Compare commits
3 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 250ba269f5 | |||
| 3cd92945ac | |||
| 4576653b4e |
@@ -337,10 +337,24 @@ func (a *App) runSaveRemotePipeline(pngBytes []byte) error {
|
|||||||
}
|
}
|
||||||
slog.Info("save-remote dispatch",
|
slog.Info("save-remote dispatch",
|
||||||
"host", cfg.SSH.Host, "user", cfg.SSH.User, "port", cfg.SSH.Port,
|
"host", cfg.SSH.Host, "user", cfg.SSH.User, "port", cfg.SSH.Port,
|
||||||
"png_size", len(pngBytes))
|
"auth_method", cfg.SSH.AuthMethod, "png_size", len(pngBytes))
|
||||||
|
|
||||||
|
// Select the uploader by auth method: Kerberos delegates to the system
|
||||||
|
// ssh/scp binaries (reusing the kinit credential cache), bgo delegates to
|
||||||
|
// the internal `bgo scp` client (under a PTY), while builtin uses the
|
||||||
|
// in-process Go SSH client.
|
||||||
|
var uploader application.SSHUploader
|
||||||
|
switch {
|
||||||
|
case cfg.SSH.IsKerberos():
|
||||||
|
uploader = sshpkg.NewKerberosUploader(cfg.SSH)
|
||||||
|
case cfg.SSH.IsBgo():
|
||||||
|
uploader = sshpkg.NewBgoUploader(cfg.SSH)
|
||||||
|
default:
|
||||||
|
uploader = sshpkg.NewUploader(cfg.SSH)
|
||||||
|
}
|
||||||
|
|
||||||
svc := &application.CaptureAndSSHService{
|
svc := &application.CaptureAndSSHService{
|
||||||
Uploader: sshpkg.NewUploader(cfg.SSH),
|
Uploader: uploader,
|
||||||
Clipboard: a.clip,
|
Clipboard: a.clip,
|
||||||
Notifier: &runtimeNotifier{ctx: a.ctx},
|
Notifier: &runtimeNotifier{ctx: a.ctx},
|
||||||
Cfg: cfg.SSH,
|
Cfg: cfg.SSH,
|
||||||
@@ -446,7 +460,26 @@ func (a *App) TestConnection(cfg domain.S3Config) error {
|
|||||||
func (a *App) TestSSHConnection(cfg domain.SSHConfig) error {
|
func (a *App) TestSSHConnection(cfg domain.SSHConfig) error {
|
||||||
slog.Info("RPC TestSSHConnection",
|
slog.Info("RPC TestSSHConnection",
|
||||||
"host", cfg.Host, "user", cfg.User, "port", cfg.Port,
|
"host", cfg.Host, "user", cfg.User, "port", cfg.Port,
|
||||||
|
"auth_method", cfg.AuthMethod,
|
||||||
"strict_host_key", cfg.StrictHostKey, "has_password", cfg.Password != "")
|
"strict_host_key", cfg.StrictHostKey, "has_password", cfg.Password != "")
|
||||||
|
// Kerberos auth delegates to the system ssh binary (see KerberosUploader)
|
||||||
|
// so its probe path differs from the in-process client.
|
||||||
|
if cfg.IsKerberos() {
|
||||||
|
if err := sshpkg.TestKerberosConnection(a.ctx, cfg); err != nil {
|
||||||
|
slog.Error("RPC TestSSHConnection (kerberos) failed", "err", err)
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
// bgo manages its own auth; we can only confirm the binary is installed
|
||||||
|
// and resolvable (a real transfer would need a live remote + PTY).
|
||||||
|
if cfg.IsBgo() {
|
||||||
|
if err := sshpkg.TestBgoConnection(a.ctx, cfg); err != nil {
|
||||||
|
slog.Error("RPC TestSSHConnection (bgo) failed", "err", err)
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
if err := sshpkg.TestConnection(a.ctx, cfg); err != nil {
|
if err := sshpkg.TestConnection(a.ctx, cfg); err != nil {
|
||||||
slog.Error("RPC TestSSHConnection failed", "err", err)
|
slog.Error("RPC TestSSHConnection failed", "err", err)
|
||||||
return err
|
return err
|
||||||
|
|||||||
@@ -46,8 +46,8 @@ const activeTab = ref<SettingsTab>('general')
|
|||||||
// a one-line change. The label values match the user-facing tab names.
|
// a one-line change. The label values match the user-facing tab names.
