Skip to content

feat(net): honor ssh_config source binding and IPQoS - #307

Merged
inureyes merged 6 commits into
mainfrom
feature/issue-300-source-binding
Aug 30, 2026
Merged

inureyes merged 6 commits into
mainfrom
feature/issue-300-source-binding

Conversation

@inureyes

Copy link
Copy Markdown
Member

Summary

  • honor BindAddress, BindInterface, and interactive/bulk IPQoS before TCP connection establishment
  • create family-matched nonblocking sockets with explicit source binding, interface selection, IPv4 TOS, and IPv6 traffic-class handling
  • resolve authentication, transport, and host-key policy per original host alias across direct, interactive, command, and file-transfer connections
  • preserve final-destination policy separately from ProxyJump hop resolution and enforce CLI > ssh_config > YAML jump precedence
  • normalize ProxyJump none and direct as authoritative direct connections across every execution path

Validation

  • cargo fmt --all -- --check
  • cargo check --locked --lib --bins --tests
  • scoped bssh Clippy with -D warnings
  • support registry: 3 passed
  • authentication integration boundary: 3 passed
  • forwarding policy/live/saturation integration: 14 passed
  • source binding, IPv4/IPv6 QoS, per-node alias authentication, ProxyJump policy, and production command/transfer paths: 21 passed

Closes #300

Retain the SSH connection config resolver in interactive commands so ProxyJump bastions apply their own BindAddress, BindInterface, and IPQoS directives instead of inheriting the final target's socket policy.

Derive direct and jump traffic purpose from SessionPolicy so no-PTY shells use bulk QoS, correct Voice-Admit encoding to 0xb0, and cover fixed-config compatibility plus IPv4 and IPv6 socket behavior.

Validated with scoped format, check, clippy, per-hop policy, source-binding, and IPQoS tests.

Refs #300
Keep final-destination SSH policy separate from jump-host resolution so HostName expansion cannot replace source, QoS, host-key, or proxy settings selected by the original alias.

Resolve every interactive node from node.config_host(), pass that target config through host verification, direct connections, and jump construction, and make command and transfer ProxyJump lookup use the original alias.

Preserve explicit jump-host precedence and fixed-config callers while applying the per-host resolver only to bastion aliases.

Refs #300
ProxyJump none was passed through as a requested jump specification, so command and transfer connections parsed it as a bastion named `none` even though the resolved target policy correctly selected a direct transport.

Normalize none, direct, and the internal empty sentinel before jump selection while preserving the explicit decision over lower-priority configuration. Real CLI jump hosts remain authoritative, and both typed and fixed-config callers defensively reject direct markers as hop names.

Cover command, file and directory upload, file and directory download, interactive selection, alias policy preservation, and typed resolver fallback behavior with focused regressions.

Refs #300
Dispatcher paths pre-combined the YAML cluster jump with the explicit CLI field, causing downstream command, transfer, and interactive connections to mistake a fallback value for a CLI override and bypass per-host ssh_config ProxyJump decisions.

Thread only explicit CLI jump input through command parameters and keep ssh_config plus YAML inside the per-node resolver, which remains the single owner of CLI > ssh_config > YAML precedence. Share final jump selection between client and interactive paths, and derive SSH-mode session tokens from the same resolved ProxyMode.

Validate config direct and jump overrides, YAML fallback, CLI jump and direct overrides, original HostName aliases, and the command plus every file and directory transfer production path.

Refs #300
Interactive connections resolved transport and host-key policy per node but selected credentials from the dispatcher's shared fallback, allowing one host's ssh_config authentication settings to leak into other aliases.

Resolve each node's target config before authentication in both multiplex and PTY paths, and feed that same config through authentication, host verification, and direct or jump transport. Add two-host alias regressions that preserve explicit CLI identity and agent settings while distinguishing per-host IdentitiesOnly, IdentityFile, PasswordAuthentication, and BatchMode.

Validated with cargo fmt, full lib/bin/test cargo check, scoped Clippy with warnings denied, and focused #296/#300 authentication and transport tests.

Refs #300
@inureyes inureyes added type:enhancement New feature or request status:review Under review priority:high High priority issue labels Aug 30, 2026
@inureyes
inureyes merged commit e749df8 into main Aug 30, 2026
5 checks passed
@inureyes
inureyes deleted the feature/issue-300-source-binding branch August 30, 2026 08:00
@inureyes inureyes added status:done Completed and removed status:review Under review labels Aug 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority:high High priority issue status:done Completed type:enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(net): honor ssh_config source binding and IPQoS

1 participant