Public Access
The throughput harness the plan requires before any UI, plus the SSH plumbing under it. 94 new tests, no WebView involved. Credit-based flow control is what makes `yes` survivable. A terminal renders at 60 Hz at best while a remote produces output as fast as the network allows, and the difference has to accumulate somewhere or be refused. Credit is reserved *before* reading, never after: because the pump cannot read more than the renderer has room for, the coalescing buffer is bounded by the window rather than by how fast the remote can talk. When credit runs out the pump stops reading, SSH's own receive window closes, and the remote sshd blocks -- backpressure to the source with no custom protocol. Verified by falsification, not just by passing: with the credit gate removed three tests fail, including the throughput harness's bounded-memory assertion. Acknowledgements are clamped because they cross into JavaScript, where a buggy or hostile page could otherwise claim to have rendered a gigabyte and talk the host into an unbounded read. Host key trust is enforced by *failing* the connection rather than prompting inside the handshake. SSH.NET raises verification synchronously, so consulting the user there would block the handshake on a UI round trip and deadlock the first time the prompt needed the UI thread. Unknown host and changed key become distinct exceptions the caller resolves asynchronously. A mismatch has no retry path at all: a dialog offering to continue is how users are trained to click through the one warning that actually indicates interception. A legitimately rebuilt server is handled by removing the pin in settings, away from the moment of connecting. The data plane serves the renderer page from the same loopback listener as the socket, which makes Origin predictable -- always http://127.0.0.1:{port} -- where a WebView virtual-host mapping would give a different origin per backend and nothing to validate. The token is substituted at serve time, so it never touches disk and never appears in a URL. Being clear about what that buys: not protection from a process running as this user, which can read our memory anyway, but from a page in the user's browser attempting WebSocket connections to loopback ports, which is a real and routine thing. Two bugs the tests caught. The accept loop handled connections serially, so an upgraded WebSocket parked it inside the receive loop and every later request went unanswered -- the page's own script among them. The suite hung rather than failed, which is how I found it. And SHA-1 is unavoidable here: RFC 6455 mandates it for Sec-WebSocket-Accept, where it authenticates nothing. Suppressed narrowly with that reasoning; the alternative, HttpListener.AcceptWebSocketAsync, throws PlatformNotSupportedException off Windows.
249 lines
9.0 KiB
C#
249 lines
9.0 KiB
C#
using System.Text;
|
|
using Renci.SshNet;
|
|
using Renci.SshNet.Common;
|
|
|
|
namespace DodoSSH.Client.Ssh;
|
|
|
|
/// <summary>
|
|
/// Opens SSH connections with SSH.NET, checking host key trust during the handshake.
|
|
/// </summary>
|
|
/// <remarks>
|
|
/// The pinned fingerprint is looked up <em>before</em> connecting, so the comparison inside SSH.NET's
|
|
/// synchronous <c>HostKeyReceived</c> event is a pure equality check with no I/O and no chance of
|
|
/// blocking the handshake on a UI round trip. Anything the comparison cannot settle becomes an
|
|
/// exception the caller resolves asynchronously.
|
|
/// </remarks>
|
|
public sealed class SshNetConnectionFactory(IKnownHostStore knownHosts) : ISshConnectionFactory
|
|
{
|
|
private static readonly TimeSpan DefaultConnectTimeout = TimeSpan.FromSeconds(15);
|
|
|
|
/// <inheritdoc />
|
|
public async Task<ISshConnection> ConnectAsync(
|
|
SshConnectionRequest request,
|
|
CancellationToken cancellationToken)
|
|
{
|
|
ArgumentNullException.ThrowIfNull(request);
|
|
|
|
var client = new SshClient(BuildConnectionInfo(request));
|
|
var gate = new HostKeyGate(knownHosts, request, cancellationToken);
|
|
|
|
client.HostKeyReceived += gate.OnHostKeyReceived;
|
|
|
|
try
|
|
{
|
|
await client.ConnectAsync(cancellationToken).ConfigureAwait(false);
|
|
}
|
|
catch (Exception exception) when (exception is SshConnectionException or SshAuthenticationException)
|
|
{
|
|
client.Dispose();
|
|
|
|
// Translate a refusal we caused ourselves into something the caller can act on. Without
|
|
// this the user sees "connection lost" for what is really "do you trust this key?".
