mirror of
https://github.com/stablyai/orca.git
synced 2026-09-29 08:03:20 +00:00
* feat(ssh): support Kerberos/GSSAPI hosts via the system OpenSSH transport ssh2 has no gssapi-with-mic support, and adding it would mean forking its protocol layer plus packaging the kerberos native module for three platforms. Instead, route GSSAPI hosts through the existing system-OpenSSH transport, which delegates Kerberos (tickets, SSPI on Windows) to the platform ssh binary. Two tiers, because RHEL-family distros enable GSSAPIAuthentication globally in /etc/ssh/ssh_config and ssh -G therefore reports it for every host: - Targets whose ~/.ssh/config Host block explicitly sets GSSAPIAuthentication yes (imported as target.gssapiAuthentication) try system ssh first, falling through to ssh2 so key auth and credential prompts still work when no ticket is available. - When ssh2 exhausts key/agent auth and the ssh -G-resolved config enables GSSAPI, retry over system ssh before prompting for credentials, so Kerberos-only hosts on distro-default configs connect without a password prompt. Hosts where keys work never leave the ssh2 path. Manual targets flagged for GSSAPI pass -o GSSAPIAuthentication=yes explicitly since they bypass ssh_config. Both tiers work headless (no credential callbacks required). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(ssh): harden GSSAPI transport selection (review fixes for PR #7507) Review fixes on top of the Kerberos/GSSAPI feature branch (s546126/kerberos-ssh): - HIGH: reset useSystemSshTransport on the ssh2 fall-through. doSystemSshProbe sets the flag before spawnSystemSshCommand, which throws synchronously when no system ssh binary is on PATH (outside the probe try/catch). The proactive fall-through previously reset only 2 of 3 transport fields, so exec/sftp kept routing through the failed transport - breaking GSSAPI on Windows-with-Git-ssh and headless Linux. - MEDIUM: throw a cancellation error (not the stale ssh2 authError) when a disconnect supersedes the reactive probe mid-flight, and guard connect()'s catch on disposed, so a deliberate disconnect is not overwritten with auth-failed. - MEDIUM: skip the encrypted-key passphrase prompt when the GSSAPI fallback applies, so a Kerberos ticket is tried before prompting; the general prompt still fires if the probe fails. Adds 3 mutation-verified regression tests and hardens two existing tests to assert the probe actually ran. Not connected to any PR remote. Co-authored-by: Orca <help@stably.ai> * fix(ssh): isolate GSSAPI system transport Co-authored-by: Orca <help@stably.ai> --------- Co-authored-by: s546126 <268420947+s546126@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com> Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com> Co-authored-by: Orca <help@stably.ai>
133 lines
4.2 KiB
TypeScript
133 lines
4.2 KiB
TypeScript
import { createHash } from 'node:crypto'
|
|
import { lstatSync, mkdirSync, rmSync } from 'node:fs'
|
|
import { tmpdir } from 'node:os'
|
|
import { isAbsolute, join as pathJoin } from 'node:path'
|
|
import type { SshTarget } from '../../shared/ssh-types'
|
|
import type { SshResolvedConfig } from './ssh-config-parser'
|
|
|
|
export type SystemSshResolvedConfig = Pick<
|
|
SshResolvedConfig,
|
|
| 'hostname'
|
|
| 'port'
|
|
| 'user'
|
|
| 'identityFile'
|
|
| 'identityAgent'
|
|
| 'identitiesOnly'
|
|
| 'forwardAgent'
|
|
| 'proxyCommand'
|
|
| 'proxyJump'
|
|
| 'proxyUseFdpass'
|
|
| 'controlMaster'
|
|
| 'controlPath'
|
|
| 'controlPersist'
|
|
>
|
|
|
|
const OPENSSH_CONTROL_SOCKET_SUFFIX_BUDGET = 18
|
|
const UNIX_SOCKET_PATH_LIMIT = process.platform === 'darwin' ? 104 : 108
|
|
const CONTROL_SOCKET_PATH_MAX_LENGTH = UNIX_SOCKET_PATH_LIMIT - OPENSSH_CONTROL_SOCKET_SUFFIX_BUDGET
|
|
|
|
export function getControlSocketPath(
|
|
target: SshTarget,
|
|
resolvedConfig?: SystemSshResolvedConfig | null,
|
|
gssapiOnly = false
|
|
): string | null {
|
|
if (process.platform === 'win32') {
|
|
return null
|
|
}
|
|
const uid = process.getuid?.()
|
|
if (uid === undefined) {
|
|
return null
|
|
}
|
|
|
|
const dir = findControlSocketDirectory(uid)
|
|
if (!dir) {
|
|
return null
|
|
}
|
|
|
|
// Why: include both persisted target fields and fresh ssh -G output so a
|
|
// live ControlPersist master is not reused after config-backed routes change.
