2 Commits
Author SHA1 Message Date
jaap-jan 6fc1e3a7c5 Merge pull request 'Say how far a connection has got while it is still being made' (#6) from claude/connection-status-indicator-e52da7 into main
ci / build and test (push) Failing after 2m22s
ci / desktop nightly (push) Skipped
ci / api image (push) Skipped
ci / android head (push) Successful in 3m48s
Reviewed-on: #6
2026-08-10 13:53:06 +00:00
jaap-jan 8a77b7ca68 Say how far a connection has got while it is still being made
ci / build and test (pull_request) Failing after 2m34s
ci / desktop nightly (pull_request) Skipped
ci / api image (pull_request) Skipped
ci / android head (pull_request) Successful in 3m28s
The connecting card set its status string once, when the tab was created, and
never touched it again. Every connection therefore looked identical from the
outside: one three seconds into a key exchange, one waiting out a fifteen-second
timeout against a machine that is asleep, and one that had hung all drew the
same "connecting…". The card now draws the five steps of getting there, each lit
at the moment the handshake reports reaching it, over an amber track that fills
as they finish.

◆ NOTHING ON THE LIST IS INVENTED. Every row changes state because a layer below
it said so, at the instant the thing it names actually began.

That is the whole reason it is worth showing, and it is why most of this commit
is plumbing rather than XAML: there was no progress reporting anywhere in the
stack to hook a step list onto, and a card animating plausible progress would
have been indistinguishable from one that had stopped receiving any.

SshConnectionPhase names four phases and deliberately not more. SSH.NET runs the
entire handshake inside one ConnectAsync and raises exactly one event from the
middle of it — HostKeyReceived, once the key exchange has produced a key to show
— so that event is the only interior moment there is to report. Everything
before it is Reaching and everything after it is Authenticating. A fifth phase
in that assembly would have to be a timer, so there is not one. OpeningShell is
reported by TerminalWorkspace instead, because that is where it happens: the
factory's work ends with an authenticated connection, and asking for a
pseudo-terminal on one is a separate round trip. The SFTP path passes null — a
second connection opened behind an already-open shell has nobody watching a step
list for it.

The card's fifth step, "Starting the terminal", is the renderer wait and lives
in the shell rather than in the SSH assembly, which has never heard of a
renderer. On the first connection after a cold start it is a real wait with a
real failure mode of its own — a missing WebView2 runtime — so a list that began
at "reaching the host" would leave the one wait most likely to hang unnamed.

Amber for the step in flight, and that follows the palette's rule rather than
bending it. Green is what is true and purple is what you can press; a step still
happening is neither, and it is exactly the caveat-worth-reading that amber
exists for. Steps behind it go green as they become true. Nothing animates,
which is the argument TransfersScreen.axaml already makes for its own track,
reaching a screen with far more reason to want a spinner: a spinner is furniture
invented to fill a state nobody measured, and these states are measured, so the
track fills to what has finished and then waits there.

A refusal keeps the step it stopped on, in red, with the ones behind it still
green. That is the half a progress bar could not do, and it is the difference
between "that host is not there" and "that host is there and would not have me"
— a question the reason sentence alone frequently does not settle.

The strip's dot goes amber while a tab is connecting, on both heads. It was
grey, and so is a tab whose shell has exited: the two states in that strip with
the least in common, one worth waiting for and one over. PhoneShell's own
comment already recorded half of this — the dot stopped being green before
anything had answered — and this is the other half.

Progress is raised inline rather than through System.Progress<T>, which captures
whatever synchronisation context it was constructed on and posts to it. That
reads like a convenience and is really a second place the marshalling decision
gets made: silently, differently under a test with no context, and out of order
with respect to the failure that follows a phase. The shell marshals once, in
one handler, through a new optional post parameter on MainWindowViewModel — the
same seam TransfersViewModel already uses, and for the reason its own remark
gives. The three Dispatcher.UIThread.Post calls that predate it are the ones
this suite's comments record as out of reach; they are left alone rather than
swept in here.

Both heads draw the list. They differ in one place: Phone.axaml's mono class
sets a colour and a size along with the family, so the caption rule names its
own family instead of composing the two and asking two rules for one Foreground.
The desktop's mono sets the family alone, which is why ConnectingCard does
compose them. Each head also gains SHOW LOGS beside the button that gives up —
the step list is this attempt and the log is every other one, which is what a
connection taking too long actually raises.

Seven tests, and the two that matter most run against the container rather than
a fake: a real handshake reports its phases in order, and a host-key refusal
never claims to have authenticated. A fake asserting what it was written to
assert would have established nothing about either. The rest cover the tab
advancing while the connection is gated, the step a refusal stops on, and a
phase reported after the user has given up on the tab. 1,861 tests, none
failing.

The Android head's layout is not verified by anything. It compiles, and
compiled bindings mean every new binding path resolves, but that project is not
in DodoSSH.slnx, there is no test project for it and no device here — so unlike
the desktop card, whose shapes the layout harness measures, these rows have not
been drawn. Vertical fit is reasoned, not observed.
2026-08-10 15:47:45 +02:00
22 changed files with 1145 additions and 68 deletions
@@ -436,6 +436,20 @@
<Setter Property="Fill" Value="{StaticResource Live}" /> <Setter Property="Fill" Value="{StaticResource Live}" />
</Style> </Style>
<!--
Amber, and it does not contradict the remark above. That one says green is a fact about a host rather
than an accent, and this is the colour for a fact that is not settled yet: green is what is true, purple
is what you can press, and a connection still being made is neither. The palette's own rule gives amber
to the caveat worth reading, which is exactly what this is.
Only the tab strips use it, and only for a tab with no shell behind it yet — the same amber, from the
same brush, as the track and the running step on the connecting screen, so that a tab and the screen it
opens agree about what is happening. See TerminalScreen.axaml.
-->
<Style Selector="Ellipse.dot.connecting">
<Setter Property="Fill" Value="{StaticResource Warn}" />
</Style>
<!-- Every label, count, address and fingerprint in this design is monospace. See Palette.axaml. --> <!-- Every label, count, address and fingerprint in this design is monospace. See Palette.axaml. -->
<Style Selector="TextBlock.mono"> <Style Selector="TextBlock.mono">
<Setter Property="FontFamily" Value="{StaticResource MonoFont}" /> <Setter Property="FontFamily" Value="{StaticResource MonoFont}" />
@@ -320,8 +320,14 @@
which was true when a tab could not exist without a session; one can now — which was true when a tab could not exist without a session; one can now —
connecting opens the tab first — and a dot that was green before anything had connecting opens the tab first — and a dot that was green before anything had
answered would be the one thing on this strip claiming something untrue. answered would be the one thing on this strip claiming something untrue.
Amber while it is being made, which is the other half of that correction. Not being
green stopped the dot lying, but it left a tab still dialling drawn exactly like a
tab whose shell has exited — the two states on this strip with the least in common,
one worth waiting for and one over. See Phone.axaml.
--> -->
<Ellipse Classes="dot" Classes.live="{Binding IsLive}" Width="6" Height="6" <Ellipse Classes="dot" Classes.live="{Binding IsLive}"
Classes.connecting="{Binding IsConnecting}" Width="6" Height="6"
VerticalAlignment="Center" /> VerticalAlignment="Center" />
<TextBlock Classes="mono" FontSize="11" Text="{Binding Label}" /> <TextBlock Classes="mono" FontSize="11" Text="{Binding Label}" />
</StackPanel> </StackPanel>
@@ -33,6 +33,85 @@
gesture does the same thing the arrow does. gesture does the same thing the arrow does.
--> -->
<UserControl.Styles>
<!--
── the connecting step list ─────────────────────────────────────────────────────────────────────
The same five rows the desktop's ConnectingCard draws, from the same reported phases, in this head's
own sizes. Kept here rather than in Phone.axaml because nothing else on this head has a step list —
the theme file is for what more than one screen shares, and a rule that exists for one control is
easier to read beside it.
Amber for the step in flight, green behind it, red where it stopped. That is the palette's rule
rather than an exception to it: green is what is true and purple is what you can press, and a step
still happening is neither. See ConnectingCard.axaml for the longer version of this argument, and
Palette.axaml for the rule itself.
A phone needs this more than a desktop does, which is the same thing the connecting block below
already says about itself: mobile links are slower and drop more often, so the stretch this describes
is longer here and more likely to end badly.
-->
<!--
Its own FontFamily rather than the row also carrying the mono class, which is this head's convention
and not a stylistic preference: Phone.axaml's mono sets a colour and a size along with the family, so
a caption wearing both classes would be asking two rules for one Foreground and settling it on style
ordering. Every other text class here — body, label, title, detail — names its own family for exactly
that reason. The desktop's mono sets the family alone, which is why ConnectingCard composes the two
and this does not.
-->
<Style Selector="TextBlock.stepcaption">
<Setter Property="FontFamily" Value="{StaticResource MonoFont}" />
<Setter Property="Foreground" Value="{StaticResource TextFaint}" />
<Setter Property="FontSize" Value="11" />
<Setter Property="VerticalAlignment" Value="Center" />
</Style>
<Style Selector="TextBlock.stepcaption.done">
<Setter Property="Foreground" Value="{StaticResource TextDim}" />
</Style>
<Style Selector="TextBlock.stepcaption.running">
<Setter Property="Foreground" Value="{StaticResource WarnText}" />
<Setter Property="FontWeight" Value="SemiBold" />
</Style>
<Style Selector="TextBlock.stepcaption.stopped">
<Setter Property="Foreground" Value="{StaticResource DangerText}" />
</Style>
<!-- Fixed width and centred: four different characters on a ragged edge is a list that looks broken. -->
<Style Selector="TextBlock.stepmark">
<Setter Property="Foreground" Value="{StaticResource BorderMid}" />
<Setter Property="FontSize" Value="11" />
<Setter Property="Width" Value="13" />
<Setter Property="TextAlignment" Value="Center" />
<Setter Property="VerticalAlignment" Value="Center" />
</Style>
<Style Selector="TextBlock.stepmark.done">
<Setter Property="Foreground" Value="{StaticResource Live}" />
</Style>
<Style Selector="TextBlock.stepmark.running">
<Setter Property="Foreground" Value="{StaticResource Warn}" />
</Style>
<Style Selector="TextBlock.stepmark.stopped">
<Setter Property="Foreground" Value="{StaticResource Danger}" />
</Style>
<!--
4 rather than the desktop's 5, which is the only deliberate difference between the two heads here:
this bar sits in a column 24 from each edge of a 360dp screen rather than under a 460-wide card, so
the same height reads as a heavier rule across a narrower span.
-->
<Style Selector="ProgressBar.steptrack">
<Setter Property="Height" Value="4" />
<Setter Property="MinHeight" Value="4" />
<Setter Property="CornerRadius" Value="2" />
<Setter Property="Background" Value="{StaticResource Chip}" />
<Setter Property="Foreground" Value="{StaticResource Warn}" />
</Style>
<Style Selector="ProgressBar.steptrack.stopped">
<Setter Property="Foreground" Value="{StaticResource Danger}" />
</Style>
</UserControl.Styles>
<Panel> <Panel>
<Grid RowDefinitions="Auto,*,Auto"> <Grid RowDefinitions="Auto,*,Auto">
@@ -97,8 +176,12 @@
Command="{Binding $parent[views:TerminalScreen].((vm:MainWindowViewModel)DataContext).SelectTabCommand}" Command="{Binding $parent[views:TerminalScreen].((vm:MainWindowViewModel)DataContext).SelectTabCommand}"
CommandParameter="{Binding}"> CommandParameter="{Binding}">
<StackPanel Orientation="Horizontal" Spacing="7" VerticalAlignment="Center"> <StackPanel Orientation="Horizontal" Spacing="7" VerticalAlignment="Center">
<!-- Green only while there is a shell behind it; see the same dot in PhoneShell. --> <!--
<Ellipse Classes="dot" Classes.live="{Binding IsLive}" Width="6" Height="6" Green only while there is a shell behind it, amber while one is being made; see
the same dot in PhoneShell, and Phone.axaml for why amber is not a rule broken.