|
|
throw gate.TranslateFailure() ?? exception;
|
|
}
|
|
catch
|
|
{
|
|
client.Dispose();
|
|
throw;
|
|
}
|
|
|
|
return new SshNetConnection(client, gate.Presented!);
|
|
}
|
|
|
|
/// <summary>
|
|
/// Decides host key trust during the handshake, and remembers enough to explain a refusal.
|
|
/// </summary>
|
|
/// <remarks>
|
|
/// Separate from the connect method because the decision is the security-relevant part and reads
|
|
/// better on its own: pinned and equal accepts, pinned and different refuses as a mismatch,
|
|
/// unpinned refuses as unknown. There is no fourth branch, and there is no prompt.
|
|
/// </remarks>
|
|
private sealed class HostKeyGate(
|
|
IKnownHostStore knownHosts,
|
|
SshConnectionRequest request,
|
|
CancellationToken cancellationToken)
|
|
{
|
|
/// <summary>What the server offered, once the handshake has reached that point.</summary>
|
|
public HostKeyPresentation? Presented { get; private set; }
|
|
|
|
private string? pinned;
|
|
private bool mismatch;
|
|
|
|
public void OnHostKeyReceived(object? sender, HostKeyEventArgs e)
|
|
{
|
|
var presentation = new HostKeyPresentation(
|
|
request.Host,
|
|
request.Port,
|
|
e.HostKeyName,
|
|
SshHostKeyFingerprint.Format(e.HostKey));
|
|
|
|
Presented = presentation;
|
|
|
|
// Looked up here rather than before connecting, because the negotiated algorithm is only
|
|
// known now and a server may choose a different one than it did last time.
|
|
//
|
|
// This is the one place the design cannot stay asynchronous: SSH.NET raises host key
|
|
// verification synchronously. It is a local store read rather than a UI round trip, and
|
|
// making the store synchronous instead would rule out a vault-backed implementation.
|
|
pinned = knownHosts
|
|
.FindAsync(request.Host, request.Port, e.HostKeyName, cancellationToken)
|
|
.AsTask()
|
|
.GetAwaiter()
|
|
.GetResult();
|
|
|
|
if (pinned is null)
|
|
{
|
|
// Refused, not prompted. The caller decides, off the handshake thread.
|
|
e.CanTrust = false;
|
|
return;
|
|
}
|
|
|
|
var matches = SshHostKeyFingerprint.Equal(pinned, presentation.Fingerprint);
|
|
mismatch = !matches;
|
|
e.CanTrust = matches;
|
|
}
|
|
|
|
/// <summary>The specific exception for a refusal this gate caused, or null if it did not.</summary>
|
|
public Exception? TranslateFailure()
|
|
{
|
|
if (Presented is not { } presentation)
|
|
{
|
|
return null;
|
|
}
|
|
|
|
if (mismatch && pinned is { } pin)
|
|
{
|
|
return new SshHostKeyMismatchException(presentation, pin);
|
|
}
|
|
|
|
return pinned is null ? new SshHostKeyUnknownException(presentation) : null;
|
|
}
|
|
}
|
|
|
|
/// <remarks>
|
|
/// The known-host lookup inside the synchronous event is the one place this design cannot avoid
|
|
/// blocking. It is a local store read rather than a UI round trip, and the alternative — making
|
|
/// the store synchronous — would rule out the encrypted vault-backed implementation entirely.
