asks.Model: opus-5-5
Review passed.
Model: opus-5-5