-->
<Ellipse Classes="dot" Classes.live="{Binding IsLive}"
Classes.connecting="{Binding IsConnecting}" Width="6" Height="6"
VerticalAlignment="Center" /> VerticalAlignment="Center" />
<TextBlock Classes="mono" FontSize="12" FontWeight="SemiBold" <TextBlock Classes="mono" FontSize="12" FontWeight="SemiBold"
Text="{Binding Label}" /> Text="{Binding Label}" />
@@ -284,11 +367,70 @@
<TextBlock Classes="title" FontSize="13" Text="{Binding SelectedTab.Label}" /> <TextBlock Classes="title" FontSize="13" Text="{Binding SelectedTab.Label}" />
<TextBlock Classes="detail" FontSize="11" Foreground="{StaticResource TextDim}" <TextBlock Classes="detail" FontSize="11" Foreground="{StaticResource TextDim}"
TextWrapping="Wrap" Text="{Binding SelectedTab.Address}" /> TextWrapping="Wrap" Text="{Binding SelectedTab.Address}" />
<TextBlock Classes="body" Text="{Binding SelectedTab.Status}" />
<Button Classes="row" MinHeight="44" Padding="14,0" HorizontalAlignment="Left" <!--
Where a single unchanging "connecting…" used to be. The track counts steps that really finished
against the five there are — StepsDone over StepCount, never a percentage, because the arithmetic
that makes a percentage is the arithmetic that starts inventing one. See TerminalTabViewModel.
Drawn for both states rather than once per state: a refused connection has the same five rows and
the same track, and the only differences are that one row is red and the track stops where it got
to. Two templates kept identical for the sake of a colour is how the two drift apart.
-->
<ProgressBar Classes="steptrack" Classes.stopped="{Binding SelectedTab.IsFailed}"
Minimum="0" Maximum="{Binding SelectedTab.StepCount}"
Value="{Binding SelectedTab.StepsDone, Mode=OneWay}" />
<ItemsControl ItemsSource="{Binding SelectedTab.Steps}">
<ItemsControl.ItemsPanel>
<ItemsPanelTemplate>
<StackPanel Spacing="6" />
</ItemsPanelTemplate>
</ItemsControl.ItemsPanel>
<ItemsControl.ItemTemplate>
<DataTemplate x:DataType="vm:ConnectionStepViewModel">
<StackPanel Orientation="Horizontal" Spacing="9">
<TextBlock Classes="stepmark"
Classes.done="{Binding IsDone}"
Classes.running="{Binding IsRunning}"
Classes.stopped="{Binding IsStopped}"
Text="{Binding Mark}" />
<TextBlock Classes="stepcaption"
Classes.done="{Binding IsDone}"
Classes.running="{Binding IsRunning}"
Classes.stopped="{Binding IsStopped}"
Text="{Binding Caption}" />
</StackPanel>
</DataTemplate>
</ItemsControl.ItemTemplate>
</ItemsControl>
<!--
Only for a refusal now. While a connection is being made this used to be the whole of what this
screen said, and it is now the step list's running row said twice — so it is shown for the one
state the list cannot put into words: why it stopped.
-->
<TextBlock Classes="body" Text="{Binding SelectedTab.Status}"
Foreground="{StaticResource Danger}"
IsVisible="{Binding SelectedTab.IsFailed}" />
<!--
Two 44-high targets side by side rather than one, and the second is the logs: the step list is
this attempt and the log is every other one, which is the question a connection that is taking too
long on a mobile link actually raises — has this machine ever worked from here. Reached the
ordinary way, through ShowScreenCommand, exactly as the rail and MORE reach it.
-->
<StackPanel Orientation="Horizontal" Spacing="8" HorizontalAlignment="Left">
<Button Classes="row" MinHeight="44" Padding="14,0"
Command="{Binding CloseTabCommand}" CommandParameter="{Binding SelectedTab}"> Command="{Binding CloseTabCommand}" CommandParameter="{Binding SelectedTab}">
<TextBlock Classes="label" FontSize="9" Text="CLOSE THIS TAB" /> <TextBlock Classes="label" FontSize="9" Text="CLOSE THIS TAB" />
</Button> </Button>
<Button Classes="row" MinHeight="44" Padding="14,0"
Command="{Binding ShowScreenCommand}"
CommandParameter="{x:Static vm:ShellScreen.Logs}">
<TextBlock Classes="label" FontSize="9" Text="SHOW LOGS" />
</Button>
</StackPanel>
</StackPanel> </StackPanel>
<!-- <!--
+10
View File
@@ -1169,6 +1169,16 @@
<Setter Property="Fill" Value="{StaticResource Live}" /> <Setter Property="Fill" Value="{StaticResource Live}" />
</Style> </Style>
<!--
Amber, and it does not contradict the rule above it. Green is what is true and this is not yet true;
purple is what you can press and a dot is not pressable. What is left is the caveat colour, which is
exactly what a connection still being made is. The same amber the connecting card's track uses, from
the same brush, so that the tab and the card the tab opens agree.
-->
<Style Selector="Ellipse.dot.connecting">
<Setter Property="Fill" Value="{StaticResource Warn}" />
</Style>
<!-- <!--
The accent strip a selected row carries, drawn by the row template rather than by the item, because the The accent strip a selected row carries, drawn by the row template rather than by the item, because the
item's presenter is the thing the theme keeps repainting. item's presenter is the thing the theme keeps repainting.
+134 -14
View File
@@ -15,6 +15,28 @@
Showing the last terminal's pane would be a lie, and showing nothing reads as the application having Showing the last terminal's pane would be a lie, and showing nothing reads as the application having
broken, so this says which machine, as whom, and how far along it is. broken, so this says which machine, as whom, and how far along it is.
── The step list, and why it is amber ───────────────────────────────────────────────────────────────
"How far along it is" used to be one line of prose that never changed after the tab was created, which
made every slow connection look exactly like every hung one. It is now the five steps of actually
getting there, each lit at the moment the handshake reports it — see SshConnectionPhase, which names
only the boundaries a client can genuinely observe. A connection that stops therefore stops on a named
row, and "the host key is being checked" stops being the same screen as "the host is not answering".
Amber for the step in flight, and that is the palette's rule rather than an exception to it. Green is
what is true and purple is what you can press; a step still happening is neither, and it is precisely
the caveat-worth-reading amber exists for — see the remark above Warn in Palette.axaml. Steps behind it
go green as they become true, and the one a refusal landed on goes red. Nothing on the list is drawn in
the accent, because there is nothing on it to press.
Nothing here animates, which is the argument the transfer strip makes for its own track in
TransfersScreen.axaml, arriving at a screen with more reason to want a spinner. A spinner is furniture
invented to fill a state nobody measured; these steps are measured, so the track fills to what has
actually finished and then waits there. Waiting is what waiting looks like.
The list is drawn for both states rather than once per state. A refused connection has the same five
rows and the same track — the difference is only that one row is red and the track stops — and drawing
it twice would be two templates to keep identical for the sake of a colour.
It obeys the occlusion rule the whole window obeys: this is Avalonia-drawn content in the WebView's own It obeys the occlusion rule the whole window obeys: this is Avalonia-drawn content in the WebView's own
rectangle, so the shell collapses the terminal while it is up. IsTerminalShowing and IsConnectingShowing rectangle, so the shell collapses the terminal while it is up. IsTerminalShowing and IsConnectingShowing
are exclusive by construction — a selected tab either has a session or it does not — which is what makes are exclusive by construction — a selected tab either has a session or it does not — which is what makes
@@ -24,8 +46,69 @@
can be laid out by a test: WebView2's adapter refuses the headless session's thread. can be laid out by a test: WebView2's adapter refuses the headless session's thread.
--> -->
<UserControl.Styles>
<!--
A rule per lit state over one quiet default, so that the pending weight is stated once and each state
that differs from it is the one line that says how.
-->
<Style Selector="TextBlock.stepcaption">
<Setter Property="Foreground" Value="{StaticResource TextFaint}" />
<Setter Property="FontSize" Value="12" />
<Setter Property="VerticalAlignment" Value="Center" />
</Style>
<Style Selector="TextBlock.stepcaption.done">
<Setter Property="Foreground" Value="{StaticResource TextDim}" />
</Style>
<Style Selector="TextBlock.stepcaption.running">
<Setter Property="Foreground" Value="{StaticResource WarnText}" />
<Setter Property="FontWeight" Value="Medium" />
</Style>
<Style Selector="TextBlock.stepcaption.stopped">
<Setter Property="Foreground" Value="{StaticResource DangerText}" />
</Style>
<!--
The marker beside each caption. Fixed width and centred, because four different characters on a
ragged left edge is a list that looks broken; see ConnectionStepViewModel.Mark for which they are.
-->
<Style Selector="TextBlock.stepmark">
<Setter Property="Foreground" Value="{StaticResource BorderMid}" />
<Setter Property="FontSize" Value="12" />
<Setter Property="Width" Value="14" />
<Setter Property="TextAlignment" Value="Center" />
<Setter Property="VerticalAlignment" Value="Center" />
</Style>
<Style Selector="TextBlock.stepmark.done">
<Setter Property="Foreground" Value="{StaticResource Live}" />
</Style>
<Style Selector="TextBlock.stepmark.running">
<Setter Property="Foreground" Value="{StaticResource Warn}" />
</Style>
<Style Selector="TextBlock.stepmark.stopped">
<Setter Property="Foreground" Value="{StaticResource Danger}" />
</Style>
<!--
The track over the list. Amber while the attempt is alive and red once it is not, so that the bar says
the same thing as the row it stopped on rather than staying the colour of something still being waited
for. Chip underneath, matching the transfer strip's track.
-->
<Style Selector="ProgressBar.steptrack">
<Setter Property="Height" Value="5" />
<Setter Property="MinHeight" Value="5" />
<Setter Property="CornerRadius" Value="3" />
<Setter Property="Background" Value="{StaticResource Chip}" />
<Setter Property="Foreground" Value="{StaticResource Warn}" />
</Style>
<Style Selector="ProgressBar.steptrack.stopped">
<Setter Property="Foreground" Value="{StaticResource Danger}" />
</Style>
</UserControl.Styles>
<Panel> <Panel>
<StackPanel VerticalAlignment="Center" HorizontalAlignment="Center" Spacing="14" MaxWidth="460" <StackPanel VerticalAlignment="Center" HorizontalAlignment="Center" Spacing="18" MaxWidth="460"
Margin="24"> Margin="24">
<StackPanel Spacing="6" HorizontalAlignment="Center"> <StackPanel Spacing="6" HorizontalAlignment="Center">
@@ -38,15 +121,43 @@
</StackPanel> </StackPanel>
<!-- <!--
Two states, deliberately different. Waiting is an accent line under the host's name; a refusal is Bound to StepsDone against StepCount rather than to a percentage: five steps and a maximum of five
the reason, in the palette's red, because it is the only place the reason will be after the user means the bar is a count of things that really finished, and the arithmetic that would turn it into
navigates away from the screen that started the connection. a percentage is exactly the arithmetic that would start inventing one.
--> -->
<TextBlock Classes="mono" Text="{Binding SelectedTab.Status}" FontSize="12" <ProgressBar Classes="steptrack" Classes.stopped="{Binding SelectedTab.IsFailed}"
Foreground="{StaticResource Accent}" HorizontalAlignment="Center" Minimum="0" Maximum="{Binding SelectedTab.StepCount}"
TextWrapping="Wrap" TextAlignment="Center" Value="{Binding SelectedTab.StepsDone, Mode=OneWay}" />
IsVisible="{Binding SelectedTab.IsConnecting}" />
<ItemsControl ItemsSource="{Binding SelectedTab.Steps}" HorizontalAlignment="Center">
<ItemsControl.ItemsPanel>
<ItemsPanelTemplate>
<StackPanel Spacing="7" />
</ItemsPanelTemplate>
</ItemsControl.ItemsPanel>
<ItemsControl.ItemTemplate>
<DataTemplate x:DataType="vm:ConnectionStepViewModel">
<StackPanel Orientation="Horizontal" Spacing="10">
<TextBlock Classes="stepmark"
Classes.done="{Binding IsDone}"
Classes.running="{Binding IsRunning}"
Classes.stopped="{Binding IsStopped}"
Text="{Binding Mark}" />
<TextBlock Classes="stepcaption mono"
Classes.done="{Binding IsDone}"
Classes.running="{Binding IsRunning}"
Classes.stopped="{Binding IsStopped}"
Text="{Binding Caption}" />
</StackPanel>
</DataTemplate>
</ItemsControl.ItemTemplate>
</ItemsControl>
<!--
A refusal is the reason, in the palette's red, because it is the only place the reason will be after
the user navigates away from the screen that started the connection. It sits under the list rather
than replacing it: which row it stopped on is half the answer and the sentence is the other half.
