Commit Graph
4 Commits
Author SHA1 Message Date
OrcaWinandm4air 5f308bfa9c revert: take the 26 Phase 3 (#16741 port) PRs back out of main (#24559)
* Revert "feat(orcad): source-side dormant export of a relay-hosted SSH target (#16741 T6-8) (#24519)"

This reverts commit 783101b304.

* Revert "feat(ssh): update, roll back, recover and stop a managed orcad server (#16741 T6-5 follow-up) (#24463)"

This reverts commit 38c2d1dcb9.

* Revert "feat(ssh): deploy and pair an empty managed orcad server over SSH (#16741 T6-5) (#24453)"

This reverts commit 8b76683b40.

* Revert "fix(ssh): orcad GC honors the activation journal; readiness requires proven daemon coverage (#16741 T6 follow-up) (#24451)"

This reverts commit d3f8c5063b.

* Revert "feat(ssh): remote orcad stop by request file and journaled decommission (#16741 T6-4) (#24449)"

This reverts commit 43d9b43d3f.

* Revert "feat(orcad): supervisable server: stop requests, managed stop receipts and a lifetime that keeps its lock on failed teardown (#16741 T6-3) (#24433)"

This reverts commit b093d3ab20.

* Revert "feat(ssh): crash-safe orcad activation, rollback and recovery (#16741 T6-2) (#24423)"

This reverts commit 1a9ac0e955.

* Revert "feat(runtime): SSH access links for paired servers in a downgrade-safe sidecar (#16741 T5-1+T5-2) (#24420)"

This reverts commit 99db2bfae4.

* Revert "feat(relay): capability-gated owner reset with a durable preparation journal (#16741 T3 R1) (#24418)"

This reverts commit 34a582bd39.

* Revert "feat(ssh): track connection-manager drains, test probes and provider continuations (#16741 T2 P3+P8a) (#24407)"

This reverts commit d53063d2b1.

* Revert "feat(daemon): idle retirement, session census and recovery-only provider (#16741 T2 P4b) (#24409)"

This reverts commit ff212dbbef.

* Revert "feat(ssh): add pty.resumeClient and split SSH PTY process listing (#16741 T2 P5+P6) (#24414)"

This reverts commit 92cb71765e.

* Revert "feat(relay): await owned watcher and agent children on shutdown (#16741 T2 P1) (#24400)"

This reverts commit 6b36e4f85b.

* Revert "feat(session): retry failed renderer session writes and verify local folder PTYs (#16741 T2 P9) (#24406)"

This reverts commit d23ecef301.

* Revert "feat(ssh): remote orcad primitives on the pinned Node runtime (#16741 T6-1) (#24419)"

This reverts commit dd87ae578d.

* Revert "fix(runtime): fence runtime-environment subscriptions and status probes by identity (#16741 T5-3) (#24421)"

This reverts commit ece9e4d2e3.

* Revert "feat(orcad): migration manifest and dormant-state contracts (#16741 T6-7) (#24422)"

This reverts commit 3fbdaba262.

* Revert "feat(ssh): wire SshConnection through the work and transport close ledgers (#16741 T2 P2) (#24401)"

This reverts commit 4e8edc8872.

* Revert "feat(profiles): carry markdown frontmatter visibility in project transfers (#16741 T2 P7) (#24405)"

This reverts commit 60c93263cc.

* Revert "fix(runtime): project the PTY incarnation onto mobile session tabs (#24413)"

This reverts commit 99e0303572.

* Revert "feat(daemon): tag daemon stream data with the PTY incarnation id (#16741 T2 P4a) (#24402)"

This reverts commit 817af768b0.

* Revert "feat(ssh): port the SSH connection work ledger and transport close ledger (#16741 T2) (#24210)"

This reverts commit c9918931c8.

* Revert "feat(relay): fence and drain file and git response streams on shutdown (#24185)"

This reverts commit dc08ffeba9.

* Revert "refactor(runtime-rpc): extract the Node WebSocket lifecycle; opt-in pinned port (#24186)"

This reverts commit a789233bbb.

* Revert "feat(relay): route relay handlers through work admission; producer publication drain (#24181)"

This reverts commit 0b812bd698.

* Revert "feat(relay): land the #16741 T1 seam (work drain, publication drain, release gate) (#24156)"

This reverts commit 3aa2d3af7c.

