Repository navigation
fix(ssh): finalize config keyword support invariant - #309
Merged
Merged
Conversation
Collapse accepted SSH config keyword support into Runtime or Unimplemented, audit the exact 91-spelling registry, and preserve shared diagnostic provenance and deduplication across config files and -o overlays. Allow repeated OpenSSH -t flags while retaining boolean runtime consumers and last-option-wins precedence against -T, restoring the key-options regression case. Validated with focused registry, parser, resolver, diagnostics, CLI, authentication, session, transport, forwarding, host-key, source/QoS, rekey, and OpenSSH named regression tests, plus format, check, and Clippy gates. Refs #281
SSH config filenames and unknown keywords are untrusted diagnostic fields. Rendering control characters verbatim allowed newline injection and ANSI terminal manipulation in stderr or -E logs. Escape every Unicode control character at the output boundary while preserving printable Unicode, and model config lines versus -o options explicitly so CLI diagnostics identify `-o option #N`. Add unit and end-to-end regressions covering control escaping, printable Unicode, malicious newline filenames, ANSI-bearing unknown keywords, single-line log integrity, and ordinary provenance. Refs #281
SSH config path failures were still rendered through raw Path::display calls across cache loading, include resolution, and path validation. A newline-bearing missing -F path could inject forged -E log lines despite parser warning escaping. Move control escaping to a crate-visible SSH config diagnostic helper and reuse it at every user-visible path and pattern context in the SSH config and cache modules. The helper returns Cow so ordinary printable UTF-8 remains unchanged and allocation-free. Add an end-to-end missing-path regression alongside the existing warning-path coverage, and audit remaining raw display calls as test-only fixture construction. Refs #281
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
DelegatedSSH-config support state and enforce the exact accepted-keyword invariant: 91 spellings = 51 runtime + 40 unimplemented.-ooverlays while preserving the first real source location.-tflags and preserve last-option-wins behavior between-tand-T.-o option #Nrather than ambiguous source lines.Security review
Independent review reproduced log-line and ANSI injection through control characters in config paths. The final implementation centralizes output-boundary escaping, covers successful parsing and load-error paths, and leaves raw path values intact for validation and policy decisions.
The final re-audit found no CRITICAL, HIGH, or MEDIUM findings.
Validation
cargo check --locked --lib --bins --tests-D warningscargo fmt --checkgit diff --checkThe integrated OpenSSH named run is 14 pass / 3 fail / 2 environmental / 1 skip. The remaining candidate failures require
-Gfrom #282 (percent,rekey) and-nfrom #285 (dynamic-forward). Thekey-optionscase now passes after the repeated-tfix.Tracker status
This PR intentionally references rather than closes #281. The tracker requires the named regress set to pass, so it will remain open until #282 and #285 remove the three known blockers and the integrated set is rerun.
Refs #281