-->
<SelectableTextBlock Text="{Binding SelectedTab.Status}" FontSize="13" <SelectableTextBlock Text="{Binding SelectedTab.Status}" FontSize="13"
Foreground="{StaticResource Danger}" HorizontalAlignment="Center" Foreground="{StaticResource Danger}" HorizontalAlignment="Center"
TextWrapping="Wrap" TextAlignment="Center" TextWrapping="Wrap" TextAlignment="Center"
@@ -62,14 +173,23 @@
handshake that finishes afterwards is adopted rather than dropped — see handshake that finishes afterwards is adopted rather than dropped — see
MainWindowViewModel.CloseTabAsync. Two buttons rather than one with a converted label, because the MainWindowViewModel.CloseTabAsync. Two buttons rather than one with a converted label, because the
two are different decisions and only one of them abandons something still running. two are different decisions and only one of them abandons something still running.
-->
<Button Classes="ghost" HorizontalAlignment="Center" Content="GIVE UP"
Command="{Binding CloseTabCommand}" CommandParameter="{Binding SelectedTab}"
IsVisible="{Binding SelectedTab.IsConnecting}" />
<Button Classes="ghost" HorizontalAlignment="Center" Content="CLOSE TAB" Beside each, the logs. The step list is this attempt and the log is every other one, which is the
Command="{Binding CloseTabCommand}" CommandParameter="{Binding SelectedTab}" question both a connection taking too long and a connection just refused actually raise — has this
machine ever worked. It is the ordinary rail destination reached the ordinary way rather than a
second log grown inside this card, and leaving by it does not abandon the handshake: the tab stays
in the strip and the card is still here on the way back.
-->
<StackPanel Orientation="Horizontal" Spacing="10" HorizontalAlignment="Center">
<Button Classes="ghost" Content="SHOW LOGS" Command="{Binding ShowScreenCommand}"
CommandParameter="{x:Static vm:ShellScreen.Logs}" />
<Button Classes="ghost" Content="GIVE UP" Command="{Binding CloseTabCommand}"
CommandParameter="{Binding SelectedTab}"
IsVisible="{Binding SelectedTab.IsConnecting}" />
<Button Classes="ghost" Content="CLOSE TAB" Command="{Binding CloseTabCommand}"
CommandParameter="{Binding SelectedTab}"
IsVisible="{Binding SelectedTab.IsFailed}" /> IsVisible="{Binding SelectedTab.IsFailed}" />
</StackPanel>
</StackPanel> </StackPanel>
</Panel> </Panel>
@@ -60,12 +60,23 @@
ToolTip.Tip="{Binding Address}"> ToolTip.Tip="{Binding Address}">
<StackPanel Orientation="Horizontal" Spacing="9" VerticalAlignment="Center"> <StackPanel Orientation="Horizontal" Spacing="9" VerticalAlignment="Center">
<!-- <!--
Two states, as the strip's own dots always were: green while the shell behind this tab is Three states now, where there were two. Green while the shell behind this tab is running
running, grey while it is connecting and once it has ended. The design's third, amber, and grey once it has ended, as the strip's dots always were — and amber while it is
state has no meaning here — nothing in this application checks whether a host is merely connecting, which used to be grey as well.
reachable — so it is not drawn; see design-notes/v5b-fidelity-notes.md.
The design's amber had no meaning here while nothing in this application knew how far a
connection had got; that changed with the step list, and the note this comment used to
carry — that amber is for a host merely reachable, so it is not drawn — is answered
rather than ignored. It is not being reachable that is amber, it is being underway. See
ConnectingCard.axaml, whose track and running step are the same colour for the same
reason, and design-notes/v5b-fidelity-notes.md for the state this is not.
Worth the third colour because the two it replaces were the same one: a tab still
dialling and a tab whose shell has exited both drew grey, which are the two states in
this strip with the least in common — one is worth waiting for and the other is over.
--> -->
<Ellipse Classes="dot" Width="8" Height="8" Classes.live="{Binding IsLive}" <Ellipse Classes="dot" Width="8" Height="8" Classes.live="{Binding IsLive}"
Classes.connecting="{Binding IsConnecting}"
VerticalAlignment="Center" /> VerticalAlignment="Center" />
<TextBlock Text="{Binding Label}" VerticalAlignment="Center" /> <TextBlock Text="{Binding Label}" VerticalAlignment="Center" />
@@ -328,6 +328,9 @@ internal sealed partial class MainWindowViewModel : ObservableObject, IAsyncDisp
/// </remarks> /// </remarks>
private readonly Func<string, Task>? copyToClipboard; private readonly Func<string, Task>? copyToClipboard;
/// <inheritdoc cref="MainWindowViewModel(ClientPaths, ClientCacheFactory, TerminalWorkspace, VaultKnownHostStore, IDeviceKeyStore, SignInHandler, TimeProvider, ISftpSessionFactory, Argon2Profile?, ResumeHandler?, Func{string, Task}?, string?, IUpdateChannel?, Action{Action}?)" path="/param[@name='post']" />
private readonly Action<Action> post;
/// <remarks> /// <remarks>
/// Created once and kept for the life of the process, like <see cref="workspace"/> and for the same /// Created once and kept for the life of the process, like <see cref="workspace"/> and for the same
/// reason: file transfer opens its own authenticated connection, and locking the vault must not destroy /// reason: file transfer opens its own authenticated connection, and locking the vault must not destroy
@@ -470,6 +473,19 @@ internal sealed partial class MainWindowViewModel : ObservableObject, IAsyncDisp
/// absence of a line rather than by a line somebody has to remember to keep a no-op; and ADR 0011 settles /// absence of a line rather than by a line somebody has to remember to keep a no-op; and ADR 0011 settles
/// the Android head's distribution separately, so it must never acquire one by accident. /// the Android head's distribution separately, so it must never acquire one by accident.
/// </param> /// </param>
/// <param name="post">
/// Runs an action on the thread this shell's view models are read from. Defaults to the UI thread's
/// dispatcher, which is the answer in every real head.
/// <para>
/// A delegate rather than <c>Dispatcher.UIThread</c> reached directly, for exactly the reason
/// <c>TransfersViewModel</c>'s is one — see the remark there. It is process-wide and belongs to whichever
/// thread touched it first, so a suite that runs with no window has no way to drain it and no way to
/// know whose it is. This one exists because connection phases are reported from the handshake's own
/// thread, which is the first thing in this class that has to cross onto the UI thread and also has to
/// be assertable: the three <c>Dispatcher.UIThread.Post</c> calls that predate it are the ones this
/// suite's own comments record as out of reach, and they are left alone rather than swept in here.
/// </para>
/// </param>
internal MainWindowViewModel( internal MainWindowViewModel(
ClientPaths paths, ClientPaths paths,
ClientCacheFactory caches, ClientCacheFactory caches,
@@ -483,8 +499,11 @@ internal sealed partial class MainWindowViewModel : ObservableObject, IAsyncDisp
ResumeHandler? resume = null, ResumeHandler? resume = null,
Func<string, Task>? copyToClipboard = null, Func<string, Task>? copyToClipboard = null,
string? deviceName = null, string? deviceName = null,
IUpdateChannel? updates = null) IUpdateChannel? updates = null,
Action<Action>? post = null)
{ {
this.post = post ?? (action => Dispatcher.UIThread.Post(action));
this.paths = paths; this.paths = paths;
this.caches = caches; this.caches = caches;
this.workspace = workspace; this.workspace = workspace;
@@ -3243,7 +3262,7 @@ internal sealed partial class MainWindowViewModel : ObservableObject, IAsyncDisp
oldValue.PropertyChanged -= OnVaultPropertyChanged; oldValue.PropertyChanged -= OnVaultPropertyChanged;
oldValue.Hosts.CollectionChanged -= OnVaultHostsChanged; oldValue.Hosts.CollectionChanged -= OnVaultHostsChanged;
// The three connection events are kept while an attempt is still in flight, and that is not an // The four connection events are kept while an attempt is still in flight, and that is not an
// oversight. Locking does not end a handshake any more than it ends a shell — the workspace is // oversight. Locking does not end a handshake any more than it ends a shell — the workspace is
// what holds both, and it outlives every vault — so a connection started just before a lock still // what holds both, and it outlives every vault — so a connection started just before a lock still
// has an answer coming, and the tab standing in for it is still in the strip afterwards, because // has an answer coming, and the tab standing in for it is still in the strip afterwards, because
@@ -3257,6 +3276,7 @@ internal sealed partial class MainWindowViewModel : ObservableObject, IAsyncDisp
if (attempts.Count == 0) if (attempts.Count == 0)
{ {
oldValue.ConnectionStarting -= OnVaultConnectionStarting; oldValue.ConnectionStarting -= OnVaultConnectionStarting;
oldValue.ConnectionProgress -= OnVaultConnectionProgress;
oldValue.ConnectionFailed -= OnVaultConnectionFailed; oldValue.ConnectionFailed -= OnVaultConnectionFailed;
oldValue.SessionOpened -= OnVaultSessionOpened; oldValue.SessionOpened -= OnVaultSessionOpened;
} }
@@ -3265,6 +3285,7 @@ internal sealed partial class MainWindowViewModel : ObservableObject, IAsyncDisp
if (newValue is not null) if (newValue is not null)
{ {
newValue.ConnectionStarting += OnVaultConnectionStarting; newValue.ConnectionStarting += OnVaultConnectionStarting;
newValue.ConnectionProgress += OnVaultConnectionProgress;
newValue.ConnectionFailed += OnVaultConnectionFailed; newValue.ConnectionFailed += OnVaultConnectionFailed;
newValue.SessionOpened += OnVaultSessionOpened; newValue.SessionOpened += OnVaultSessionOpened;
newValue.PropertyChanged += OnVaultPropertyChanged; newValue.PropertyChanged += OnVaultPropertyChanged;
@@ -3406,6 +3427,41 @@ internal sealed partial class MainWindowViewModel : ObservableObject, IAsyncDisp
AdoptTab(tab); AdoptTab(tab);
} }
/// <summary>
/// Moves a connecting tab's step list on, from the handshake's own report.
/// </summary>
/// <remarks>
/// <para>
/// The one place the phases raised by <c>VaultViewModel.ConnectionProgress</c> are marshalled, and the
/// reason that event does not marshal for itself: doing it here means it happens once, visibly, at the
/// only boundary that cares — everything this touches is a view model an Avalonia binding is attached to.
/// </para>
/// <para>
/// Posted unconditionally rather than applied inline when it looks safe. Some phases really do arrive
/// on this thread — the first is reported before the handshake has yielded at all — and a
/// <c>CheckAccess</c> fast path for them would buy one dispatcher turn on a card that is up for seconds,
/// at the price of the two orderings existing at once and only one of them being the one a test runs.
/// </para>
/// <para>
/// A step that arrives after the attempt has settled is harmless and needs no guard here:
/// <see cref="TerminalTabViewModel.Advance"/> ignores anything reported to a tab that is no longer
/// connecting, which is what a posted phase landing behind its own <see cref="OnVaultSessionOpened"/>
/// looks like.
/// </para>
/// <para>
/// A report for an attempt with no tab is dropped, exactly as the other two handlers drop one: the user
/// closed the connecting tab and there is nothing left to draw a step on. The handshake is not affected
/// and its session is still adopted if it opens.
