Conversation
The macOS GIT_SSH_COMMAND used BSD nc for its ProxyCommand, and nc only
speaks the SOCKS5 no-auth method. When SRT owns the proxy it always sets
a per-session auth token, so every sandboxed git-over-ssh attempt died
at the SOCKS handshake ("authentication method negotiation failed") —
the code comment acknowledged this and punted users to git-over-https.
Linux never had the problem because it emits
socat - PROXY:localhost:%h:%p,proxyport=<port>,proxyauth=<user>:<token>
— an HTTP CONNECT tunnel that can present Proxy-Authorization. The mux
serves HTTP CONNECT on the same port on macOS, and the terminate proxy
already sniffs for a ClientHello before MITM-ing, so non-TLS SSH bytes
pass through opaquely (pinned by connect-non-tls.test.ts).
macOS now emits the identical socat spelling whenever socat is found on
PATH (whichSync, per generateProxyEnvVars call — the wrapper already
probes PATH per wrap for the shell) and httpProxyPort is set, keeping
the nc spelling as the fallback for hosts without socat. socat stays an
optional macOS dependency, unlike Linux where it is mandatory.
Tests pin all four macOS shapes: socat+auth, socat+per-command
attribution username (userRaw, not percent-encoded — the Basic header
takes it verbatim), socat without auth, and the nc fallback. Also fixes
stale "Linux-only" wording in http-proxy.ts / connect-non-tls.test.ts
and the SOCKS5 misnomer in the linux-sandbox-utils docblock.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
On macOS, the sandbox's
GIT_SSH_COMMANDuses BSDncas itsProxyCommand:BSD
nconly speaks the SOCKS5 no-auth method, but when SRT owns the proxy it always sets a per-session auth token — so every sandboxed git-over-SSH attempt dies at the SOCKS handshake withnc: authentication method negotiation failed. The code comment ingenerateProxyEnvVarsacknowledges this and punts users to git-over-HTTPS.Linux never had this problem: it emits
— an HTTP CONNECT tunnel that can present
Proxy-Authorization.Fix
macOS now emits the identical socat spelling whenever
whichSync('socat')finds socat on the host PATH andhttpProxyPortis set, keeping thencspelling as the fallback for hosts without socat. Unlike Linux (where socat is a required dependency), socat stays optional on macOS — no new install requirement, just better behavior when it's present.This works because:
connect-non-tls.test.ts),userRaw(not the percent-encoded form) goes intoproxyauth=, matching the Linux branch — socat sends it verbatim in the Basic header.whichSyncis called pergenerateProxyEnvVarsinvocation (~1-5 ms spawnSync); the macOS wrapper already probes PATH per wrap for the shell, so this adds no meaningful overhead and keeps the check trivially mockable in tests.Verified end-to-end on macOS: with an ssh-agent socket allowed via
network.allowUnixSocketsand socat installed,git ls-remote git@github.com:...succeeds inside the sandbox against the auth-required session proxy (and against a private GitLab instance).Tests
Four new cases in
test/sandbox/proxy-env-vars.test.ts(spy pattern fromcheck-dependencies.test.ts) pin all macOS shapes:proxyauth=srt:<token>proxyauth=srt.<base64>:<token>(userRaw verbatim)proxyauthnc -X 5fallbackAlso fixes stale "Linux-only" wording in
http-proxy.ts/connect-non-tls.test.ts(the non-TLS CONNECT path now matters on macOS too) and the SOCKS5→HTTP CONNECT misnomer in thelinux-sandbox-utils.tsdocblock.