|
||||||
const sidebarItems: Array<{ id: SettingsTab; label: string }> = [
|
const sidebarItems: Array<{ id: SettingsTab; label: string }> = [
|
||||||
{ id: 'general', label: 'General' },
|
{ id: 'general', label: 'General' },
|
||||||
{ id: 's3', label: 'S3-Conf' },
|
{ id: 's3', label: 'S3' },
|
||||||
{ id: 'ssh', label: 'SSH-Conf' },
|
{ id: 'ssh', label: 'SSH' },
|
||||||
]
|
]
|
||||||
|
|
||||||
interface OverlayPayload {
|
interface OverlayPayload {
|
||||||
|
|||||||
@@ -43,6 +43,7 @@ interface SSHConfig {
|
|||||||
host: string
|
host: string
|
||||||
port: number
|
port: number
|
||||||
user: string
|
user: string
|
||||||
|
authMethod: string
|
||||||
password: string
|
password: string
|
||||||
pathPrefix: string
|
pathPrefix: string
|
||||||
strictHostKey: boolean
|
strictHostKey: boolean
|
||||||
@@ -77,6 +78,7 @@ function defaultConfig(): AppConfig {
|
|||||||
host: '',
|
host: '',
|
||||||
port: 22,
|
port: 22,
|
||||||
user: '',
|
user: '',
|
||||||
|
authMethod: 'password',
|
||||||
password: '',
|
password: '',
|
||||||
pathPrefix: 'snapgo/',
|
pathPrefix: 'snapgo/',
|
||||||
strictHostKey: false,
|
strictHostKey: false,
|
||||||
@@ -280,14 +282,28 @@ onMounted(load)
|
|||||||
placeholder="22"
|
placeholder="22"
|
||||||
/>
|
/>
|
||||||
</label>
|
</label>
|
||||||
<label class="field">
|
<div class="field-row auth-row">
|
||||||
<span>User *</span>
|
<label class="field">
|
||||||
<input v-model="config.ssh.user" placeholder="ubuntu" />
|
<span>Auth method</span>
|
||||||
</label>
|
<select v-model="config.ssh.authMethod">
|
||||||
<label class="field">
|
<option value="password">Password</option>
|
||||||
<span>Password (optional)</span>
|
<option value="key">SSH-Key</option>
|
||||||
<input v-model="config.ssh.password" type="password" />
|
<option value="kerberos">Kerberos</option>
|
||||||
</label>
|
<option value="bgo">bgo</option>
|
||||||
|
</select>
|
||||||
|
</label>
|
||||||
|
<label class="field">
|
||||||
|
<span>User *</span>
|
||||||
|
<input v-model="config.ssh.user" placeholder="ubuntu" />
|
||||||
|
</label>
|
||||||
|
<label
|
||||||
|
v-if="config.ssh.authMethod === 'password'"
|
||||||
|
class="field"
|
||||||
|
>
|
||||||
|
<span>Password</span>
|
||||||
|
<input v-model="config.ssh.password" type="password" />
|
||||||
|
</label>
|
||||||
|
</div>
|
||||||
<label class="field full">
|
<label class="field full">
|
||||||
<span>Remote path (under home)</span>
|
<span>Remote path (under home)</span>
|
||||||
<div class="prefixed-input">
|
<div class="prefixed-input">
|
||||||
@@ -324,9 +340,35 @@ onMounted(load)
|
|||||||
</span>
|
</span>
|
||||||
</label>
|
</label>
|
||||||
</div>
|
</div>
|
||||||
<p v-if="!config.ssh.password" class="hint warn">
|
<p v-if="config.ssh.authMethod === 'kerberos'" class="hint">
|
||||||
Password is empty — please make sure password-less SSH is configured on
|
Kerberos mode delegates to the system <code>ssh</code>/<code>scp</code>.
|
||||||
this machine (e.g. via <code>ssh-copy-id</code> or your <code>ssh-agent</code>).
|
Run <code>kinit your.name@BYTEDANCE.COM</code> in a terminal first; tickets
|
||||||
|
expire (typically every 10–24h), so re-run <code>kinit</code> if uploads
|
||||||
|
start failing. Verify with <code>klist</code>.
|
||||||
|
</p>
|
||||||
|
<p v-else-if="config.ssh.authMethod === 'key'" class="hint">
|
||||||
|
SSH-Key mode uses your <code>ssh-agent</code> and <code>~/.ssh/id_*</code>
|
||||||
|
keys. Make sure password-less login already works (e.g. via
|
||||||
|
<code>ssh-copy-id</code>).
|
||||||
|
</p>
|
||||||
|
<p v-else-if="config.ssh.authMethod === 'bgo'" class="hint">
|
||||||
|
bgo mode delegates uploads to the internal <code>bgo scp</code> client,
|
||||||
|
which handles authentication itself. Install bgo and add it to your
|
||||||
|
<code>PATH</code> first — see the
|
||||||
|
<a
|
||||||
|
href="https://bytedance.larkoffice.com/wiki/HpUCw7qRDiW66YkzKdwcXYrTnLf"
|
||||||
|
target="_blank"
|
||||||
|
rel="noopener"
|
||||||
|
>setup guide</a>.
|
||||||
|
Note: bgo cannot create remote directories, so screenshots are saved
|
||||||
|
flat into the remote home directory (the Remote path setting is ignored).
|
||||||
|
</p>
|
||||||
|
<p
|
||||||
|
v-else-if="config.ssh.authMethod === 'password' && !config.ssh.password"
|
||||||
|
class="hint warn"
|
||||||
|
>
|
||||||
|
Password is empty — enter the remote login password, or switch the auth
|
||||||
|
method to SSH-Key.