/// </para>
/// </remarks>
private void OnVaultConnectionProgress(object? sender, ConnectionProgressEventArgs e) => post(() =>
{
if (attempts.TryGetValue(e.AttemptId, out var tab))
{
tab.Advance(e.Step);
}
});
/// <summary> /// <summary>
/// Redraws the vault menu after a synchronisation pass found a vault this account had not seen. /// Redraws the vault menu after a synchronisation pass found a vault this account had not seen.
/// </summary> /// </summary>
@@ -1,7 +1,129 @@
using CommunityToolkit.Mvvm.ComponentModel; using CommunityToolkit.Mvvm.ComponentModel;
using DodoSSH.Client.Ssh;
namespace DodoSSH.Client.Shell.ViewModels; namespace DodoSSH.Client.Shell.ViewModels;
/// <summary>
/// One named part of making a connection, in the order they happen.
/// </summary>
/// <remarks>
/// <para>
/// <see cref="SshConnectionPhase"/> with one more at the front. The SSH assembly reports four phases and
/// knows about no others, which is correct for it — it has never heard of a renderer. But the first thing a
/// connection here waits on is the terminal page attaching its socket, and on the first connection after a
/// cold start that is a real wait with a real failure mode of its own: a missing WebView2 runtime. A step
/// list that began at "reaching the host" would leave the one wait most likely to hang unnamed.
/// </para>
/// <para>
/// Declared here rather than shared with the SSH layer for that reason, and the mapping between the two is
/// one <c>switch</c> in <c>VaultViewModel</c>. The numbering is the order and the order is load-bearing:
/// <see cref="TerminalTabViewModel.Advance"/> compares these values to decide what is already behind it.
/// </para>
/// </remarks>
internal enum ConnectionStep
{
/// <summary>Waiting for the renderer to attach, before anything is dialled.</summary>
PreparingTerminal = 0,
/// <inheritdoc cref="SshConnectionPhase.Reaching" />
Reaching = 1,
/// <inheritdoc cref="SshConnectionPhase.CheckingHostKey" />
CheckingHostKey = 2,
/// <inheritdoc cref="SshConnectionPhase.Authenticating" />
Authenticating = 3,
/// <inheritdoc cref="SshConnectionPhase.OpeningShell" />
OpeningShell = 4,
}
/// <summary>How one step of a connection is getting on.</summary>
/// <remarks>
/// Four states rather than a bool per row, because a step list is read as a sequence and the reader's
/// question at each row is which of the four this is: behind us, happening, not yet, or where it stopped.
/// <see cref="Stopped"/> exists only for the row a failure landed on — see
/// <see cref="TerminalTabViewModel.Failed"/> — and is what turns the list from a progress bar into an
/// account of how far the attempt got.
/// </remarks>
internal enum ConnectionStepState
{
/// <summary>Not started. Nothing is known about it yet.</summary>
Pending = 0,
/// <summary>Happening now.</summary>
Running = 1,
/// <summary>Finished, because something after it started.</summary>
Done = 2,
/// <summary>Where the attempt stopped. There is no step after this one.</summary>
Stopped = 3,
}
/// <summary>One row of the connecting card's step list.</summary>
/// <remarks>
/// A view model per step rather than an index the view compares against, because each row draws its own
/// state and an <c>ItemsControl</c> has no way to ask "am I before the current one?" — the alternative was a
/// converter taking two bindings, which is the same comparison written somewhere it cannot be tested.
/// </remarks>
internal sealed partial class ConnectionStepViewModel : ObservableObject
{
internal ConnectionStepViewModel(ConnectionStep step, string caption)
{
Step = step;
Caption = caption;
}
/// <summary>Which step this is.</summary>
internal ConnectionStep Step { get; }
/// <summary>What the row says, in the present tense of the thing being waited on.</summary>
internal string Caption { get; }
/// <inheritdoc cref="ConnectionStepState" />
[ObservableProperty]
private ConnectionStepState state;
/// <summary>Whether this step is the one happening now.</summary>
internal bool IsRunning => State is ConnectionStepState.Running;
/// <summary>Whether this step finished.</summary>
internal bool IsDone => State is ConnectionStepState.Done;
/// <summary>Whether the attempt stopped on this step.</summary>
internal bool IsStopped => State is ConnectionStepState.Stopped;
/// <summary>
/// The character drawn beside the caption for whichever state this is in.
/// </summary>
/// <remarks>
/// Here rather than in a converter for the reason <c>TransferRowViewModel.StatusWord</c> is: the mapping
/// is four cases with no arithmetic, and a converter would put it in a file the shell's tests cannot
/// reach. The colours stay in the view, where the palette is.
/// <para>
/// Four distinguishable shapes rather than one recoloured, because the difference between a step that
/// finished and a step still running has to survive somebody who cannot tell this design's green from
/// its amber.
/// </para>
/// </remarks>
internal string Mark => State switch
{
ConnectionStepState.Done => "✓",
ConnectionStepState.Running => "●",
ConnectionStepState.Stopped => "✕",
_ => "○",
};
partial void OnStateChanged(ConnectionStepState value)
{
OnPropertyChanged(nameof(IsRunning));
OnPropertyChanged(nameof(IsDone));
OnPropertyChanged(nameof(IsStopped));
OnPropertyChanged(nameof(Mark));
}
}
/// <summary> /// <summary>
/// How far along a tab's connection is. /// How far along a tab's connection is.
/// </summary> /// </summary>
@@ -57,8 +179,23 @@ internal sealed partial class TerminalTabViewModel : ObservableObject
{ {
Label = label; Label = label;
Address = address; Address = address;
status = "connecting…";
isLive = false; isLive = false;
Steps =
[
new ConnectionStepViewModel(ConnectionStep.PreparingTerminal, "Starting the terminal"),
new ConnectionStepViewModel(ConnectionStep.Reaching, "Reaching the host"),
new ConnectionStepViewModel(ConnectionStep.CheckingHostKey, "Checking the host key"),
new ConnectionStepViewModel(ConnectionStep.Authenticating, "Signing in"),
new ConnectionStepViewModel(ConnectionStep.OpeningShell, "Opening the shell"),
];
// The first step is running before anything is awaited, because it is: the tab is created in the
// same turn as the click and the renderer wait starts immediately after. A list that opened with
// every row pending would show a connection that had not begun, which is one turn of the dispatcher
// away from being untrue and is the turn the card is first drawn in.
status = Steps[0].Caption;
Steps[0].State = ConnectionStepState.Running;
} }
/// <summary>A tab for a session that is already open.</summary> /// <summary>A tab for a session that is already open.</summary>
@@ -72,6 +209,12 @@ internal sealed partial class TerminalTabViewModel : ObservableObject
state = TerminalTabState.Open; state = TerminalTabState.Open;
status = string.Empty; status = string.Empty;
isLive = true; isLive = true;
// A session that already exists got through every step by definition, even though this tab watched
// none of them happen — an adopted session is one whose connecting tab the user closed. The list is
// never drawn for a tab in this state; it is filled in so that nothing downstream has to treat "open"
// as a fourth answer to "how far did it get".
CompleteSteps();
} }
/// <summary> /// <summary>
@@ -128,6 +271,36 @@ internal sealed partial class TerminalTabViewModel : ObservableObject
/// </remarks> /// </remarks>
internal string? IdentityLabel { get; set; } internal string? IdentityLabel { get; set; }
/// <summary>
/// How far this connection got, step by step, for the card that stands in for the pane.
/// </summary>
/// <remarks>
/// <para>
/// Fixed at construction and never added to or removed from — the steps of a connection are known before
/// it starts, and only their state changes — so a plain array is enough and the view needs no collection
/// change notification for it.
/// </para>
/// <para>
/// <b>Every row here is reported, not guessed.</b> The states come from
/// <see cref="SshConnectionPhase"/>, raised by the handshake itself at the moment each part of it begins.
/// Nothing on this list is a timer, a fraction, or a step this view model decided had probably finished
/// by now. That is the whole reason it is worth showing: a card that invented plausible progress would be
/// indistinguishable from one that had stopped receiving any.
/// </para>
/// </remarks>
internal IReadOnlyList<ConnectionStepViewModel> Steps { get; }
/// <summary>How many steps are behind the attempt, for the card's track.</summary>
/// <remarks>
/// Counted rather than stored, and it counts <see cref="ConnectionStepState.Done"/> alone: the running
/// step is deliberately not half a step. The track fills to where the attempt has actually got to and
/// stops there, which is the same promise the list itself makes.
/// </remarks>
internal int StepsDone => Steps.Count(step => step.IsDone);
/// <summary>How many steps there are, for the card's track.</summary>
internal int StepCount => Steps.Count;
/// <inheritdoc cref="TerminalTabState" /> /// <inheritdoc cref="TerminalTabState" />
[ObservableProperty] [ObservableProperty]
private TerminalTabState state; private TerminalTabState state;
@@ -187,6 +360,54 @@ internal sealed partial class TerminalTabViewModel : ObservableObject
/// <summary>Whether this tab is a connection that never happened.</summary> /// <summary>Whether this tab is a connection that never happened.</summary>
internal bool IsFailed => State is TerminalTabState.Failed; internal bool IsFailed => State is TerminalTabState.Failed;
/// <summary>
/// Records that the connection has reached a named step.
/// </summary>
/// <remarks>
/// <para>
/// Everything before <paramref name="step"/> is marked done, because a phase that has begun is proof the
/// ones before it ended — the handshake is a sequence and there is no way to be at one point in it
/// without having passed the earlier ones. That is also what covers a step too fast to observe: it is
/// closed by its successor rather than needing a report of its own.
/// </para>
/// <para>
/// Monotonic, and silently so. A report that has already been passed is ignored rather than rewinding
/// the list, because the one thing that can produce one is a retry after the host-key question, and a
/// card that jumped backwards would read as the connection having come undone.
/// </para>
/// </remarks>
internal void Advance(ConnectionStep step)
{
if (State is not TerminalTabState.Connecting)
{
// Nothing to draw and nothing to correct. A late report from a handshake that has since
// finished or been given up on is not worth reopening a settled tab for.
return;
}
var reached = Steps.FirstOrDefault(row => row.Step == step);
if (reached is null || reached.IsDone)
{
return;
}
foreach (var row in Steps)
{
if (row.Step < step)
{
row.State = ConnectionStepState.Done;
}
else if (row.Step == step)
{
row.State = ConnectionStepState.Running;
}
}
Status = reached.Caption;
OnPropertyChanged(nameof(StepsDone));
}
/// <summary>Takes ownership of the session that has just opened for this tab.</summary> /// <summary>Takes ownership of the session that has just opened for this tab.</summary>
internal void Opened(uint sessionId) internal void Opened(uint sessionId)
{ {
@@ -194,6 +415,8 @@ internal sealed partial class TerminalTabViewModel : ObservableObject
Status = string.Empty; Status = string.Empty;
IsLive = true; IsLive = true;
State = TerminalTabState.Open; State = TerminalTabState.Open;
CompleteSteps();
} }
/// <summary> /// <summary>
@@ -208,9 +431,33 @@ internal sealed partial class TerminalTabViewModel : ObservableObject
{ {
Status = reason; Status = reason;
IsLive = false; IsLive = false;
// Before the state change, so the list is already correct the first time a view asks. The step that
// was running is where it stopped, and the ones behind it stay done: how far a refused connection
// got is the most useful thing the card still knows, and it is the difference between "that host is
// not there" and "that host is there and would not have me".
foreach (var row in Steps)
{
if (row.IsRunning)
{
row.State = ConnectionStepState.Stopped;
}
}
State = TerminalTabState.Failed; State = TerminalTabState.Failed;
} }
/// <summary>Marks every step done, for a connection that is no longer being waited on.</summary>
private void CompleteSteps()
{
foreach (var row in Steps)
{
row.State = ConnectionStepState.Done;
}
OnPropertyChanged(nameof(StepsDone));
}
partial void OnStateChanged(TerminalTabState value) partial void OnStateChanged(TerminalTabState value)
{ {
OnPropertyChanged(nameof(HasSession)); OnPropertyChanged(nameof(HasSession));
@@ -943,6 +943,31 @@ internal sealed class ConnectionAttemptEventArgs(Guid attemptId, string label, s
internal string Address { get; } = address; internal string Address { get; } = address;
} }
/// <summary>A connection that has got as far as a named step.</summary>
/// <param name="attemptId">The attempt this is about.</param>
/// <param name="step">The step that has just begun.</param>
/// <remarks>
/// <para>
/// The fourth of the attempt events, and the only one that can be raised more than once for an attempt. It
/// exists because the other three say a connection started and then, seconds later, whether it worked — and
/// the seconds in between are the whole of what a user staring at a connecting card is trying to find out.