---------

Co-authored-by: m4air <m4air@Mac.localdomain>
2026-10-02 00:52:32 -07:00
OrcaWinandm4air 4e8edc8872 feat(ssh): wire SshConnection through the work and transport close ledgers (#16741 T2 P2) (#24401)
* feat(ssh): wire SshConnection through the work and transport close ledgers (#16741 T2 P2)

Every operation SshConnection admits (exec, shell, sftp, file transfers, upload
sessions, forwarded channels and sockets, system-SSH commands) now runs through
the connection's work ledger, and every ssh2 client and proxy process it
allocates is tracked until it physically closes. Ordinary connect, reconnect
and disconnect behavior is unchanged.

Adds:
- subscribeTransportClosure: one-shot notice once the connection is disposed,
  every allocated transport has emitted 'close' and tracked work has drained.
  System-SSH startup is never proven closed from here.
- disconnectAndDrain(signal): for owned single-lifetime transports; fences new
  work, disconnects, and waits for physical close of the client, proxy, every
  allocated client and all fenced work. Refuses (after cleaning up) when the
  transport cannot be proven, e.g. system SSH or a connect still in flight.
- getExecutionDestination: the ssh2 endpoint, accepted host-key fingerprint and
  proxy-route digest proven by the current handshake (ssh-connection-destination).
- getTransportGeneration, prepareForwardRoute, openForwardSocket, forwardOut,
  forwardStreamLocal for later forwarding callers.
- An automaticReconnect constructor option (default on).

Channel close is local lifetime evidence only, never a remote-exit verdict.

Porting note (source: #16741 head a68b6f3531, merge-base 277c289bd4):
- Taken: the ledger hunks of ssh-connection.ts, ssh-connection-destination,
  ssh-forward-channel-lifetime, ssh-upload-session-lifetime, the system-SSH
  facade EOF hunk, and their tests.
- Adapted: operation bodies became private *Untracked methods called through
  the ledger instead of being re-indented; closure gating and the close drain
  moved to ssh-connection-transport-closure / ssh-connection-close-drain; the
  destination parser uses type guards instead of a cast. disconnectAndDrain
  fences through the ledger directly. Main's plain-SSH shell() goes through the
  ledger too. execCommand takes Pick<SshConnection, 'exec' |
  'usesSystemSshTransport'>; its string-stdin/maxOutputBytes hunk is not taken
  because main already streams stdin. Work-drain tests fence the private ledger
  until T3 adds the public fence; system-SSH drain cases split into their own
  file.
- Left for later slices: fenceWorkForReset (T3), isEphemeralRuntimeSshOwner
  (T6), assertProfileLifetimeAdmission (P8b), and the four manager drain cases
  in ssh-connection-disconnect-drain.test.ts (P3).

* refactor(ssh): shrink SshConnection below main and surface unhandled channel errors

ssh-connection.ts no longer grows under its max-lines exemption: it is 1872
lines, below main's 1917. The public API is unchanged.

- ssh-channel-open.ts: the channel-open waiter and session-limit retry.
- ssh-connection-file-transfers.ts: the uploadDirectory, downloadFile, upload
  session, writeFile and writeBuffer bodies, reading the connection through a
  small getter-based host so each read still sees the live transport.
- ssh-forward-channel-lifetime.ts: the forward client and stream-local checks.

The lifetime tracker's 'error' listener no longer hides errors. When it is a
channel's only error listener, the error is reported: SshConnection logs
"[ssh] Unhandled <kind> channel error for <target>: <message>", and other
callers fall back to a generic [ssh] warning. Nothing throws, so an orphaned
channel error still cannot crash the process.

* fix(ssh): name the forwarded local socket type and type the upload-session test stub

The forwarded local socket now takes SshConnectionWorkChannel, the event
surface the ledger tracks, instead of a broad object. The upload-session
lifetime test binds an EventEmitter rather than an untyped {}.

---------

Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
2026-10-01 09:47:17 -07:00
Brennan BensonandMerge Sim bcb703fb4c test(ssh): isolate the MFA fixture from the developer's real ~/.ssh (#19300)
The multi-stage cases pass `resolved: null`, so `resolvePrivateKeys` falls
through to `findDefaultKeyFile`, which reads `~/.ssh/id_*` via `homedir()`.
On a machine with an encrypted default key ssh2 rejects with "Cannot parse
privateKey" before authentication is exercised, so two cases failed locally
while staying green on hosted CI, which has no key. Point home at the existing
fixture directory so default-key discovery stays in the test's control.

