Skip to content

feat(cli): dump resolved SSH configuration - #310

Merged
inureyes merged 9 commits into
mainfrom
feature/issue-282-ssh-config-dump
Aug 31, 2026
Merged

inureyes merged 9 commits into
mainfrom
feature/issue-282-ssh-config-dump

Conversation

@inureyes

@inureyes inureyes commented Aug 31, 2026 •

Copy link
Copy Markdown
Member

Summary

  • add bssh -G to resolve and print effective SSH configuration without connecting
  • apply CLI and -o precedence together with ordered Host, Match, and Include processing across user/system first and final passes
  • emit deterministic, reparsable output with OpenSSH-shaped token, path, environment, algorithm-list, and forwarding behavior
  • isolate trusted config-dump Match exec shell evaluation with null stdio, a bounded timeout, process-group cleanup, cached pass results, and TOCTOU-safe Include reads

Validation

  • cargo fmt --all -- --check
  • git diff --check
  • cargo check --locked --lib --bin bssh --tests
  • cargo clippy --locked --lib --bin bssh --tests -- -D warnings
  • cargo test --locked --lib — 1651 passed, 7 ignored
  • cargo test --locked --quiet --lib ssh::ssh_config — 293 passed
  • cargo test --locked --test ssh_config_command_options_advanced_test — 15 passed
  • cargo test --locked --quiet --test ssh_config_dump_test — 21 passed
  • cargo test --locked --quiet --test ssh_compat_output_test — 12 passed
  • OpenSSH V_10_3_P1 regressions: cfgparse, sshcfgparse, cfgmatch, and cfginclude — 4/4 passed
  • independent final audit at c3fb91f91ae34e0d6798dcca1e1d289f51a8a389 — merge-safe, no feat(cli): implement -G to dump the resolved configuration #282 blockers

The broader percent regression still contains live runtime and invalid-user cases outside this issue's four acceptance regressions.

Closes #282

Resolve OpenSSH-style configuration queries without starting connection services. Preserve argv provenance, contextual Match and Include behavior, and deterministic rendering for typed and retained configuration values.
Make raw -G dispatch fail closed before normal CLI initialization, preserve OpenSSH argv and Include semantics, and emit deterministic reparse-safe resolved configuration.

Add final-pass matching, retained keyword defaults, permission-aware Include traversal, and focused differential regressions.

Refs: #282
Carry the complete resolved CLI/source state into host-aware Include parsing so Match exec and Include tokens see the effective host, user, port, key alias, jump host, and connection hash across source and final-pass boundaries. Restrict trusted-shell loaders behind explicitly named config-dump APIs and keep lower-level entry points crate-private.

Validate CLI, cross-source, final-pass, cache, visibility, and config-dump behavior with focused regressions.

Refs #282
Resolve source-boundary context from pass-one blocks only so a user Match final request cannot fix an unset HostName before system config is parsed. Keep the complete first-pass config available to system Include and Match exec token expansion, then retain the existing final-pass bootstrap after all sources have run.

Add a user/system regression that proves system HostName, %h Include, and Match exec behavior across both passes.

Refs #282
@inureyes inureyes added priority:high High priority issue status:in-progress Currently being worked on type:enhancement New feature or request labels Aug 31, 2026
@inureyes
inureyes force-pushed the feature/issue-282-ssh-config-dump branch from c198eec to c3fb91f Compare August 31, 2026 15:57
@inureyes
inureyes merged commit ca531c8 into main Aug 31, 2026
5 checks passed
@inureyes
inureyes deleted the feature/issue-282-ssh-config-dump branch August 31, 2026 16:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority:high High priority issue status:in-progress Currently being worked on type:enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(cli): implement -G to dump the resolved configuration

1 participant