/// </para>
/// <para>
/// <b>Raised on whichever thread the handshake is on.</b> SSH.NET reports the interior of a connection from
/// its own thread, and this event is that report forwarded rather than a copy made on a timer, so a
/// subscriber that touches a view model must marshal for itself. <c>MainWindowViewModel</c> does; see the
/// handler.
/// </para>
/// </remarks>
internal sealed class ConnectionProgressEventArgs(Guid attemptId, ConnectionStep step) : EventArgs
{
/// <inheritdoc cref="ConnectionAttemptEventArgs.AttemptId" />
internal Guid AttemptId { get; } = attemptId;
/// <inheritdoc cref="ConnectionProgressEventArgs" path="/param[@name='step']" />
internal ConnectionStep Step { get; } = step;
}
/// <summary>A connection that was asked for and did not happen.</summary> /// <summary>A connection that was asked for and did not happen.</summary>
/// <param name="attemptId">The attempt that has just ended.</param> /// <param name="attemptId">The attempt that has just ended.</param>
/// <param name="reason">What to say about it, in the tab.</param> /// <param name="reason">What to say about it, in the tab.</param>
@@ -4127,6 +4152,15 @@ internal sealed partial class VaultViewModel(
/// </remarks> /// </remarks>
internal event EventHandler<ConnectionAttemptEventArgs>? ConnectionStarting; internal event EventHandler<ConnectionAttemptEventArgs>? ConnectionStarting;
/// <summary>Raised as a connection this vault announced gets from one step to the next.</summary>
/// <remarks>
/// Between <see cref="ConnectionStarting"/> and whichever of the other two ends the attempt, any number
/// of times including none — a handshake fast enough to finish inside one turn reports nothing, which is
/// the honest account of it. See <see cref="ConnectionProgressEventArgs"/> for the threading, which is
/// the one way this event differs from its three neighbours.
/// </remarks>
internal event EventHandler<ConnectionProgressEventArgs>? ConnectionProgress;
/// <summary>Raised when a connection this vault announced does not become a session.</summary> /// <summary>Raised when a connection this vault announced does not become a session.</summary>
/// <inheritdoc cref="ConnectionStarting" path="/remarks" /> /// <inheritdoc cref="ConnectionStarting" path="/remarks" />
internal event EventHandler<ConnectionFailedEventArgs>? ConnectionFailed; internal event EventHandler<ConnectionFailedEventArgs>? ConnectionFailed;
@@ -10889,6 +10923,53 @@ internal sealed partial class VaultViewModel(
return true; return true;
} }
/// <summary>Turns the handshake's phases into this attempt's progress events.</summary>
/// <remarks>
/// <para>
/// Forwarded rather than accumulated, because the tab is the thing that knows what has already happened
/// and this object deliberately does not: a connection here is one straight line from renderer to
/// session, and a running total of where it had got to would be a second copy of the state the card
/// already draws from the first.
/// </para>
/// <para>
/// <b>Deliberately not <c>System.Progress&lt;T&gt;</c></b>, which captures whatever synchronisation
/// context it happens to be constructed on and posts to it. That reads like a convenience and is really
/// a second place the marshalling decision gets made: silently, differently under a test with no
/// context, and — because a post is a later turn — out of order with respect to the failure or the
/// session that follows the phase. Raised inline instead, and the shell marshals once where it can be
/// seen. See <c>MainWindowViewModel.OnVaultConnectionProgress</c>.
/// </para>
/// </remarks>
private PhaseReporter ReporterFor(ConnectionAttemptEventArgs attempt) => new(phase =>
ConnectionProgress?.Invoke(this, new ConnectionProgressEventArgs(attempt.AttemptId, StepFor(phase))));
/// <summary>The step a handshake phase is reported to the shell as.</summary>
/// <remarks>
/// The whole of the mapping between the SSH assembly's four phases and the card's five steps, in one
/// place. <see cref="ConnectionStep.PreparingTerminal"/> is not here because nothing reports it: the tab
/// starts on it, and the first phase to arrive is what closes it.
/// </remarks>
private static ConnectionStep StepFor(SshConnectionPhase phase) => phase switch
{
SshConnectionPhase.Reaching => ConnectionStep.Reaching,
SshConnectionPhase.CheckingHostKey => ConnectionStep.CheckingHostKey,
SshConnectionPhase.Authenticating => ConnectionStep.Authenticating,
SshConnectionPhase.OpeningShell => ConnectionStep.OpeningShell,
_ => ConnectionStep.Reaching,
};
/// <summary>Hands each phase straight to a delegate, on the thread that reported it.</summary>
/// <remarks>
/// The whole type, and it exists to be the thing <c>System.Progress&lt;T&gt;</c> is not — see the remark
/// at its one use. A lambda cannot implement an interface, and the alternative was widening the
/// workspace's parameter to <c>Action&lt;T&gt;</c>, which would have put a non-standard progress
/// contract into three assemblies to save one class here.
/// </remarks>
private sealed class PhaseReporter(Action<SshConnectionPhase> report) : IProgress<SshConnectionPhase>
{
public void Report(SshConnectionPhase value) => report(value);
}
/// <summary>What a manual target reads as, once it has been taken apart.</summary> /// <summary>What a manual target reads as, once it has been taken apart.</summary>
/// <remarks> /// <remarks>
/// Separate from <see cref="ConnectionTarget"/> because a keychain host has no username of its own at /// Separate from <see cref="ConnectionTarget"/> because a keychain host has no username of its own at
@@ -11238,6 +11319,8 @@ internal sealed partial class VaultViewModel(
HostAuthentication authentication, HostAuthentication authentication,
CancellationToken cancellationToken) CancellationToken cancellationToken)
{ {
// Not reported before the await: the tab is constructed with this step already running — see
// TerminalTabViewModel — because there is no moment between the two worth telling anybody about.
await workspace.WaitForRendererAsync(cancellationToken).ConfigureAwait(true); await workspace.WaitForRendererAsync(cancellationToken).ConfigureAwait(true);
var request = new SshConnectionRequest( var request = new SshConnectionRequest(
@@ -11247,7 +11330,7 @@ internal sealed partial class VaultViewModel(
authentication.Credential); authentication.Credential);
var sessionId = await workspace var sessionId = await workspace
.OpenSessionAsync(request, TerminalSize.Default, cancellationToken) .OpenSessionAsync(request, TerminalSize.Default, ReporterFor(attempt), cancellationToken)
.ConfigureAwait(true); .ConfigureAwait(true);
// The workspace has already opened a ticket for this session, with the address and the moment it // The workspace has already opened a ticket for this session, with the address and the moment it
+45 -1
View File
@@ -121,12 +121,53 @@ public interface ISshConnection : IAsyncDisposable
Task<ISshShellSession> OpenShellAsync(TerminalSize size, CancellationToken cancellationToken); Task<ISshShellSession> OpenShellAsync(TerminalSize size, CancellationToken cancellationToken);
} }
/// <summary>
/// How far a connection being made has got.
/// </summary>
/// <remarks>
/// <para>
/// These are the boundaries a client can actually observe, and there are deliberately no others. SSH.NET
/// runs the whole handshake inside one <c>ConnectAsync</c> and raises exactly one event from the middle of
/// it — <c>HostKeyReceived</c>, once the key exchange has produced a key to show. That event is the only
/// interior moment there is, so it is the only interior phase named here: everything before it is
/// <see cref="Reaching"/> and everything after it is <see cref="Authenticating"/>.
/// </para>
/// <para>
/// ◆ <b>Nothing here is a guess about elapsed time or a fraction of the way through.</b> Each value is
/// reported at the instant the thing it names actually starts, which is what makes it safe for a screen to
/// draw as fact. A phase that took no measurable time is reported anyway and simply passes at once — that
/// is a true account of a fast handshake, not a step that was skipped. See the transfer strip's own remark
/// in TransfersScreen.axaml for why this design does not invent furniture for states it cannot measure.
/// </para>
/// </remarks>
public enum SshConnectionPhase
{
/// <summary>Resolving the name, opening the socket, and exchanging keys. Before any key is known.</summary>
Reaching = 0,
/// <summary>The server has offered a host key, and its trust is being decided.</summary>
CheckingHostKey = 1,
/// <summary>The key was accepted. The credential is being offered.</summary>
Authenticating = 2,
/// <summary>Authenticated. A pseudo-terminal and a shell channel are being opened.</summary>
OpeningShell = 3,
}
/// <summary>Opens connections, enforcing host key trust before authenticating.</summary> /// <summary>Opens connections, enforcing host key trust before authenticating.</summary>
public interface ISshConnectionFactory public interface ISshConnectionFactory
{ {
/// <summary> /// <summary>
/// Connects and authenticates. /// Connects and authenticates.
/// </summary> /// </summary>
/// <param name="request">What to connect to, as whom, and with what.</param>
/// <param name="progress">
/// Told each phase as it begins, or null to report nothing. Called from whichever thread the handshake
/// is on — SSH.NET raises host key verification on its own — so an implementation that touches a UI must
/// marshal for itself.
/// </param>
/// <param name="cancellationToken">Abandons the attempt.</param>
/// <exception cref="SshHostKeyUnknownException"> /// <exception cref="SshHostKeyUnknownException">
/// The host has no pinned key. The caller must show the fingerprint, and only on explicit /// The host has no pinned key. The caller must show the fingerprint, and only on explicit
/// confirmation record it via <see cref="IKnownHostStore.TrustAsync"/> and retry. /// confirmation record it via <see cref="IKnownHostStore.TrustAsync"/> and retry.
@@ -134,5 +175,8 @@ public interface ISshConnectionFactory
/// <exception cref="SshHostKeyMismatchException"> /// <exception cref="SshHostKeyMismatchException">
/// The presented key differs from the pin. There is no retry path: this is a hard block. /// The presented key differs from the pin. There is no retry path: this is a hard block.
