github-actions[bot] opened a new pull request, #72191:
URL: https://github.com/apache/airflow/pull/72191

   When Breeze runs with --forward-credentials, the host's ~/.ssh is
   bind-mounted read-write at /root/.ssh and the container start used to
   operate on it directly. Every start overwrote the user's id_rsa with a
   throwaway key, appended that key to authorized_keys and three localhost
   entries to known_hosts (observed to accumulate hundreds of entries), left
   a dangling authorized_keys2 symlink, and ran 'chmod 600 ~/.ssh/*'. That
   chmod also strips the execute bit from the ~/.ssh/agent directory that
   OpenSSH 10.x uses for agent sockets. On macOS this kills the
   launchd-managed ssh-agent and, after the next reboot, makes every ssh on
   the host hang waiting on the dead agent socket.
   
   The ssh-to-localhost setup, which the real-connection SSH and SFTP
   provider tests rely on, now lives entirely in /root/.breeze-ssh, a path
   that is never mounted from the host. sshd accepts the generated key via
   an sshd_config.d drop-in, the OpenSSH client finds it via an ssh_config.d
   drop-in, and paramiko-based hooks, which read neither, discover it
   through an ssh-agent started by the entrypoint. entrypoint_exec.sh
   exports the agent socket so 'breeze exec' shells get it too. The
   authorized_keys2 symlink had no consumers anywhere in the repo and is
   dropped.
   (cherry picked from commit 51ebe32acc11cf39b168566e1906c26fd063557b)
   
   Co-authored-by: Ramit Kataria <[email protected]>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to