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<div class="actions">
|
<div class="actions">
|
||||||
@@ -414,17 +456,30 @@ kbd {
|
|||||||
.field.full {
|
.field.full {
|
||||||
grid-column: 1 / -1;
|
grid-column: 1 / -1;
|
||||||
}
|
}
|
||||||
|
/* field-row groups several fields onto a single full-width row. auth-row
|
||||||
|
splits Auth method / User / Password roughly 1:2:2. */
|
||||||
|
.field-row {
|
||||||
|
grid-column: 1 / -1;
|
||||||
|
display: grid;
|
||||||
|
gap: 12px 16px;
|
||||||
|
}
|
||||||
|
.auth-row {
|
||||||
|
grid-template-columns: 1fr 2fr 2fr;
|
||||||
|
}
|
||||||
.field span {
|
.field span {
|
||||||
color: #374151;
|
color: #374151;
|
||||||
font-weight: 500;
|
font-weight: 500;
|
||||||
}
|
}
|
||||||
.field input[type='text'],
|
.field input[type='text'],
|
||||||
.field input[type='number'],
|
.field input[type='number'],
|
||||||
.field input:not([type='checkbox']) {
|
.field input:not([type='checkbox']),
|
||||||
|
.field select {
|
||||||
border: 1px solid #d1d5db;
|
border: 1px solid #d1d5db;
|
||||||
border-radius: 6px;
|
border-radius: 6px;
|
||||||
padding: 7px 10px;
|
padding: 7px 10px;
|
||||||
font-size: 13px;
|
font-size: 13px;
|
||||||
|
line-height: 1.4;
|
||||||
|
height: 36px;
|
||||||
background: #fff;
|
background: #fff;
|
||||||
color: inherit;
|
color: inherit;
|
||||||
outline: none;
|
outline: none;
|
||||||
@@ -432,7 +487,8 @@ kbd {
|
|||||||
width: 100%;
|
width: 100%;
|
||||||
box-sizing: border-box;
|
box-sizing: border-box;
|
||||||
}
|
}
|
||||||
.field input:focus {
|
.field input:focus,
|
||||||
|
.field select:focus {
|
||||||
border-color: #3b82f6;
|
border-color: #3b82f6;
|
||||||
box-shadow: 0 0 0 3px rgba(59, 130, 246, 0.18);
|
box-shadow: 0 0 0 3px rgba(59, 130, 246, 0.18);
|
||||||
}
|
}
|
||||||
@@ -560,6 +616,11 @@ kbd {
|
|||||||
border-color: #374151;
|
border-color: #374151;
|
||||||
color: #e5e7eb;
|
color: #e5e7eb;
|
||||||
}
|
}
|
||||||
|
.field select {
|
||||||
|
background: #111827;
|
||||||
|
border-color: #374151;
|
||||||
|
color: #e5e7eb;
|
||||||
|
}
|
||||||
.field input:disabled {
|
.field input:disabled {
|
||||||
background: #1f2937;
|
background: #1f2937;
|
||||||
color: #6b7280;
|
color: #6b7280;
|
||||||
|
|||||||
@@ -57,6 +57,7 @@ export namespace domain {
|
|||||||
host: string;
|
host: string;
|
||||||
port: number;
|
port: number;
|
||||||
user: string;
|
user: string;
|
||||||
|
authMethod: string;
|
||||||
password: string;
|
password: string;
|
||||||
pathPrefix: string;
|
pathPrefix: string;
|
||||||
strictHostKey: boolean;
|
strictHostKey: boolean;
|
||||||
@@ -72,6 +73,7 @@ export namespace domain {
|
|||||||
this.host = source["host"];
|
this.host = source["host"];
|
||||||
this.port = source["port"];
|
this.port = source["port"];
|
||||||
this.user = source["user"];
|
this.user = source["user"];
|
||||||
|
this.authMethod = source["authMethod"];
|
||||||
this.password = source["password"];
|
this.password = source["password"];
|
||||||
this.pathPrefix = source["pathPrefix"];
|
this.pathPrefix = source["pathPrefix"];
|
||||||
this.strictHostKey = source["strictHostKey"];
|
this.strictHostKey = source["strictHostKey"];
|
||||||
|
|||||||
@@ -69,6 +69,12 @@ func (s *CaptureAndSSHService) ExecuteWithBytes(ctx context.Context, pngBytes []
|
|||||||
return fmt.Errorf("empty screenshot")
|
return fmt.Errorf("empty screenshot")
|
||||||
}
|
}
|
||||||
relPath := buildRemoteRelPath(s.Cfg.PathPrefix)
|
relPath := buildRemoteRelPath(s.Cfg.PathPrefix)
|
||||||
|
// bgo cannot create remote directories, so it uploads flat into the
|
||||||
|
// remote $HOME with a timestamped filename rather than a date-grouped
|
||||||
|
// subdirectory tree (see BgoUploader for the rationale).