/// </exception> /// </exception>
Task<ISshConnection> ConnectAsync(SshConnectionRequest request, CancellationToken cancellationToken); Task<ISshConnection> ConnectAsync(
SshConnectionRequest request,
IProgress<SshConnectionPhase>? progress,
CancellationToken cancellationToken);
} }
@@ -42,13 +42,14 @@ public sealed class SshNetConnectionFactory(IKnownHostStore knownHosts)
/// <inheritdoc /> /// <inheritdoc />
public async Task<ISshConnection> ConnectAsync( public async Task<ISshConnection> ConnectAsync(
SshConnectionRequest request, SshConnectionRequest request,
IProgress<SshConnectionPhase>? progress,
CancellationToken cancellationToken) CancellationToken cancellationToken)
{ {
ArgumentNullException.ThrowIfNull(request); ArgumentNullException.ThrowIfNull(request);
var client = new SshClient(BuildConnectionInfo(request)); var client = new SshClient(BuildConnectionInfo(request));
var gate = await ConnectThroughHostKeyGateAsync(client, request, cancellationToken) var gate = await ConnectThroughHostKeyGateAsync(client, request, progress, cancellationToken)
.ConfigureAwait(false); .ConfigureAwait(false);
return new SshNetConnection(client, gate.Presented!); return new SshNetConnection(client, gate.Presented!);
@@ -68,7 +69,10 @@ public sealed class SshNetConnectionFactory(IKnownHostStore knownHosts)
var client = new SftpClient(BuildConnectionInfo(request)) { BufferSize = SftpBufferSize }; var client = new SftpClient(BuildConnectionInfo(request)) { BufferSize = SftpBufferSize };
var gate = await ConnectThroughHostKeyGateAsync(client, request, cancellationToken) // No progress for the file-transfer path. The screen that waits on one is the file browser, which
// reports itself, and a second connection opened behind an already-open shell has nothing the user
// is watching a step list for.
var gate = await ConnectThroughHostKeyGateAsync(client, request, progress: null, cancellationToken)
.ConfigureAwait(false); .ConfigureAwait(false);
// Read once, here, rather than per call. SftpClient.WorkingDirectory canonicalises against the server // Read once, here, rather than per call. SftpClient.WorkingDirectory canonicalises against the server
@@ -101,12 +105,18 @@ public sealed class SshNetConnectionFactory(IKnownHostStore knownHosts)
private async Task<HostKeyGate> ConnectThroughHostKeyGateAsync( private async Task<HostKeyGate> ConnectThroughHostKeyGateAsync(
BaseClient client, BaseClient client,
SshConnectionRequest request, SshConnectionRequest request,
IProgress<SshConnectionPhase>? progress,
CancellationToken cancellationToken) CancellationToken cancellationToken)
{ {
var gate = new HostKeyGate(knownHosts, request, cancellationToken); var gate = new HostKeyGate(knownHosts, request, progress, cancellationToken);
client.HostKeyReceived += gate.OnHostKeyReceived; client.HostKeyReceived += gate.OnHostKeyReceived;
// Before the await rather than inside the gate, because this phase is the part of the handshake
// that happens before there is anything to raise an event about: the lookup, the socket and the key
// exchange. Nothing else can report the start of it.
progress?.Report(SshConnectionPhase.Reaching);
try try
{ {
await client.ConnectAsync(cancellationToken).ConfigureAwait(false); await client.ConnectAsync(cancellationToken).ConfigureAwait(false);
@@ -139,6 +149,7 @@ public sealed class SshNetConnectionFactory(IKnownHostStore knownHosts)
private sealed class HostKeyGate( private sealed class HostKeyGate(
IKnownHostStore knownHosts, IKnownHostStore knownHosts,
SshConnectionRequest request, SshConnectionRequest request,
IProgress<SshConnectionPhase>? progress,
CancellationToken cancellationToken) CancellationToken cancellationToken)
{ {
/// <summary>What the server offered, once the handshake has reached that point.</summary> /// <summary>What the server offered, once the handshake has reached that point.</summary>
@@ -157,6 +168,11 @@ public sealed class SshNetConnectionFactory(IKnownHostStore knownHosts)
Presented = presentation; Presented = presentation;
// Reported before the lookup rather than after it, because the lookup is the wait: this is a
// vault-backed store on the handshake thread, and on a locked or cold vault it is the part of
// "checking the host key" long enough to be worth naming.
progress?.Report(SshConnectionPhase.CheckingHostKey);
// Looked up here rather than before connecting, because the negotiated algorithm is only // Looked up here rather than before connecting, because the negotiated algorithm is only
// known now and a server may choose a different one than it did last time. // known now and a server may choose a different one than it did last time.
// //
@@ -179,6 +195,15 @@ public sealed class SshNetConnectionFactory(IKnownHostStore knownHosts)
var matches = SshHostKeyFingerprint.Equal(pinned, presentation.Fingerprint); var matches = SshHostKeyFingerprint.Equal(pinned, presentation.Fingerprint);
mismatch = !matches; mismatch = !matches;
e.CanTrust = matches; e.CanTrust = matches;
// Only on acceptance, and here rather than after the await above, because this is the last
// moment SSH.NET gives anyone: returning true from this handler is what lets the handshake go on
// to offer the credential, and it does not come back until it has an answer either way. A
// refusal reports nothing — there is no authentication about to happen for it to be true of.
if (matches)
{
progress?.Report(SshConnectionPhase.Authenticating);
}
} }
/// <summary>The specific exception for a refusal this gate caused, or null if it did not.</summary> /// <summary>The specific exception for a refusal this gate caused, or null if it did not.</summary>
@@ -369,13 +369,31 @@ public sealed class TerminalWorkspace : IAsyncDisposable
dataPlane.RendererAttached.WaitAsync(options.RendererTimeout, cancellationToken); dataPlane.RendererAttached.WaitAsync(options.RendererTimeout, cancellationToken);
/// <summary>Connects to a host and starts a terminal for it.</summary> /// <summary>Connects to a host and starts a terminal for it.</summary>
/// <param name="request">What to connect to, as whom, and with what.</param>
/// <param name="size">The pseudo-terminal's initial size.</param>
/// <param name="progress">
/// Told each phase as it begins, or null to report nothing. Reported from the handshake's own thread;
/// see <see cref="SshConnectionPhase"/>. Optional because a session opened by anything other than the
/// connecting card has nobody watching a step list for it, which is every caller but one.
/// </param>
/// <param name="cancellationToken">Abandons the attempt.</param>
/// <returns>The session id, which identifies this terminal in the renderer.</returns> /// <returns>The session id, which identifies this terminal in the renderer.</returns>
/// <remarks>
/// <see cref="SshConnectionPhase.OpeningShell"/> is reported here rather than by the factory because
/// this is where it happens: the factory's work ends with an authenticated connection, and asking for a
/// pseudo-terminal on it is a separate round trip this method makes.
/// </remarks>
public async Task<uint> OpenSessionAsync( public async Task<uint> OpenSessionAsync(
SshConnectionRequest request, SshConnectionRequest request,
TerminalSize size, TerminalSize size,
IProgress<SshConnectionPhase>? progress,
CancellationToken cancellationToken) CancellationToken cancellationToken)
{ {
var connection = await connections.ConnectAsync(request, cancellationToken).ConfigureAwait(false); var connection = await connections
.ConnectAsync(request, progress, cancellationToken)
.ConfigureAwait(false);
progress?.Report(SshConnectionPhase.OpeningShell);
ISshShellSession shell; ISshShellSession shell;
try try
+17 -3
View File
@@ -40,18 +40,32 @@ internal sealed class FakeSshConnectionFactory : ISshConnectionFactory, ISftpSes
/// <inheritdoc /> /// <inheritdoc />
public async Task<ISshConnection> ConnectAsync( public async Task<ISshConnection> ConnectAsync(
SshConnectionRequest request, SshConnectionRequest request,
IProgress<SshConnectionPhase>? progress,
CancellationToken cancellationToken) CancellationToken cancellationToken)
{ {
Requests.Add(request); Requests.Add(request);
// Before the gate rather than after it, which is what makes this fake useful for the connecting
// card: a test that holds Gate open is a connection stuck partway through, and the step list has to
// show it stuck on a named step rather than on none.
progress?.Report(SshConnectionPhase.Reaching);
if (Gate is { } gate) if (Gate is { } gate)
{ {
await gate.Task.WaitAsync(cancellationToken).ConfigureAwait(false); await gate.Task.WaitAsync(cancellationToken).ConfigureAwait(false);
} }
return Failure is { } failure if (Failure is { } failure)
? throw failure {
: new FakeSshConnection(request); throw failure;
}
// Only on the way to succeeding. A failure reported as having authenticated would let a test pass
// while the card showed a refused connection getting one step further than it did.
progress?.Report(SshConnectionPhase.CheckingHostKey);
progress?.Report(SshConnectionPhase.Authenticating);
return new FakeSshConnection(request);
} }
/// <inheritdoc /> /// <inheritdoc />
@@ -143,7 +143,14 @@ public sealed class ShellFlowTests : IAsyncLifetime
{ {
clipboard.Add(text); clipboard.Add(text);
return Task.CompletedTask; return Task.CompletedTask;
}); },
// Inline, because this suite has no window and therefore no dispatcher to drain — the same
// answer TransferQueueingTests reached, and for the reason its own remark gives: reaching
// Dispatcher.UIThread from a test means asserting on a queue owned by whichever class touched
// it first. Running the action where it was raised takes the thread out of the question, and
// every phase this suite reports is raised on the thread doing the asserting anyway.
post: action => action());
return ValueTask.CompletedTask; return ValueTask.CompletedTask;
} }
@@ -1303,6 +1310,119 @@ public sealed class ShellFlowTests : IAsyncLifetime
shell.IsConnectingShowing.ShouldBeFalse(); shell.IsConnectingShowing.ShouldBeFalse();
} }
/// <remarks>
/// <para>
/// What the card draws while the stretch above is going on. The tab used to carry one line of prose
/// fixed at the moment it was created, which made a handshake stuck on a key exchange look exactly like
/// one stuck on a dead socket — and made a connection that was progressing look exactly like one that
/// was not.
/// </para>
/// <para>
/// The gate is held open on the step the fake reports before it, so this asserts the state the card is
/// actually drawn in rather than one it passes through: one step behind, one step lit, three not
/// reached. Nothing here waits or polls, which is the other half of the claim — the report arrives on
/// the thread that raised it and the tab is up to date in the same turn.
/// </para>
/// </remarks>
[Fact]
public async Task Connecting_LightsTheStepTheHandshakeHasActuallyReached()
{
var vault = await ReadyToConnectAsync();
await using var renderer = await FakeRenderer.AttachAsync(workspace, Token);
ssh.Gate = new TaskCompletionSource();
var connecting = vault.ConnectCommand.ExecuteAsync(null);
var tab = shell.Tabs.ShouldHaveSingleItem();
tab.Steps.Select(step => step.State).ShouldBe(
[
ConnectionStepState.Done,
ConnectionStepState.Running,
ConnectionStepState.Pending,
ConnectionStepState.Pending,
ConnectionStepState.Pending,
],
"the renderer attached, the host is being reached, and nothing after that has happened");
tab.StepsDone.ShouldBe(1, "the track fills to what finished, and the running step is not half a step");
tab.Status.ShouldBe("Reaching the host");
ssh.Gate.SetResult();
await connecting;
tab.Steps.ShouldAllBe(step => step.IsDone, "a session that opened got through all of them");
tab.StepsDone.ShouldBe(tab.StepCount);
}
/// <remarks>
/// The half of the step list a progress bar could not do: where it stopped is kept, and the steps behind
/// it stay done. That is the difference between "that host is not there" and "that host is there and
/// would not have me", and it is the question the reason sentence alone often does not settle.
/// </remarks>
[Fact]
public async Task ARefusedConnection_KeepsTheStepItStoppedOn()
{
var vault = await ReadyToConnectAsync();
await using var renderer = await FakeRenderer.AttachAsync(workspace, Token);
ssh.Failure = new InvalidOperationException("No route to host.");
await vault.ConnectCommand.ExecuteAsync(null);
var tab = shell.Tabs.ShouldHaveSingleItem();
tab.Steps.Select(step => step.State).ShouldBe(
[
ConnectionStepState.Done,
ConnectionStepState.Stopped,
ConnectionStepState.Pending,
ConnectionStepState.Pending,
ConnectionStepState.Pending,
],
"it got as far as reaching the host and no further");
tab.Steps[1].Mark.ShouldBe("✕", "and says so without relying on the colour");
// The reason still goes where it always went. The list says how far, and this says what happened.
tab.Status.ShouldBe("No route to host.");
}
/// <remarks>
/// A report that arrives for an attempt the shell has forgotten. Giving up on a connecting tab removes
/// it while the handshake is still running — see <c>CloseTabAsync</c> — so every phase reported after
/// that has no tab to land on. Dropped rather than resurrecting the tab, and above all not thrown: the
/// handshake is still going, and its session is still adopted if it opens.
