-
-
Notifications
You must be signed in to change notification settings - Fork 2.4k
cmux ssh: forward invoking shell's PATH and auth socket to SSH sessions #5405
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
f35185c
e129f72
4564085
95169da
2582436
0a76ba8
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -7420,6 +7420,7 @@ struct CMUXCLI { | |
| let workspaceName: String? | ||
| let windowRaw: String? | ||
| let noFocus: Bool | ||
| let inheritEnvironment: Bool | ||
| let sshOptions: [String] | ||
| let extraArguments: [String] | ||
| let agentSocketPath: String? | ||
|
|
@@ -7437,6 +7438,7 @@ struct CMUXCLI { | |
| workspaceName: String?, | ||
| windowRaw: String? = nil, | ||
| noFocus: Bool, | ||
| inheritEnvironment: Bool = false, | ||
| sshOptions: [String], | ||
| extraArguments: [String], | ||
| agentSocketPath: String? = nil, | ||
|
|
@@ -7451,6 +7453,7 @@ struct CMUXCLI { | |
| self.workspaceName = workspaceName | ||
| self.windowRaw = windowRaw | ||
| self.noFocus = noFocus | ||
| self.inheritEnvironment = inheritEnvironment | ||
| self.sshOptions = sshOptions | ||
| self.extraArguments = extraArguments | ||
| self.agentSocketPath = agentSocketPath | ||
|
|
@@ -7711,10 +7714,9 @@ struct CMUXCLI { | |
| var workspaceCreateParams: [String: Any] = [ | ||
| "initial_command": initialSSHStartupCommand, | ||
| ] | ||
| if let agentSocketPath = sshOptions.agentSocketPath { | ||
| workspaceCreateParams["initial_env"] = [ | ||
| "SSH_AUTH_SOCK": agentSocketPath, | ||
| ] | ||
| let startupEnvironment = sshStartupEnvironment(for: sshOptions) | ||
| if !startupEnvironment.isEmpty { | ||
| workspaceCreateParams["initial_env"] = startupEnvironment | ||
| } | ||
|
Comment on lines
+7717
to
7720
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
When the user creates another terminal/split in this SSH workspace, the app runs the saved Useful? React with 👍 / 👎. |
||
| try applyWindowOrCallerContext(to: &workspaceCreateParams, client: client, windowRaw: sshOptions.windowRaw) | ||
|
|
||
|
|
@@ -7890,6 +7892,7 @@ struct CMUXCLI { | |
| var workspaceName: String? | ||
| var windowRaw: String? | ||
| var noFocus = false | ||
| var inheritEnvironment = false | ||
| var sshOptions: [String] = [] | ||
| var extraArguments: [String] = [] | ||
| var forwardAgentOverride: Bool? | ||
|
|
@@ -7938,6 +7941,9 @@ struct CMUXCLI { | |
| case "--no-focus": | ||
| noFocus = true | ||
| index += 1 | ||
| case "--inherit-env": | ||
| inheritEnvironment = true | ||
| index += 1 | ||
| case "-A", "--forward-agent": | ||
| forwardAgentOverride = true | ||
| index += 1 | ||
|
|
@@ -7985,6 +7991,7 @@ struct CMUXCLI { | |
| workspaceName: workspaceName, | ||
| windowRaw: windowRaw ?? windowOverride, | ||
| noFocus: noFocus, | ||
| inheritEnvironment: inheritEnvironment, | ||
| sshOptions: agentForwarding.sshOptions, | ||
| extraArguments: extraArguments, | ||
| agentSocketPath: agentForwarding.agentSocketPath, | ||
|
|
@@ -7993,6 +8000,57 @@ struct CMUXCLI { | |
| ) | ||
| } | ||
|
|
||
| private static let safeSSHStartupEnvironmentKeys: [String] = [ | ||
| "PATH", | ||
| "SHELL", | ||
| "SSH_AUTH_SOCK", | ||
| ] | ||
|
Comment on lines
+8003
to
+8007
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
With a stale Useful? React with 👍 / 👎. |
||
|
|
||
| private static let sshInheritedEnvironmentScrubbedKeys: Set<String> = [ | ||
| "CMUX_BUNDLED_CLI_PATH", | ||
| "CMUX_SOCKET", | ||
| "CMUX_SOCKET_PATH", | ||
| "CMUX_SOCKET_PASSWORD", | ||
| "CMUX_WORKSPACE_ID", | ||
| "CMUX_SURFACE_ID", | ||
| "CMUX_PANEL_ID", | ||
| "CMUX_TAB_ID", | ||
| "CMUX_PANE_ID", | ||
| "CMUXD_UNIX_PATH", | ||
|
Comment on lines
+8009
to
+8023
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
coderabbitai[bot] marked this conversation as resolved.
|
||
| "CMUX_DEBUG_LOG", | ||
| "CMUX_RELAY_ID", | ||
| "CMUX_RELAY_TOKEN", | ||
| ] | ||
|
|
||
| private func sshStartupEnvironment(for options: SSHCommandOptions) -> [String: String] { | ||
| let environment = ProcessInfo.processInfo.environment | ||
| var startupEnvironment = options.inheritEnvironment | ||
| ? scrubbedSSHInheritedEnvironment(environment) | ||
| : safeSSHStartupEnvironment(environment) | ||
| if let agentSocketPath = options.agentSocketPath { | ||
| startupEnvironment["SSH_AUTH_SOCK"] = agentSocketPath | ||
| } | ||
| return startupEnvironment | ||
| } | ||
|
|
||
| private func safeSSHStartupEnvironment(_ environment: [String: String]) -> [String: String] { | ||
| var result: [String: String] = [:] | ||
| for key in Self.safeSSHStartupEnvironmentKeys { | ||
| if let value = Self.normalizedEnvValue(environment[key]) { | ||
| result[key] = value | ||
| } | ||
| } | ||
| return result | ||
| } | ||
|
|
||
| private func scrubbedSSHInheritedEnvironment(_ environment: [String: String]) -> [String: String] { | ||
| var result = environment.compactMapValues { Self.normalizedEnvValue($0) } | ||
| for key in Self.sshInheritedEnvironmentScrubbedKeys { | ||
|
Comment on lines
+8046
to
+8052
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time! |
||
| result.removeValue(forKey: key) | ||
| } | ||
| return result | ||
| } | ||
|
|
||
| private func resolvedSSHAgentForwarding( | ||
| sshOptions: [String], | ||
| override: Bool? | ||
|
|
@@ -13522,6 +13580,7 @@ struct CMUXCLI { | |
| -A, --forward-agent Forward the caller's SSH agent; also honors ForwardAgent yes from ssh_config | ||
| -a, --no-forward-agent Disable SSH agent forwarding for this workspace | ||
| --ssh-option <opt> Extra SSH -o option (repeatable) | ||
| --inherit-env Forward the caller environment after scrubbing stale cmux context | ||
| --window <id|ref|index> Target window for the managed workspace | ||
| --no-focus Create workspace without switching to it | ||
|
|
||
|
|
||
Uh oh!
There was an error while loading. Please reload this page.