|
||||||
|
if s.Cfg.IsBgo() {
|
||||||
|
relPath = buildRemoteFlatName()
|
||||||
|
}
|
||||||
sshSvcLog().Info("save-remote pipeline start",
|
sshSvcLog().Info("save-remote pipeline start",
|
||||||
"host", s.Cfg.Host, "user", s.Cfg.User, "port", s.Cfg.Port,
|
"host", s.Cfg.Host, "user", s.Cfg.User, "port", s.Cfg.Port,
|
||||||
"size", len(pngBytes), "remote_path", relPath,
|
"size", len(pngBytes), "remote_path", relPath,
|
||||||
@@ -128,6 +134,17 @@ func buildRemoteRelPath(prefix string) string {
|
|||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// buildRemoteFlatName produces a flat, timestamped filename (no directory
|
||||||
|
// components) for destinations that cannot create remote directories, such
|
||||||
|
// as the bgo client. The file lands directly in the remote $HOME.
|
||||||
|
func buildRemoteFlatName() string {
|
||||||
|
now := time.Now()
|
||||||
|
return fmt.Sprintf("%s-%s.png",
|
||||||
|
now.Format("20060102-150405"),
|
||||||
|
randomSuffix(6),
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
func (s *CaptureAndSSHService) notifyFailure(reason string) {
|
func (s *CaptureAndSSHService) notifyFailure(reason string) {
|
||||||
if s.Notifier != nil {
|
if s.Notifier != nil {
|
||||||
s.Notifier.NotifyFailure(reason)
|
s.Notifier.NotifyFailure(reason)
|
||||||
|
|||||||
@@ -10,12 +10,12 @@ package domain
|
|||||||
// endpoint, etc.).
|
// endpoint, etc.).
|
||||||
//
|
//
|
||||||
// Field design notes:
|
// Field design notes:
|
||||||
// - PathPrefix supports object name templating so users can group screenshots
|
// - PathPrefix supports object name templating so users can group screenshots
|
||||||
// by date.
|
// by date.
|
||||||
// - PublicURLBase is optional to support CDN-fronted buckets; otherwise the
|
// - PublicURLBase is optional to support CDN-fronted buckets; otherwise the
|
||||||
// adapter falls back to "{Endpoint}/{Bucket}/{Key}" (path-style).
|
// adapter falls back to "{Endpoint}/{Bucket}/{Key}" (path-style).
|
||||||
// - UsePathStyle defaults to true because many self-hosted MinIO / R2
|
// - UsePathStyle defaults to true because many self-hosted MinIO / R2
|
||||||
// deployments do not support virtual-hosted-style addressing.
|
// deployments do not support virtual-hosted-style addressing.
|
||||||
type S3Config struct {
|
type S3Config struct {
|
||||||
Endpoint string `json:"endpoint"`
|
Endpoint string `json:"endpoint"`
|
||||||
Region string `json:"region"`
|
Region string `json:"region"`
|
||||||
@@ -33,9 +33,27 @@ type S3Config struct {
|
|||||||
// Field design notes:
|
// Field design notes:
|
||||||
// - Host / Port form the destination endpoint. Port defaults to 22 when 0.
|
// - Host / Port form the destination endpoint. Port defaults to 22 when 0.
|
||||||
// - User is the SSH login name.
|
// - User is the SSH login name.
|
||||||
|
// - AuthMethod selects how the connection authenticates:
|
||||||
|
// "password" → password only, via the in-process Go SSH client.
|
||||||
|
// "key" → ssh-agent + ~/.ssh/id_* key files (no password),
|
||||||
|
// via the in-process Go SSH client.
|
||||||
|
// "kerberos" → delegate to the system /usr/bin/ssh binary so the
|
||||||
|
// existing Kerberos (GSSAPI) credential cache from
|
||||||
|
// `kinit` is reused. Native GSSAPI is required here
|
||||||
|
// because macOS stores tickets in an API: ccache
|
||||||
|
// that pure-Go SSH libraries cannot read.
|
||||||
|
// "bgo" → delegate to the internal `bgo scp` client which
|
||||||
|
// handles its own auth/credential management. bgo
|
||||||
|
// must run under a PTY and cannot create remote
|
||||||
|
// directories, so this mode uploads to the user's
|
||||||
|
// remote $HOME with a flat, timestamped filename.
|
||||||
|
// "" / "builtin" → legacy combined behaviour (password → agent → key
|
||||||
|
// files) kept only for backward compatibility with
|
||||||
|
// configs written before the method was split.
|
||||||
// - Password is optional; when empty the implementation falls back to the
|
// - Password is optional; when empty the implementation falls back to the
|
||||||
// local SSH agent or ~/.ssh/id_* keys (i.e. the user is responsible for
|
// local SSH agent or ~/.ssh/id_* keys (i.e. the user is responsible for
|
||||||
// having password-less access already configured on this machine).
|
// having password-less access already configured on this machine).
|
||||||
|
// It is ignored entirely when AuthMethod is "kerberos".
