git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Ensure that SSH runs in non-interactive mode

From
Jeff King <peff@peff.net>
Date
Jul 21, 2008, 00:14 UTC
Message-ID
<20080721001422.GB12454@sigill.intra.peff.net>
In-Reply-To
<7v63r0bejy.fsf@gitster.siamese.dyndns.org>
On Sun, Jul 20, 2008 at 11:23:13AM -0700, Junio C Hamano wrote:
Show 5 quoted lines
> I think that is a very sensible approach, but just like we have a few
> "built-in" function-header regexps with customization possibilities for
> the user, we might want to:
> 
>  * Have that "-x", "-T" in the command line we generate for OpenSSH;

I am slightly negative on this, because we are setting OpenSSH preferences behind the user's back that they would not normally expect git to be tampering with.

I think the expectation for this is that it impacts only the ssh session used by git. But because OpenSSH supports the concept of "master" and "slave" sessions (i.e., it can multiplex many sessions over a single ssh session, avoiding authentication and thus reducing latency until the start of the session), what you do in one session can impact other sessions. In particular, if the 'master' does not have x11 forwarding (because it happens to be started by git), then slave connections do not get it. So a user with X11Forwarding and ControlMaster set in his config would usually have everything work, but bad timing with the git-initiated session as the master would unexpectedly break his X11Forwarding for other sessions.

I don't know how commonly the ControlMaster option for openssh is used. I also don't know if this should simply be considered a bug in openssh, since it silently ignores the request for X forwarding. Personally, I will not be affected because I don't do X forwarding by default, anyway. But I thought I would raise the point.

-Peff
Previous: Steffen ProhaskaNext: Mike Hommey
Message 14 of 16 in “Ensure that SSH runs in non-interactive mode”
  1. Ensure that SSH runs in non-interactive modeFredrik Tolf, Jul 19, 2008
  2. Mike HommeyJul 19, 2008
  3. Keith PackardJul 19, 2008
  4. Fredrik TolfJul 19, 2008
  5. Johannes SchindelinJul 20, 2008
  6. Fredrik TolfJul 20, 2008
  7. Johannes SchindelinJul 20, 2008
  8. Fredrik TolfJul 20, 2008
  9. Junio C HamanoJul 20, 2008
  10. Johannes SchindelinJul 20, 2008
  11. Junio C HamanoJul 20, 2008
  12. Johannes SchindelinJul 20, 2008
  13. Steffen ProhaskaJul 21, 2008
  14. Jeff KingJul 21, 2008
  15. Mike HommeyJul 21, 2008
  16. Jeff KingJul 21, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.