/// </remarks>
[Fact]
public async Task GivingUpOnATab_LeavesLaterPhasesWithNothingToDo()
{
var vault = await ReadyToConnectAsync();
await using var renderer = await FakeRenderer.AttachAsync(workspace, Token);
ssh.Gate = new TaskCompletionSource();
var connecting = vault.ConnectCommand.ExecuteAsync(null);
var tab = shell.Tabs.ShouldHaveSingleItem();
await shell.CloseTabCommand.ExecuteAsync(tab);
// Everything after the gate — the host key, the credential, the shell — is reported to a shell that
// no longer has a tab for this attempt.
ssh.Gate.SetResult();
await connecting;
// The session opened anyway and was adopted, which is the behaviour giving up already promised.
var adopted = shell.Tabs.ShouldHaveSingleItem();
adopted.HasSession.ShouldBeTrue();
adopted.ShouldNotBe(tab);
// And the forgotten tab was left where it was rather than being advanced from the sidelines.
tab.Steps[1].IsRunning.ShouldBeTrue("nothing moved it on after the shell let go of it");
}
/// <remarks> /// <remarks>
/// A refusal has to end up somewhere the user will see it, and by the time one arrives they are quite /// A refusal has to end up somewhere the user will see it, and by the time one arrives they are quite
/// likely looking at another screen — which is exactly what not blocking bought. The tab is that place, /// likely looking at another screen — which is exactly what not blocking bought. The tab is that place,
@@ -2341,6 +2461,7 @@ public sealed class ShellFlowTests : IAsyncLifetime
await workspace.OpenSessionAsync( await workspace.OpenSessionAsync(
new SshConnectionRequest("host.invalid", 22, "dodo", new SshPasswordCredential("irrelevant")), new SshConnectionRequest("host.invalid", 22, "dodo", new SshPasswordCredential("irrelevant")),
TerminalSize.Default, TerminalSize.Default,
progress: null,
Token); Token);
workspace.LiveSessionCount.ShouldBe(1); workspace.LiveSessionCount.ShouldBe(1);
@@ -8112,6 +8233,7 @@ public sealed class ShellFlowTests : IAsyncLifetime
await workspace.OpenSessionAsync( await workspace.OpenSessionAsync(
new SshConnectionRequest("host.invalid", 22, "dodo", new SshPasswordCredential("irrelevant")), new SshConnectionRequest("host.invalid", 22, "dodo", new SshPasswordCredential("irrelevant")),
TerminalSize.Default, TerminalSize.Default,
progress: null,
Token); Token);
shell.SignOutCommand.Execute(null); shell.SignOutCommand.Execute(null);
@@ -73,7 +73,8 @@ public sealed class KeyAuthenticationTests(SshServerFixture fixture)
var factory = new SshNetConnectionFactory(knownHosts); var factory = new SshNetConnectionFactory(knownHosts);
await Should.ThrowAsync<SshAuthenticationException>(async () => await Should.ThrowAsync<SshAuthenticationException>(async () =>
await factory.ConnectAsync(Request(new SshPrivateKeyCredential(Pkcs1(stranger), null)), Token)); await factory.ConnectAsync(
Request(new SshPrivateKeyCredential(Pkcs1(stranger), null)), progress: null, Token));
} }
[Fact] [Fact]
@@ -125,6 +126,86 @@ public sealed class KeyAuthenticationTests(SshServerFixture fixture)
shell.IsOpen.ShouldBeTrue(); shell.IsOpen.ShouldBeTrue();
} }
/// <remarks>
/// <para>
/// The claim the connecting card is built on, checked where it can actually be checked: against a real
/// handshake rather than a fake that reports whatever it was written to report. Every other test of the
/// step list asserts that the shell draws what it is told; this one asserts that what it is told is
/// true.
/// </para>
/// <para>
/// The order is the assertion. A step list is only readable if the reports arrive in the order it draws
/// them, and the middle one is the load-bearing part — <see cref="SshConnectionPhase.CheckingHostKey"/>
/// comes out of SSH.NET's <c>HostKeyReceived</c>, which is the single interior moment the library gives
/// anybody, and it has to land between the other two rather than beside them.
/// </para>
/// <para>
/// <see cref="SshConnectionPhase.OpeningShell"/> is deliberately absent: this factory's work ends with
/// an authenticated connection, and the phase for opening a channel on one belongs to the layer that
/// opens it. <c>TerminalWorkspaceTests</c> covers that half.
/// </para>
/// </remarks>
[Fact]
public async Task AHandshake_ReportsItsPhasesInTheOrderTheyHappen()
{
var knownHosts = await TrustedStoreAsync();
var reported = new List<SshConnectionPhase>();
await using var connection = await new SshNetConnectionFactory(knownHosts).ConnectAsync(
Request(new SshPrivateKeyCredential(Pkcs1(fixture.ClientKey), Passphrase: null)),
new DelegateProgress<SshConnectionPhase>(phase =>
{
lock (reported)
{
// Locked because the last two are reported from SSH.NET's own handshake thread rather
// than from the awaiting one, which is the whole reason the shell marshals them.
reported.Add(phase);
}
}),
Token);
connection.IsConnected.ShouldBeTrue();
lock (reported)
{
reported.ShouldBe(
[
SshConnectionPhase.Reaching,
SshConnectionPhase.CheckingHostKey,
SshConnectionPhase.Authenticating,
]);
}
}
/// <remarks>
/// The other half of the phase contract, and the one that would be easy to get wrong by reporting
/// optimistically: a refused key stops at the check. Nothing may claim the credential was offered, and
/// against an unknown host nothing ever is — the gate returns false and SSH.NET abandons the handshake
/// before authentication.
/// </remarks>
[Fact]
public async Task AHostKeyRefusal_NeverClaimsToHaveAuthenticated()
{
var reported = new List<SshConnectionPhase>();
await Should.ThrowAsync<SshHostKeyUnknownException>(async () =>
await new SshNetConnectionFactory(new InMemoryKnownHostStore()).ConnectAsync(
Request(new SshPasswordCredential(SshServerFixture.Password)),
new DelegateProgress<SshConnectionPhase>(phase =>
{
lock (reported)
{
reported.Add(phase);
}
}),
Token));
lock (reported)
{
reported.ShouldBe([SshConnectionPhase.Reaching, SshConnectionPhase.CheckingHostKey]);
}
}
private static byte[] Pkcs1(RSA key) => Encoding.UTF8.GetBytes(key.ExportRSAPrivateKeyPem()); private static byte[] Pkcs1(RSA key) => Encoding.UTF8.GetBytes(key.ExportRSAPrivateKeyPem());
private static byte[] Pkcs8(RSA key) => Encoding.UTF8.GetBytes(key.ExportPkcs8PrivateKeyPem()); private static byte[] Pkcs8(RSA key) => Encoding.UTF8.GetBytes(key.ExportPkcs8PrivateKeyPem());
@@ -141,7 +222,7 @@ public sealed class KeyAuthenticationTests(SshServerFixture fixture)
// Learned by being refused, which is the only way this client learns a host key. // Learned by being refused, which is the only way this client learns a host key.
var unknown = await Should.ThrowAsync<SshHostKeyUnknownException>(async () => var unknown = await Should.ThrowAsync<SshHostKeyUnknownException>(async () =>
await factory.ConnectAsync( await factory.ConnectAsync(
Request(new SshPasswordCredential(SshServerFixture.Password)), Token)); Request(new SshPasswordCredential(SshServerFixture.Password)), progress: null, Token));
await knownHosts.TrustAsync(unknown.Presentation, Token); await knownHosts.TrustAsync(unknown.Presentation, Token);
@@ -153,6 +234,6 @@ public sealed class KeyAuthenticationTests(SshServerFixture fixture)
var knownHosts = await TrustedStoreAsync(); var knownHosts = await TrustedStoreAsync();
return await new SshNetConnectionFactory(knownHosts) return await new SshNetConnectionFactory(knownHosts)
.ConnectAsync(Request(credential), Token); .ConnectAsync(Request(credential), progress: null, Token);
} }
} }
@@ -137,3 +137,14 @@ public sealed class KnownHostStoreTests
string fingerprint = "SHA256:approved") => string fingerprint = "SHA256:approved") =>
new(host, port, algorithm, fingerprint); new(host, port, algorithm, fingerprint);
} }
/// <summary>An <see cref="IProgress{T}"/> that runs its callback on the thread that reported.</summary>
/// <remarks>
/// <c>System.Progress&lt;T&gt;</c> posts to a captured synchronisation context, or to the thread pool when
/// there is none — which is what a test has here — so a list it appended to would be asserted on before it
/// had been written. The same reason the shell does not use it either; see <c>VaultViewModel.ReporterFor</c>.
/// </remarks>
internal sealed class DelegateProgress<T>(Action<T> report) : IProgress<T>
{
public void Report(T value) => report(value);
}
@@ -66,7 +66,7 @@ public sealed class LoopbackProxyTests(SshServerFixture fixture)
var factory = new SshNetConnectionFactory(knownHosts); var factory = new SshNetConnectionFactory(knownHosts);
var unknown = await Should.ThrowAsync<SshHostKeyUnknownException>(async () => var unknown = await Should.ThrowAsync<SshHostKeyUnknownException>(async () =>
await factory.ConnectAsync(request, Token)); await factory.ConnectAsync(request, progress: null, Token));
unknown.Presentation.Host.ShouldBe(InternalHost, "the target's name, not the proxy's"); unknown.Presentation.Host.ShouldBe(InternalHost, "the target's name, not the proxy's");
unknown.Presentation.Port.ShouldBe(SshServerFixture.InternalPort); unknown.Presentation.Port.ShouldBe(SshServerFixture.InternalPort);
@@ -75,7 +75,7 @@ public sealed class LoopbackProxyTests(SshServerFixture fixture)
await knownHosts.TrustAsync(unknown.Presentation, Token); await knownHosts.TrustAsync(unknown.Presentation, Token);
await using var connection = await factory.ConnectAsync(request, Token); await using var connection = await factory.ConnectAsync(request, progress: null, Token);
connection.IsConnected.ShouldBeTrue(); connection.IsConnected.ShouldBeTrue();
connection.HostKey.Host.ShouldBe(InternalHost); connection.HostKey.Host.ShouldBe(InternalHost);
@@ -121,7 +121,8 @@ public sealed class LoopbackProxyTests(SshServerFixture fixture)
var request = Request(Credential(), new SshLoopbackProxy(DeadPort())); var request = Request(Credential(), new SshLoopbackProxy(DeadPort()));
var failure = await Should.ThrowAsync<Exception>(async () => var failure = await Should.ThrowAsync<Exception>(async () =>
await new SshNetConnectionFactory(new InMemoryKnownHostStore()).ConnectAsync(request, Token)); await new SshNetConnectionFactory(new InMemoryKnownHostStore())
.ConnectAsync(request, progress: null, Token));
failure.ShouldNotBeOfType<SshHostKeyUnknownException>(); failure.ShouldNotBeOfType<SshHostKeyUnknownException>();
failure.ShouldNotBeOfType<SshHostKeyMismatchException>(); failure.ShouldNotBeOfType<SshHostKeyMismatchException>();
@@ -137,7 +138,7 @@ public sealed class LoopbackProxyTests(SshServerFixture fixture)
var knownHosts = await TrustedStoreAsync(); var knownHosts = await TrustedStoreAsync();
await using var connection = await new SshNetConnectionFactory(knownHosts) await using var connection = await new SshNetConnectionFactory(knownHosts)
.ConnectAsync(Request(Credential(), proxy: null), Token); .ConnectAsync(Request(Credential(), proxy: null), progress: null, Token);
connection.IsConnected.ShouldBeTrue(); connection.IsConnected.ShouldBeTrue();
} }
@@ -216,7 +217,7 @@ public sealed class LoopbackProxyTests(SshServerFixture fixture)
var unknown = await Should.ThrowAsync<SshHostKeyUnknownException>(async () => var unknown = await Should.ThrowAsync<SshHostKeyUnknownException>(async () =>
await new SshNetConnectionFactory(knownHosts) await new SshNetConnectionFactory(knownHosts)
.ConnectAsync(Request(Credential(), proxy: null), Token)); .ConnectAsync(Request(Credential(), proxy: null), progress: null, Token));
await knownHosts.TrustAsync(unknown.Presentation, Token); await knownHosts.TrustAsync(unknown.Presentation, Token);
@@ -27,11 +27,11 @@ public sealed class PumpOverRealSshTests(SshServerFixture fixture)
new SshPasswordCredential(SshServerFixture.Password)); new SshPasswordCredential(SshServerFixture.Password));
var unknown = await Should.ThrowAsync<SshHostKeyUnknownException>(async () => var unknown = await Should.ThrowAsync<SshHostKeyUnknownException>(async () =>
await factory.ConnectAsync(request, TestContext.Current.CancellationToken)); await factory.ConnectAsync(request, progress: null, TestContext.Current.CancellationToken));
await knownHosts.TrustAsync(unknown.Presentation, TestContext.Current.CancellationToken); await knownHosts.TrustAsync(unknown.Presentation, TestContext.Current.CancellationToken);
return await factory.ConnectAsync(request, TestContext.Current.CancellationToken); return await factory.ConnectAsync(request, progress: null, TestContext.Current.CancellationToken);
} }
[Fact] [Fact]
@@ -110,7 +110,7 @@ public sealed class TerminalEndToEndTests(SshServerFixture fixture)
var unknown = await Should.ThrowAsync<SshHostKeyUnknownException>(async () => var unknown = await Should.ThrowAsync<SshHostKeyUnknownException>(async () =>
await workspace.OpenSessionAsync( await workspace.OpenSessionAsync(
request, TerminalSize.Default, TestContext.Current.CancellationToken)); request, TerminalSize.Default, progress: null, TestContext.Current.CancellationToken));
unknown.Presentation.Fingerprint.ShouldStartWith(SshHostKeyFingerprint.Prefix); unknown.Presentation.Fingerprint.ShouldStartWith(SshHostKeyFingerprint.Prefix);
@@ -119,6 +119,7 @@ public sealed class TerminalEndToEndTests(SshServerFixture fixture)
return await workspace.OpenSessionAsync( return await workspace.OpenSessionAsync(
request, request,
new TerminalSize(100, 30, 1000, 750), new TerminalSize(100, 30, 1000, 750),
progress: null,
TestContext.Current.CancellationToken); TestContext.Current.CancellationToken);
} }
@@ -139,8 +139,15 @@ internal sealed class FakeConnectionFactory(long bytesPerShell = long.MaxValue,
/// <inheritdoc /> /// <inheritdoc />
public Task<ISshConnection> ConnectAsync( public Task<ISshConnection> ConnectAsync(
SshConnectionRequest request, SshConnectionRequest request,
IProgress<SshConnectionPhase>? progress,
CancellationToken cancellationToken) CancellationToken cancellationToken)
{ {
// The real factory's own order, so that a test watching this fake is watching the same sequence a
// real handshake produces. It cannot report CheckingHostKey — there is no key exchange here to
// produce a key — and inventing one would make this the only place that phase came from.