|
||||||
// - PathPrefix is interpreted *relative to the remote user's $HOME*. The
|
// - PathPrefix is interpreted *relative to the remote user's $HOME*. The
|
||||||
// UI presents it as "~/<PathPrefix>" so the user cannot escape the home
|
// UI presents it as "~/<PathPrefix>" so the user cannot escape the home
|
||||||
// directory by writing absolute paths. Leading "/" or "~" markers are
|
// directory by writing absolute paths. Leading "/" or "~" markers are
|
||||||
@@ -51,6 +69,7 @@ type SSHConfig struct {
|
|||||||
Host string `json:"host"`
|
Host string `json:"host"`
|
||||||
Port int `json:"port"`
|
Port int `json:"port"`
|
||||||
User string `json:"user"`
|
User string `json:"user"`
|
||||||
|
AuthMethod string `json:"authMethod"`
|
||||||
Password string `json:"password"`
|
Password string `json:"password"`
|
||||||
PathPrefix string `json:"pathPrefix"`
|
PathPrefix string `json:"pathPrefix"`
|
||||||
StrictHostKey bool `json:"strictHostKey"`
|
StrictHostKey bool `json:"strictHostKey"`
|
||||||
@@ -58,6 +77,35 @@ type SSHConfig struct {
|
|||||||
ConnectTimeoutSecs int `json:"connectTimeoutSecs"`
|
ConnectTimeoutSecs int `json:"connectTimeoutSecs"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// SSH authentication method identifiers stored in SSHConfig.AuthMethod.
|
||||||
|
const (
|
||||||
|
// SSHAuthBuiltin is the legacy combined method (password → agent → key
|
||||||
|
// files). Retained for backward compatibility with older config files;
|
||||||
|
// new configs use the explicit methods below.
|
||||||
|
SSHAuthBuiltin = "builtin"
|
||||||
|
// SSHAuthPassword authenticates with the password field only.
|
||||||
|
SSHAuthPassword = "password"
|
||||||
|
// SSHAuthKey authenticates with ssh-agent / ~/.ssh/id_* key files only.
|
||||||
|
SSHAuthKey = "key"
|
||||||
|
// SSHAuthKerberos delegates to the system ssh binary so an existing
|
||||||
|
// Kerberos credential cache (populated by `kinit`) is reused via GSSAPI.
|
||||||
|
SSHAuthKerberos = "kerberos"
|
||||||
|
// SSHAuthBgo delegates to the internal `bgo scp` client, which manages
|
||||||
|
// its own authentication. bgo requires a PTY and cannot create remote
|
||||||
|
// directories, so uploads land flat in the remote $HOME.
|
||||||
|
SSHAuthBgo = "bgo"
|
||||||
|
)
|
||||||
|
|
||||||
|
// IsKerberos reports whether this config requests Kerberos/GSSAPI auth.
|
||||||
|
func (c SSHConfig) IsKerberos() bool {
|
||||||
|
return c.AuthMethod == SSHAuthKerberos
|
||||||
|
}
|
||||||
|
|
||||||
|
// IsBgo reports whether this config requests the internal bgo client.
|
||||||
|
func (c SSHConfig) IsBgo() bool {
|
||||||
|
return c.AuthMethod == SSHAuthBgo
|
||||||
|
}
|
||||||
|
|
||||||
// AppConfig is the top-level on-disk configuration document.
|
// AppConfig is the top-level on-disk configuration document.
|
||||||
//
|
//
|
||||||
// We keep S3 / SSH nested so that adding more providers later (e.g. AliyunOSS,
|
// We keep S3 / SSH nested so that adding more providers later (e.g. AliyunOSS,
|
||||||
|
|||||||
@@ -0,0 +1,200 @@
|
|||||||
|
// bgo_uploader.go — an SSHUploader implementation that delegates to the
|
||||||
|
// internal `bgo scp` client. bgo is ByteDance's internal credential/auth
|
||||||
|
// management tool; it wraps ssh/scp and handles login transparently once the
|
||||||
|
// user has configured it (see the Lark guide linked in the Settings UI).
|
||||||
|
//
|
||||||
|
// 设计理由 (为什么不能直接 exec bgo, 也不能复用 KerberosUploader):
|
||||||
|
// - bgo 强制要求在 PTY (伪终端) 下运行: 它会对 stdin/stdout 做终端 ioctl
|
||||||
|
// (resize pty). 没有 PTY 时直接 panic ("operation not supported by
|
||||||
|
// device"). 因此必须用系统 /usr/bin/script 为其分配一个伪终端:
|
||||||
|
// script -q /dev/null <bgo> scp <src> <user@host:dst>
|
||||||
|
// 这样既不引入额外的 PTY 依赖, 又满足 bgo 的运行约束.
|
||||||
|
// - bgo scp 不会自动创建远程目录, 且 bgo ssh 无法执行远程命令 (会 panic),
|
||||||
|
// 所以无法像 Kerberos 那样先 `mkdir -p`. 故 bgo 模式只能把文件平铺上传
|
||||||
|
// 到远端用户的 $HOME 根目录 (文件名内嵌时间戳保证唯一), 上层 service
|
||||||
|
// 负责生成扁平文件名.
|
||||||
|
// - bgo 自带鉴权, 不需要也不应传 GSSAPI / 密码 / 公钥相关的 ssh 选项.