|
|
const key = JSON.stringify({
|
|
target: {
|
|
id: target.id,
|
|
configHost: target.configHost || '',
|
|
host: target.host || '',
|
|
port: target.port || 22,
|
|
user: target.username || '',
|
|
proxyCommand: target.proxyCommand || '',
|
|
jumpHost: target.jumpHost || '',
|
|
identityFile: target.identityFile || '',
|
|
identityAgent: target.identityAgent || '',
|
|
identitiesOnly: target.identitiesOnly || false
|
|
},
|
|
resolved: normalizeResolvedConfig(resolvedConfig),
|
|
// Why: a Kerberos-only session must not reuse a master authenticated by a key.
|
|
gssapiOnly
|
|
})
|
|
const hash = createHash('sha256').update(key).digest('hex').slice(0, 16)
|
|
const socketPath = pathJoin(dir, hash)
|
|
return socketPath.length <= CONTROL_SOCKET_PATH_MAX_LENGTH ? socketPath : null
|
|
}
|
|
|
|
export function removeControlSocketPath(socketPath: string): void {
|
|
try {
|
|
rmSync(socketPath, { force: true })
|
|
} catch {
|
|
// Best-effort stale socket cleanup; the retry can still use `-S none`.
|
|
}
|
|
}
|
|
|
|
function findControlSocketDirectory(uid: number): string | null {
|
|
const candidates = getControlSocketDirectoryCandidates(uid)
|
|
for (const dir of candidates) {
|
|
if (ensurePrivateDirectory(dir, uid)) {
|
|
return dir
|
|
}
|
|
}
|
|
return null
|
|
}
|
|
|
|
function getControlSocketDirectoryCandidates(uid: number): string[] {
|
|
const candidates: string[] = []
|
|
const xdgRuntimeDir = process.env.XDG_RUNTIME_DIR
|
|
if (xdgRuntimeDir && isAbsolute(xdgRuntimeDir)) {
|
|
candidates.push(pathJoin(xdgRuntimeDir, 'orca-ssh'))
|
|
}
|
|
candidates.push(pathJoin(tmpdir(), `orca-ssh-${uid}`))
|
|
return candidates
|
|
}
|
|
|
|
function ensurePrivateDirectory(dir: string, uid: number): boolean {
|
|
try {
|
|
mkdirSync(dir, { recursive: true, mode: 0o700 })
|
|
// Why: mkdir mode is ignored for pre-existing dirs; lstat rejects symlink
|
|
// swaps and the owner/perms check avoids exposing the mux socket cross-user.
|
|
const st = lstatSync(dir)
|
|
return st.isDirectory() && st.uid === uid && (st.mode & 0o77) === 0
|
|
} catch {
|
|
return false
|
|
}
|
|
}
|
|
|
|
function normalizeResolvedConfig(
|
|
resolvedConfig: SystemSshResolvedConfig | null | undefined
|
|
): Record<string, unknown> | null {
|
|
if (!resolvedConfig) {
|
|
return null
|
|
}
|
|
return {
|
|
hostname: resolvedConfig.hostname || '',
|
|
port: resolvedConfig.port || 22,
|
|
user: resolvedConfig.user || '',
|
|
identityFile: resolvedConfig.identityFile ?? [],
|
|
identityAgent: resolvedConfig.identityAgent || '',
|
|
identitiesOnly: resolvedConfig.identitiesOnly || false,
|
|
forwardAgent: resolvedConfig.forwardAgent || false,
|
|
proxyCommand: resolvedConfig.proxyCommand || '',
|
|
proxyJump: resolvedConfig.proxyJump || '',
|
|
proxyUseFdpass: resolvedConfig.proxyUseFdpass || false,
|
|
controlMaster: resolvedConfig.controlMaster || 'no',
|
|
controlPath: resolvedConfig.controlPath || '',
|
|
controlPersist: resolvedConfig.controlPersist || 'no'
|
|
}
|
|
}
|