Repository navigation
feat(net): honor ssh_config source binding and IPQoS - #307
Merged
Merged
Conversation
Retain the SSH connection config resolver in interactive commands so ProxyJump bastions apply their own BindAddress, BindInterface, and IPQoS directives instead of inheriting the final target's socket policy. Derive direct and jump traffic purpose from SessionPolicy so no-PTY shells use bulk QoS, correct Voice-Admit encoding to 0xb0, and cover fixed-config compatibility plus IPv4 and IPv6 socket behavior. Validated with scoped format, check, clippy, per-hop policy, source-binding, and IPQoS tests. Refs #300
Keep final-destination SSH policy separate from jump-host resolution so HostName expansion cannot replace source, QoS, host-key, or proxy settings selected by the original alias. Resolve every interactive node from node.config_host(), pass that target config through host verification, direct connections, and jump construction, and make command and transfer ProxyJump lookup use the original alias. Preserve explicit jump-host precedence and fixed-config callers while applying the per-host resolver only to bastion aliases. Refs #300
ProxyJump none was passed through as a requested jump specification, so command and transfer connections parsed it as a bastion named `none` even though the resolved target policy correctly selected a direct transport. Normalize none, direct, and the internal empty sentinel before jump selection while preserving the explicit decision over lower-priority configuration. Real CLI jump hosts remain authoritative, and both typed and fixed-config callers defensively reject direct markers as hop names. Cover command, file and directory upload, file and directory download, interactive selection, alias policy preservation, and typed resolver fallback behavior with focused regressions. Refs #300
Dispatcher paths pre-combined the YAML cluster jump with the explicit CLI field, causing downstream command, transfer, and interactive connections to mistake a fallback value for a CLI override and bypass per-host ssh_config ProxyJump decisions. Thread only explicit CLI jump input through command parameters and keep ssh_config plus YAML inside the per-node resolver, which remains the single owner of CLI > ssh_config > YAML precedence. Share final jump selection between client and interactive paths, and derive SSH-mode session tokens from the same resolved ProxyMode. Validate config direct and jump overrides, YAML fallback, CLI jump and direct overrides, original HostName aliases, and the command plus every file and directory transfer production path. Refs #300
Interactive connections resolved transport and host-key policy per node but selected credentials from the dispatcher's shared fallback, allowing one host's ssh_config authentication settings to leak into other aliases. Resolve each node's target config before authentication in both multiplex and PTY paths, and feed that same config through authentication, host verification, and direct or jump transport. Add two-host alias regressions that preserve explicit CLI identity and agent settings while distinguishing per-host IdentitiesOnly, IdentityFile, PasswordAuthentication, and BatchMode. Validated with cargo fmt, full lib/bin/test cargo check, scoped Clippy with warnings denied, and focused #296/#300 authentication and transport tests. Refs #300
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
BindAddress,BindInterface, and interactive/bulkIPQoSbefore TCP connection establishmentCLI > ssh_config > YAMLjump precedenceProxyJump noneanddirectas authoritative direct connections across every execution pathValidation
cargo fmt --all -- --checkcargo check --locked --lib --bins --tests-D warningsCloses #300