Co-authored-by: Merge Sim <sim@local>
2026-09-07 09:32:14 -07:00
Neil 278f9ee876 fix(ssh): answer every MFA stage, stop dialling an unclaimed alias, and say where a clone failed (#17946)
* fix(ssh): answer every MFA stage, not just the first

ssh2 walks one flat auth-method list exactly once, so keyboard-interactive
could only ever be offered a single time. A host running
`AuthenticationMethods keyboard-interactive,keyboard-interactive` (or any
ladder ending in a second challenge) partial-succeeds the first stage and
then finds the list exhausted, which the user sees as "All configured
authentication methods failed" — the reports in #8622 and #16820.

Orca's own auth handler now runs for every target instead of only multi-key
ones, and rebuilds its queue on each SSH_MSG_USERAUTH_FAILURE that carries
partial success, narrowed to the methods the host still offers. Narrowing
also stops keys being re-offered after the host has moved past publickey,
which is what exhausts MaxAuthTries before the challenge is ever shown.

Covered by a real ssh2 server fixture that stages partial success.

* fix(git): say where a failing clone ran and why nothing could prompt

Clones go through nonInteractiveGitEnv, so `ssh` runs with BatchMode=yes and an
emptied SSH_ASKPASS. On a remote or paired-runtime clone that produces
`fatal: Could not read from remote repository.` while the same `git clone`
typed by hand on that box succeeds — the divergence in #14533. Nothing in the
message said the clone ran on the other machine, under its keys, with the
prompt deliberately disabled.

getGitCloneFailureMessage now appends that fact, and names the two recognisable
shapes: a publickey refusal (load the key into an agent there) and a host-key
failure (record the key in that machine's known_hosts). Unrecognised SSH
failures still get the where-it-ran note; non-SSH failures are untouched.

One builder, so the SSH-target relay path and the runtime path both get it.

* fix(ssh): stop dialling a bare alias no ssh_config block claims

A wildcard `Host *` block supplies ProxyCommand/ProxyJump for every alias, so
shouldUseSystemSshTransport picks the system transport for an alias whose own
Host block was renamed or deleted, and buildSshArgs then dials that alias
verbatim: no -l, no -p, no Hostname. Orca connects as the wildcard's user to
the wildcard's host and discards the endpoint it stored (#11746).

The signal #11746 assumed (hostBlockMatch, from the still-open #11707) does not
exist, and `ssh -G` cannot supply it — it prints the merged config and answers
for unknown aliases too. The config file is the only source of truth, so:

- parseSshConfigAliasClaims retains raw Host patterns and flags Match blocks,
  which parseSshConfig discards because it mints importable targets.
- sshConfigMayClaimAlias is sound in the negative direction only: an unreadable
  file, any Match block, or any non-catch-all pattern that might match all
  answer "claimed", so absence of evidence is never read as evidence of
  absence. Only a proven-unclaimed alias licenses an override.
- buildSshArgs then states Hostname/Port/User, and only those: the wildcard is
  still the route, and -o Hostname does not change block selection, so the
  proxy keeps applying and %h expands to the host we mean.

The verdict is injected rather than read inside buildSshArgs, so an arg builder
does not answer differently per machine. Default is today's behaviour.

Scoped to the system-SSH transport and the connection's own command/transport
path. Port-forward processes and the ssh2 transport (#11707) are unchanged.

* fix(ssh): read a negated Host group as uncertainty, and gate clone SSH guidance

`Host * !prod` applies to every alias but `prod`, yet skipping both the catch-all
and the `!` pattern answered "unclaimed" for `stage` — which licences overriding
Hostname/Port/User against a block the user wrote. Any negation now makes the
whole group uncertain; the function is only sound in the negative direction.

Also require an ssh(1) diagnostic beside "could not read from remote repository"
before appending the SSH clone note: git prints that same line for the HTTP
remote helper, where advice about keys and agents is simply wrong.

* fix(i18n): restore the activity-options key the rebase dropped

* fix(i18n): union en.json with main so the rebase cannot drop keys
2026-09-02 15:14:53 -07:00