|
||||||
|
package ssh
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"context"
|
||||||
|
"fmt"
|
||||||
|
"os"
|
||||||
|
"os/exec"
|
||||||
|
"path"
|
||||||
|
"path/filepath"
|
||||||
|
"strconv"
|
||||||
|
"strings"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/mmmy/snapgo/internal/domain"
|
||||||
|
)
|
||||||
|
|
||||||
|
// systemScriptPath is the absolute path to the macOS BSD `script` utility,
|
||||||
|
// which we use purely to allocate a PTY for bgo. Absolute path avoids PATH
|
||||||
|
// hijacking and the minimal PATH GUI apps inherit on macOS.
|
||||||
|
const systemScriptPath = "/usr/bin/script"
|
||||||
|
|
||||||
|
// bgoSearchPaths lists the locations we probe for the bgo binary when it is
|
||||||
|
// not already resolvable via $PATH. GUI apps on macOS launch with a minimal
|
||||||
|
// PATH that usually omits ~/.local/bin and Homebrew dirs, so we look there
|
||||||
|
// explicitly rather than failing with a confusing "command not found".
|
||||||
|
func bgoSearchPaths() []string {
|
||||||
|
home, _ := os.UserHomeDir()
|
||||||
|
return []string{
|
||||||
|
filepath.Join(home, ".local", "bin", "bgo"),
|
||||||
|
"/usr/local/bin/bgo",
|
||||||
|
"/opt/homebrew/bin/bgo",
|
||||||
|
"/opt/bin/bgo",
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// BgoUploader satisfies application.SSHUploader by shelling out to `bgo scp`
|
||||||
|
// under a PTY allocated via the system `script` utility.
|
||||||
|
type BgoUploader struct {
|
||||||
|
cfg domain.SSHConfig
|
||||||
|
}
|
||||||
|
|
||||||
|
// NewBgoUploader returns an uploader that delegates to the bgo client.
|
||||||
|
func NewBgoUploader(cfg domain.SSHConfig) *BgoUploader {
|
||||||
|
return &BgoUploader{cfg: cfg}
|
||||||
|
}
|
||||||
|
|
||||||
|
// resolveBgoBinary locates the bgo executable, first via $PATH and then via
|
||||||
|
// the well-known install locations. Returns a clear error pointing the user
|
||||||
|
// to the setup guide when bgo cannot be found.
|
||||||
|
func resolveBgoBinary() (string, error) {
|
||||||
|
if p, err := exec.LookPath("bgo"); err == nil {
|
||||||
|
return p, nil
|
||||||
|
}
|
||||||
|
for _, candidate := range bgoSearchPaths() {
|
||||||
|
if info, err := os.Stat(candidate); err == nil && !info.IsDir() {
|
||||||
|
return candidate, nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return "", fmt.Errorf("bgo executable not found — install bgo and add it to PATH (see the setup guide)")
|
||||||
|
}
|
||||||
|
|
||||||
|
// Upload writes data to a flat remote filename in the user's remote $HOME by
|
||||||
|
// staging it locally and invoking `bgo scp` once under a PTY.
|
||||||
|
//
|
||||||
|
// remoteRelPath is expected to be a flat filename (no directory components),
|
||||||
|
// because bgo cannot create remote directories. Any directory components are
|
||||||
|
// collapsed to the base name defensively.
|
||||||
|
func (u *BgoUploader) Upload(ctx context.Context, remoteRelPath string, data []byte, mode os.FileMode) error {
|
||||||
|
start := time.Now()
|
||||||
|
// Collapse to a flat filename: bgo scp cannot create remote directories.
|
||||||
|
name := path.Base(normaliseRemotePath(remoteRelPath))
|
||||||
|
if name == "" || name == "." || name == "/" {
|
||||||
|
return fmt.Errorf("ssh(bgo): remote filename is empty")
|
||||||
|
}
|
||||||
|
|
||||||
|
bgoBin, err := resolveBgoBinary()
|
||||||
|
if err != nil {
|
||||||
|
sshLog().Error("bgo uploader: binary not found", "err", err)
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
sshLog().Info("bgo uploader start",
|
||||||
|
"host", u.cfg.Host, "user", u.cfg.User, "port", u.cfg.Port,
|
||||||
|
"remote_file", name, "size", len(data), "bgo", bgoBin)
|
||||||
|
|
||||||
|
// 1. Stage the payload to a local temp file for scp to read.
|
||||||
|
tmp, err := os.CreateTemp("", "snapgo-bgo-*.png")
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("ssh(bgo): create temp: %w", err)
|
||||||
|
}
|
||||||
|
tmpPath := tmp.Name()
|
||||||
|
defer os.Remove(tmpPath)
|
||||||
|
if _, err := tmp.Write(data); err != nil {
|
||||||
|
_ = tmp.Close()
|
||||||
|
return fmt.Errorf("ssh(bgo): write temp: %w", err)
|
||||||
|
}
|
||||||
|
if err := tmp.Close(); err != nil {
|
||||||
|
return fmt.Errorf("ssh(bgo): close temp: %w", err)
|
||||||
|
}
|
||||||
|
if err := os.Chmod(tmpPath, mode.Perm()); err != nil {
|
||||||
|
sshLog().Debug("bgo uploader chmod temp failed", "err", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// 2. bgo scp <tmp> <user@host:name> under a PTY (via `script`).
