Repository navigation
feat(cli): dump resolved SSH configuration - #310
Merged
Merged
Conversation
Resolve OpenSSH-style configuration queries without starting connection services. Preserve argv provenance, contextual Match and Include behavior, and deterministic rendering for typed and retained configuration values.
Make raw -G dispatch fail closed before normal CLI initialization, preserve OpenSSH argv and Include semantics, and emit deterministic reparse-safe resolved configuration. Add final-pass matching, retained keyword defaults, permission-aware Include traversal, and focused differential regressions. Refs: #282
Carry the complete resolved CLI/source state into host-aware Include parsing so Match exec and Include tokens see the effective host, user, port, key alias, jump host, and connection hash across source and final-pass boundaries. Restrict trusted-shell loaders behind explicitly named config-dump APIs and keep lower-level entry points crate-private. Validate CLI, cross-source, final-pass, cache, visibility, and config-dump behavior with focused regressions. Refs #282
Resolve source-boundary context from pass-one blocks only so a user Match final request cannot fix an unset HostName before system config is parsed. Keep the complete first-pass config available to system Include and Match exec token expansion, then retain the existing final-pass bootstrap after all sources have run. Add a user/system regression that proves system HostName, %h Include, and Match exec behavior across both passes. Refs #282
inureyes
force-pushed
the
feature/issue-282-ssh-config-dump
branch
from
August 31, 2026 15:57
c198eec to
c3fb91f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
bssh -Gto resolve and print effective SSH configuration without connecting-oprecedence together with orderedHost,Match, andIncludeprocessing across user/system first and final passesMatch execshell evaluation with null stdio, a bounded timeout, process-group cleanup, cached pass results, and TOCTOU-safe Include readsValidation
cargo fmt --all -- --checkgit diff --checkcargo check --locked --lib --bin bssh --testscargo clippy --locked --lib --bin bssh --tests -- -D warningscargo test --locked --lib— 1651 passed, 7 ignoredcargo test --locked --quiet --lib ssh::ssh_config— 293 passedcargo test --locked --test ssh_config_command_options_advanced_test— 15 passedcargo test --locked --quiet --test ssh_config_dump_test— 21 passedcargo test --locked --quiet --test ssh_compat_output_test— 12 passedV_10_3_P1regressions:cfgparse,sshcfgparse,cfgmatch, andcfginclude— 4/4 passedc3fb91f91ae34e0d6798dcca1e1d289f51a8a389— merge-safe, no feat(cli): implement -G to dump the resolved configuration #282 blockersThe broader
percentregression still contains live runtime and invalid-user cases outside this issue's four acceptance regressions.Closes #282