github-actions[bot] opened a new pull request, #72191: URL: https://github.com/apache/airflow/pull/72191
When Breeze runs with --forward-credentials, the host's ~/.ssh is bind-mounted read-write at /root/.ssh and the container start used to operate on it directly. Every start overwrote the user's id_rsa with a throwaway key, appended that key to authorized_keys and three localhost entries to known_hosts (observed to accumulate hundreds of entries), left a dangling authorized_keys2 symlink, and ran 'chmod 600 ~/.ssh/*'. That chmod also strips the execute bit from the ~/.ssh/agent directory that OpenSSH 10.x uses for agent sockets. On macOS this kills the launchd-managed ssh-agent and, after the next reboot, makes every ssh on the host hang waiting on the dead agent socket. The ssh-to-localhost setup, which the real-connection SSH and SFTP provider tests rely on, now lives entirely in /root/.breeze-ssh, a path that is never mounted from the host. sshd accepts the generated key via an sshd_config.d drop-in, the OpenSSH client finds it via an ssh_config.d drop-in, and paramiko-based hooks, which read neither, discover it through an ssh-agent started by the entrypoint. entrypoint_exec.sh exports the agent socket so 'breeze exec' shells get it too. The authorized_keys2 symlink had no consumers anywhere in the repo and is dropped. (cherry picked from commit 51ebe32acc11cf39b168566e1906c26fd063557b) Co-authored-by: Ramit Kataria <[email protected]> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