progress?.Report(SshConnectionPhase.Reaching);
progress?.Report(SshConnectionPhase.Authenticating);
var connection = new FakeConnection(request, bytesPerShell, blockShellReads); var connection = new FakeConnection(request, bytesPerShell, blockShellReads);
Connections.Add(connection); Connections.Add(connection);
@@ -250,3 +257,15 @@ internal sealed class RecordingTransport : ITerminalTransport
TerminalFrame.TryRead(frame, out var actual, out _, out _) TerminalFrame.TryRead(frame, out var actual, out _, out _)
&& actual == (byte)opcode); && actual == (byte)opcode);
} }
/// <summary>An <see cref="IProgress{T}"/> that runs its callback on the thread that reported.</summary>
/// <remarks>
/// <c>System.Progress&lt;T&gt;</c> would post to a captured synchronisation context, or to the thread pool
/// when there is none — which is what a test has here — so a list it appended to would be asserted on before
/// it had been written. This is the same reason the shell does not use it either; see
/// <c>VaultViewModel.ReporterFor</c>.
/// </remarks>
internal sealed class DelegateProgress<T>(Action<T> report) : IProgress<T>
{
public void Report(T value) => report(value);
}
@@ -72,12 +72,12 @@ public sealed class TerminalWorkspaceTests
workspace.LiveSessionCount.ShouldBe(0); workspace.LiveSessionCount.ShouldBe(0);
await workspace.OpenSessionAsync( await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
workspace.LiveSessionCount.ShouldBe(1); workspace.LiveSessionCount.ShouldBe(1);
await workspace.OpenSessionAsync( await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
workspace.LiveSessionCount.ShouldBe(2); workspace.LiveSessionCount.ShouldBe(2);
} }
@@ -98,11 +98,63 @@ public sealed class TerminalWorkspaceTests
await using var workspace = CreateWorkspace(connections); await using var workspace = CreateWorkspace(connections);
await workspace.OpenSessionAsync( await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
await WaitUntilAsync(() => workspace.LiveSessionCount == 0); await WaitUntilAsync(() => workspace.LiveSessionCount == 0);
} }
/// <remarks>
/// <para>
/// <see cref="SshConnectionPhase.OpeningShell"/> is the one phase no connection factory can report,
/// because by the time it happens the factory has handed back a connection and gone. If this layer did
/// not report it the card's last step would light only when the whole session opened, which is the one
/// moment the card is already being taken down — a step nobody would ever see lit.
/// </para>
/// <para>
/// Asserted as the whole sequence rather than as "contains OpeningShell", because the order is the part
/// that matters: a step list is only readable if what it is told arrives in the order it draws.
/// </para>
/// </remarks>
[Fact]
public async Task OpeningASession_ReportsTheShellPhaseTheFactoryCannot()
{
var connections = new FakeConnectionFactory();
var reported = new List<SshConnectionPhase>();
await using var workspace = CreateWorkspace(connections);
await workspace.OpenSessionAsync(
Request(),
TerminalSize.Default,
new DelegateProgress<SshConnectionPhase>(reported.Add),
TestContext.Current.CancellationToken);
reported.ShouldBe(
[
SshConnectionPhase.Reaching,
SshConnectionPhase.Authenticating,
SshConnectionPhase.OpeningShell,
],
"the factory's own phases, then the one this layer performs itself");
}
/// <remarks>
/// Nobody watching is the ordinary case — every caller but the connecting card passes null — so it is
/// worth one test that the null is a null and not a null reference.
/// </remarks>
[Fact]
public async Task OpeningASession_WorksWithNobodyWatchingItsPhases()
{
var connections = new FakeConnectionFactory();
await using var workspace = CreateWorkspace(connections);
var sessionId = await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
workspace.IsSessionLive(sessionId).ShouldBeTrue();
}
[Fact] [Fact]
public async Task ClosingASessionEndsItAndDisposesItsConnection() public async Task ClosingASessionEndsItAndDisposesItsConnection()
{ {
@@ -111,7 +163,7 @@ public sealed class TerminalWorkspaceTests
await using var workspace = CreateWorkspace(connections); await using var workspace = CreateWorkspace(connections);
var sessionId = await workspace.OpenSessionAsync( var sessionId = await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
await workspace.CloseSessionAsync(sessionId); await workspace.CloseSessionAsync(sessionId);
@@ -138,9 +190,9 @@ public sealed class TerminalWorkspaceTests
await using var workspace = CreateWorkspace(connections); await using var workspace = CreateWorkspace(connections);
var first = await workspace.OpenSessionAsync( var first = await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
var second = await workspace.OpenSessionAsync( var second = await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
workspace.IsSessionLive(first).ShouldBeTrue(); workspace.IsSessionLive(first).ShouldBeTrue();
workspace.IsSessionLive(second).ShouldBeTrue(); workspace.IsSessionLive(second).ShouldBeTrue();
@@ -166,7 +218,7 @@ public sealed class TerminalWorkspaceTests
await using var workspace = CreateWorkspace(connections); await using var workspace = CreateWorkspace(connections);
var sessionId = await workspace.OpenSessionAsync( var sessionId = await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
var facts = workspace.GetSessionFacts(sessionId).ShouldNotBeNull(); var facts = workspace.GetSessionFacts(sessionId).ShouldNotBeNull();
var connection = connections.Connections.ShouldHaveSingleItem(); var connection = connections.Connections.ShouldHaveSingleItem();
@@ -199,7 +251,7 @@ public sealed class TerminalWorkspaceTests
await using var workspace = CreateWorkspace(connections); await using var workspace = CreateWorkspace(connections);
var sessionId = await workspace.OpenSessionAsync( var sessionId = await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
(await workspace.PasteAsync( (await workspace.PasteAsync(
sessionId, "uptime", execute: false, TestContext.Current.CancellationToken)) sessionId, "uptime", execute: false, TestContext.Current.CancellationToken))
@@ -245,7 +297,7 @@ public sealed class TerminalWorkspaceTests
}; };
var sessionId = await workspace.OpenSessionAsync( var sessionId = await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
await WaitUntilAsync(() => await WaitUntilAsync(() =>
{ {
@@ -283,7 +335,7 @@ public sealed class TerminalWorkspaceTests
}; };
var sessionId = await workspace.OpenSessionAsync( var sessionId = await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
await workspace.CloseSessionAsync(sessionId); await workspace.CloseSessionAsync(sessionId);
@@ -309,9 +361,9 @@ public sealed class TerminalWorkspaceTests
workspace.SessionEnded += (_, _) => Interlocked.Increment(ref announcements); workspace.SessionEnded += (_, _) => Interlocked.Increment(ref announcements);
await workspace.OpenSessionAsync( await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
await workspace.OpenSessionAsync( await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
await workspace.DisposeAsync(); await workspace.DisposeAsync();
@@ -355,7 +407,7 @@ public sealed class TerminalWorkspaceTests
using var first = await ConnectRendererAsync(workspace); using var first = await ConnectRendererAsync(workspace);
var sessionId = await workspace.OpenSessionAsync( var sessionId = await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
// The session's own opening frame, sent as soon as the pump starts running. Not a replay, and not // The session's own opening frame, sent as soon as the pump starts running. Not a replay, and not
// what this test is about — read and discarded so it cannot be confused for one below. // what this test is about — read and discarded so it cannot be confused for one below.
@@ -422,7 +474,7 @@ public sealed class TerminalWorkspaceTests
await using var workspace = CreateWorkspace(connections); await using var workspace = CreateWorkspace(connections);
var sessionId = await workspace.OpenSessionAsync( var sessionId = await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
// The up-arrow, as a PTY expects it. Three bytes, and all three matter. // The up-arrow, as a PTY expects it. Three bytes, and all three matter.
byte[] upArrow = [0x1B, (byte)'[', (byte)'A']; byte[] upArrow = [0x1B, (byte)'[', (byte)'A'];
@@ -444,7 +496,7 @@ public sealed class TerminalWorkspaceTests
await using var workspace = CreateWorkspace(new FakeConnectionFactory()); await using var workspace = CreateWorkspace(new FakeConnectionFactory());
var sessionId = await workspace.OpenSessionAsync( var sessionId = await workspace.OpenSessionAsync(
Request(), TerminalSize.Default, TestContext.Current.CancellationToken); Request(), TerminalSize.Default, progress: null, TestContext.Current.CancellationToken);
await workspace.CloseSessionAsync(sessionId); await workspace.CloseSessionAsync(sessionId);
@@ -391,7 +391,7 @@ public sealed class M1VerticalSliceTests(DevStack stack) : IClassFixture<DevStac
try try
{ {
await using var first = await factory.ConnectAsync(request, Token); await using var first = await factory.ConnectAsync(request, progress: null, Token);
Assert.Fail("An unseen host key must not be trusted silently."); Assert.Fail("An unseen host key must not be trusted silently.");
} }
catch (SshHostKeyUnknownException exception) catch (SshHostKeyUnknownException exception)
@@ -402,7 +402,7 @@ public sealed class M1VerticalSliceTests(DevStack stack) : IClassFixture<DevStac
await knownHosts.TrustAsync(pin, Token); await knownHosts.TrustAsync(pin, Token);
} }
await using var connection = await factory.ConnectAsync(request, Token); await using var connection = await factory.ConnectAsync(request, progress: null, Token);
await using var shell = await connection.OpenShellAsync(TerminalSize.Default, Token); await using var shell = await connection.OpenShellAsync(TerminalSize.Default, Token);
await shell.WriteTextAsync("echo dodossh-e2e-ok\n", Token); await shell.WriteTextAsync("echo dodossh-e2e-ok\n", Token);