|
|
/// </remarks>
|
|
private static ConnectionInfo BuildConnectionInfo(SshConnectionRequest request)
|
|
{
|
|
AuthenticationMethod method = request.Credential switch
|
|
{
|
|
SshPasswordCredential password =>
|
|
new PasswordAuthenticationMethod(request.Username, password.Password),
|
|
|
|
SshPrivateKeyCredential key => new PrivateKeyAuthenticationMethod(
|
|
request.Username,
|
|
CreatePrivateKeyFile(key)),
|
|
|
|
_ => throw new NotSupportedException(
|
|
$"Credential type {request.Credential.GetType().Name} is not supported."),
|
|
};
|
|
|
|
return new ConnectionInfo(request.Host, request.Port, request.Username, method)
|
|
{
|
|
Timeout = request.ConnectTimeout ?? DefaultConnectTimeout,
|
|
};
|
|
}
|
|
|
|
private static PrivateKeyFile CreatePrivateKeyFile(SshPrivateKeyCredential credential)
|
|
{
|
|
using var stream = new MemoryStream(credential.PrivateKeyPem, writable: false);
|
|
|
|
return credential.Passphrase is null
|
|
? new PrivateKeyFile(stream)
|
|
: new PrivateKeyFile(stream, credential.Passphrase);
|
|
}
|
|
}
|
|
|
|
/// <summary>An SSH.NET-backed connection.</summary>
|
|
internal sealed class SshNetConnection(SshClient client, HostKeyPresentation hostKey) : ISshConnection
|
|
{
|
|
/// <inheritdoc />
|
|
public bool IsConnected => client.IsConnected;
|
|
|
|
/// <inheritdoc />
|
|
public HostKeyPresentation HostKey { get; } = hostKey;
|
|
|
|
/// <inheritdoc />
|
|
public Task<ISshShellSession> OpenShellAsync(TerminalSize size, CancellationToken cancellationToken)
|
|
{
|
|
cancellationToken.ThrowIfCancellationRequested();
|
|
|
|
var effective = size.IsUsable ? size : TerminalSize.Default;
|
|
|
|
// 4 KiB read buffer inside SSH.NET. Output is coalesced a layer up, so a larger buffer here
|
|
// only delays the first byte reaching the screen.
|
|
var shell = client.CreateShellStream(
|
|
"xterm-256color",
|
|
effective.Columns,
|
|
effective.Rows,
|
|
effective.PixelWidth,
|
|
effective.PixelHeight,
|
|
4096);
|
|
|
|
return Task.FromResult<ISshShellSession>(new SshNetShellSession(shell));
|
|
}
|
|
|
|
/// <inheritdoc />
|
|
public ValueTask DisposeAsync()
|
|
{
|
|
client.Dispose();
|
|
return ValueTask.CompletedTask;
|
|
}
|
|
}
|
|
|
|
/// <summary>An SSH.NET-backed shell session.</summary>
|
|
internal sealed class SshNetShellSession(ShellStream shell) : ISshShellSession
|
|
{
|
|
/// <inheritdoc />
|
|
public bool IsOpen => shell.CanRead;
|
|
|
|
/// <inheritdoc />
|
|
/// <remarks>
|
|
/// <c>ShellStream</c> does not override <c>ReadAsync</c>, so the base <see cref="Stream"/>
|
|
/// implementation runs the blocking read on a thread-pool thread. Every idle session therefore
|
|
/// parks one thread; see docs/platform-flags.md.
|
|
/// </remarks>
|
|
public ValueTask<int> ReadAsync(Memory<byte> buffer, CancellationToken cancellationToken) =>
|
|
shell.ReadAsync(buffer, cancellationToken);
|
|
|
|
/// <inheritdoc />
|
|
public ValueTask WriteAsync(ReadOnlyMemory<byte> data, CancellationToken cancellationToken) =>
|
|
shell.WriteAsync(data, cancellationToken);
|
|
|
|
/// <inheritdoc />
|
|
public void Resize(TerminalSize size)
|
|
{
|
|
if (!size.IsUsable)
|
|
{
|
|
// A collapsed pane or a minimised window produces these. Forwarding one leaves the
|
|
// remote's idea of the terminal nonsensical until the next resize arrives.
|
|
return;
|
|
}
|
|
|
|
shell.ChangeWindowSize(size.Columns, size.Rows, size.PixelWidth, size.PixelHeight);
|
|
}
|
|
|
|
/// <inheritdoc />
|
|
public async ValueTask DisposeAsync()
|
|
{
|
|
await shell.DisposeAsync().ConfigureAwait(false);
|
|
}
|
|
}
|
|
|
|
/// <summary>Convenience helpers over a shell session.</summary>
|
|
public static class SshShellSessionExtensions
|
|
{
|
|
/// <summary>Writes UTF-8 text to the remote.</summary>
|
|
public static ValueTask WriteTextAsync(
|
|
this ISshShellSession session,
|
|
string text,
|
|
CancellationToken cancellationToken)
|
|
{
|
|
ArgumentNullException.ThrowIfNull(session);
|
|
|
|
return session.WriteAsync(Encoding.UTF8.GetBytes(text), cancellationToken);
|
|
}
|
|
}
|