|
||||||
|
remoteTarget := fmt.Sprintf("%s@%s:%s", u.cfg.User, bracketHost(u.cfg.Host), name)
|
||||||
|
bgoArgs := u.bgoScpArgs(bgoBin, tmpPath, remoteTarget)
|
||||||
|
if err := u.runUnderPTY(ctx, bgoArgs); err != nil {
|
||||||
|
sshLog().Error("bgo uploader scp failed",
|
||||||
|
"remote_file", name, "elapsed", time.Since(start), "err", err)
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
sshLog().Info("bgo uploader done",
|
||||||
|
"remote_file", name, "size", len(data), "total_elapsed", time.Since(start))
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// bgoScpArgs builds the argument vector "bgo scp [-P port] <src> <dst>".
|
||||||
|
// bgo manages its own auth, so we pass no ssh -o options here.
|
||||||
|
func (u *BgoUploader) bgoScpArgs(bgoBin, src, dst string) []string {
|
||||||
|
args := []string{bgoBin, "scp"}
|
||||||
|
if u.cfg.Port > 0 && u.cfg.Port != 22 {
|
||||||
|
args = append(args, "-P", strconv.Itoa(u.cfg.Port))
|
||||||
|
}
|
||||||
|
args = append(args, src, dst)
|
||||||
|
return args
|
||||||
|
}
|
||||||
|
|
||||||
|
// runUnderPTY runs the given command vector under a PTY allocated by the
|
||||||
|
// system `script` utility, capturing combined output for diagnostics.
|
||||||
|
//
|
||||||
|
// macOS BSD script signature: `script -q <typescript-file> command [args...]`.
|
||||||
|
// We discard the typescript by writing to /dev/null.
|
||||||
|
func (u *BgoUploader) runUnderPTY(ctx context.Context, cmdVec []string) error {
|
||||||
|
args := append([]string{"-q", "/dev/null"}, cmdVec...)
|
||||||
|
cmd := exec.CommandContext(ctx, systemScriptPath, args...)
|
||||||
|
var combined bytes.Buffer
|
||||||
|
cmd.Stdout = &combined
|
||||||
|
cmd.Stderr = &combined
|
||||||
|
sshLog().Debug("bgo exec", "args", strings.Join(args, " "))
|
||||||
|
if err := cmd.Run(); err != nil {
|
||||||
|
msg := strings.TrimSpace(combined.String())
|
||||||
|
if msg == "" {
|
||||||
|
msg = err.Error()
|
||||||
|
}
|
||||||
|
return fmt.Errorf("bgo scp failed: %s", msg)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// bracketHost wraps a bare IPv6 literal in [] so the "user@host:path" target
|
||||||
|
// parses correctly (e.g. fdbd:dc03:8:379::130 → [fdbd:dc03:8:379::130]).
|
||||||
|
// IPv4 addresses and hostnames are returned unchanged. Already-bracketed
|
||||||
|
// inputs are left as-is.
|
||||||
|
func bracketHost(host string) string {
|
||||||
|
host = strings.TrimSpace(host)
|
||||||
|
if host == "" {
|
||||||
|
return host
|
||||||
|
}
|
||||||
|
if strings.HasPrefix(host, "[") {
|
||||||
|
return host
|
||||||
|
}
|
||||||
|
// An IPv6 literal contains multiple ':' separators; a hostname:port style
|
||||||
|
// is not expected here because the port lives in cfg.Port.
|
||||||
|
if strings.Count(host, ":") >= 2 {
|
||||||
|
return "[" + host + "]"
|
||||||
|
}
|
||||||
|
return host
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestBgoConnection verifies that the bgo binary is resolvable. A real
|
||||||
|
// transfer test is intentionally avoided: bgo requires a PTY and a live
|
||||||
|
// remote, and bgo ssh cannot run a harmless remote probe command (it panics).
|
||||||
|
// Confirming bgo is installed and on PATH is the most useful signal we can
|
||||||
|
// give without performing an actual upload.
|
||||||
|
func TestBgoConnection(ctx context.Context, cfg domain.SSHConfig) error {
|
||||||
|
sshLog().Info("bgo test connection start", "host", cfg.Host, "user", cfg.User)
|
||||||
|
bin, err := resolveBgoBinary()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
sshLog().Info("bgo test connection ok", "bgo", bin)
|
||||||
|
return nil
|
||||||
|
}
|
||||||
@@ -385,7 +385,14 @@ func shellQuote(s string) string {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// buildAuthMethods chooses authentication methods given the supplied
|
// buildAuthMethods chooses authentication methods given the supplied
|
||||||
// configuration. See Dial's docstring for the priority order.
|
// configuration.
|
||||||
|
//
|
||||||
|
// The method set is gated by cfg.AuthMethod:
|
||||||
|
// - SSHAuthPassword → password only.
|
||||||
|
// - SSHAuthKey → ssh-agent + ~/.ssh/id_* key files only.
