Skip to content

feat(ssh): enforce RekeyLimit transport policy - #308

Merged
inureyes merged 5 commits into
mainfrom
feature/issue-301-rekey-limit
Aug 30, 2026
Merged

inureyes merged 5 commits into
mainfrom
feature/issue-301-rekey-limit

Conversation

@inureyes

Copy link
Copy Markdown
Member

Summary

  • parse RekeyLimit as a typed byte/time policy with checked suffixes, defaults, none, and backend nonce-safety ceilings
  • map resolved policies to russh read, write, and idle limits for both client and server transports
  • count inbound payload bytes, arm idle rekeying immediately after authentication with safe delayed-compression ordering, and reset read/write/time epochs on completed key installation
  • verify repeated bidirectional rekeys and preserve distinct bastion and original-target-alias policies across ProxyJump chains

Validation

  • cargo fmt --all -- --check
  • cargo check --locked --lib --bins --tests
  • scoped bssh and bssh-russh production Clippy with -D warnings
  • bssh RekeyLimit parser/resolver/conversion: 7 passed
  • bssh-russh automatic rekey behavior: 10 passed
  • bssh-russh server session behavior: 23 passed
  • cipher epoch reset: passed
  • runtime/delegation registry and integrated auth/forwarding/source-QoS/jump policy regressions pass
  • OpenSSH rekey remains gated by -G support in feat(cli): implement -G to dump the resolved configuration #282

Closes #301

- Replace raw RekeyLimit strings with a checked byte/time policy and preserve OpenSSH's `default none` semantics.
- Apply the effective policy to russh read, write, and time limits while capping data at the backend's nonce-safety ceiling.
- Forward piped stdin for a single raw SSH destination so bounded transfer regressions exercise real transport rekeys without racing multi-host readers.

- `cargo test rekey --lib`
- focused ssh_config parser, resolver, and runtime registry tests
- `cargo check --lib --bins --tests`
- `cargo clippy --lib --bins --tests -- -D warnings`
- `cargo fmt --all -- --check`
- `git diff --check`

Refs #301
The transport exposed read and time limits but only evaluated write bytes and checked elapsed time while flushing outbound work, leaving inbound-heavy and idle authenticated sessions outside the configured rekey policy.

Count decrypted packet payload bytes per key epoch, trigger authenticated client and server rekeys at the read threshold, reset counters when NEWKEYS completes, and schedule finite time limits as independent event-loop deadlines. Add focused counter, threshold, and idle tests plus a loopback transfer that observes a timer-driven rekey and completes repeated bidirectional byte-limit rekeys.

Refs #301
Reset transport byte accounting whenever a new outbound cipher is installed, including the initial encrypted epoch. Gate server-initiated automatic rekeys on completed authentication and make the bidirectional transfer regression observe repeated byte-triggered exchanges.

Refs #301
The #301 transplant now leaves all completed runtime keyword classifications active while retaining the delegated classification type for future issue waves without warning under the lint gate.

Extend the jump-chain regression with distinct bastion, destination-alias, and expanded-host RekeyLimit values so the final destination cannot silently re-resolve away from its original alias policy.

Refs #301
@inureyes inureyes added type:enhancement New feature or request status:review Under review priority:high High priority issue labels Aug 30, 2026
@inureyes
inureyes merged commit 45889b1 into main Aug 30, 2026
5 checks passed
@inureyes
inureyes deleted the feature/issue-301-rekey-limit branch August 30, 2026 09:08
@inureyes inureyes added status:done Completed and removed status:review Under review labels Aug 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority:high High priority issue status:done Completed type:enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(ssh): enforce RekeyLimit through russh transport limits

1 participant