Repository navigation
feat(ssh): enforce RekeyLimit transport policy - #308
Merged
Merged
Conversation
- Replace raw RekeyLimit strings with a checked byte/time policy and preserve OpenSSH's `default none` semantics. - Apply the effective policy to russh read, write, and time limits while capping data at the backend's nonce-safety ceiling. - Forward piped stdin for a single raw SSH destination so bounded transfer regressions exercise real transport rekeys without racing multi-host readers. - `cargo test rekey --lib` - focused ssh_config parser, resolver, and runtime registry tests - `cargo check --lib --bins --tests` - `cargo clippy --lib --bins --tests -- -D warnings` - `cargo fmt --all -- --check` - `git diff --check` Refs #301
The transport exposed read and time limits but only evaluated write bytes and checked elapsed time while flushing outbound work, leaving inbound-heavy and idle authenticated sessions outside the configured rekey policy. Count decrypted packet payload bytes per key epoch, trigger authenticated client and server rekeys at the read threshold, reset counters when NEWKEYS completes, and schedule finite time limits as independent event-loop deadlines. Add focused counter, threshold, and idle tests plus a loopback transfer that observes a timer-driven rekey and completes repeated bidirectional byte-limit rekeys. Refs #301
Reset transport byte accounting whenever a new outbound cipher is installed, including the initial encrypted epoch. Gate server-initiated automatic rekeys on completed authentication and make the bidirectional transfer regression observe repeated byte-triggered exchanges. Refs #301
The #301 transplant now leaves all completed runtime keyword classifications active while retaining the delegated classification type for future issue waves without warning under the lint gate. Extend the jump-chain regression with distinct bastion, destination-alias, and expanded-host RekeyLimit values so the final destination cannot silently re-resolve away from its original alias policy. Refs #301
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
RekeyLimitas a typed byte/time policy with checked suffixes, defaults,none, and backend nonce-safety ceilingsValidation
cargo fmt --all -- --checkcargo check --locked --lib --bins --tests-D warningsrekeyremains gated by-Gsupport in feat(cli): implement -G to dump the resolved configuration #282Closes #301