|
||||||
|
// - "" / SSHAuthBuiltin (legacy) → password (if set) + agent + key files.
|
||||||
|
//
|
||||||
|
// (Kerberos never reaches here; it uses the system ssh binary instead.)
|
||||||
//
|
//
|
||||||
// Returns a human-readable summary alongside the method slice so the
|
// Returns a human-readable summary alongside the method slice so the
|
||||||
// caller can include "password+agent+ed25519" (and similar) in its dial
|
// caller can include "password+agent+ed25519" (and similar) in its dial
|
||||||
@@ -393,47 +400,58 @@ func shellQuote(s string) string {
|
|||||||
func buildAuthMethods(cfg domain.SSHConfig) ([]ssh.AuthMethod, string, error) {
|
func buildAuthMethods(cfg domain.SSHConfig) ([]ssh.AuthMethod, string, error) {
|
||||||
var methods []ssh.AuthMethod
|
var methods []ssh.AuthMethod
|
||||||
var sources []string
|
var sources []string
|
||||||
if cfg.Password != "" {
|
|
||||||
|
// Decide which families are allowed for the selected method. An empty /
|
||||||
|
// "builtin" value preserves the original combined behaviour so configs
|
||||||
|
// written before the split keep working.
|
||||||
|
allowPassword := cfg.AuthMethod == domain.SSHAuthPassword ||
|
||||||
|
cfg.AuthMethod == domain.SSHAuthBuiltin || cfg.AuthMethod == ""
|
||||||
|
allowKey := cfg.AuthMethod == domain.SSHAuthKey ||
|
||||||
|
cfg.AuthMethod == domain.SSHAuthBuiltin || cfg.AuthMethod == ""
|
||||||
|
|
||||||
|
if allowPassword && cfg.Password != "" {
|
||||||
methods = append(methods, ssh.Password(cfg.Password))
|
methods = append(methods, ssh.Password(cfg.Password))
|
||||||
sources = append(sources, "password")
|
sources = append(sources, "password")
|
||||||
}
|
}
|
||||||
if sock := os.Getenv("SSH_AUTH_SOCK"); sock != "" {
|
if allowKey {
|
||||||
if conn, err := net.Dial("unix", sock); err == nil {
|
if sock := os.Getenv("SSH_AUTH_SOCK"); sock != "" {
|
||||||
// 关键: 仅在 agent 真正持有 key 时才把它加入 auth methods.
|
if conn, err := net.Dial("unix", sock); err == nil {
|
||||||
//
|
// 关键: 仅在 agent 真正持有 key 时才把它加入 auth methods.
|
||||||
// macOS 的 launchd ssh-agent 即便没有任何 identity 也会响应,
|
//
|
||||||
// 此时若仍注册 PublicKeysCallback, x/crypto 会把它当作一次空的
|
// macOS 的 launchd ssh-agent 即便没有任何 identity 也会响应,
|
||||||
// publickey 尝试. 配合服务器的 MaxAuthTries 计数, 这次"空尝试"
|
// 此时若仍注册 PublicKeysCallback, x/crypto 会把它当作一次空的
|
||||||
// 会挤占后续基于磁盘私钥的认证机会, 最终导致
|
// publickey 尝试. 配合服务器的 MaxAuthTries 计数, 这次"空尝试"
|
||||||
// "[none publickey] no supported methods remain" —— 即便磁盘上
|
// 会挤占后续基于磁盘私钥的认证机会, 最终导致
|
||||||
// 的 key 本身完全可用. 因此空 agent 必须跳过.
|
// "[none publickey] no supported methods remain" —— 即便磁盘上
|
||||||
ag := agent.NewClient(conn)
|
// 的 key 本身完全可用. 因此空 agent 必须跳过.
|
||||||
if keys, lerr := ag.List(); lerr == nil && len(keys) > 0 {
|
ag := agent.NewClient(conn)
|
||||||
methods = append(methods, ssh.PublicKeysCallback(ag.Signers))
|
if keys, lerr := ag.List(); lerr == nil && len(keys) > 0 {
|
||||||
sources = append(sources, fmt.Sprintf("agent(%d)", len(keys)))
|
methods = append(methods, ssh.PublicKeysCallback(ag.Signers))
|
||||||
|
sources = append(sources, fmt.Sprintf("agent(%d)", len(keys)))
|
||||||
|
} else {
|
||||||
|
sshLog().Debug("ssh-agent has no identities; skipping",
|
||||||
|
"sock", sock, "list_err", lerr)
|
||||||
|
}
|
||||||
} else {
|
} else {
|
||||||
sshLog().Debug("ssh-agent has no identities; skipping",
|
sshLog().Debug("ssh-agent dial failed", "sock", sock, "err", err)
|
||||||
"sock", sock, "list_err", lerr)
|
}
|
||||||
|
}
|
||||||
|
home, err := os.UserHomeDir()
|
||||||
|
if err == nil {
|
||||||
|
// Probe the common default keys; any unreadable / missing file is
|
||||||
|
// silently skipped so the user never sees noise about keys they did
|
||||||
|
// not set up.
|
||||||
|
for _, name := range []string{"id_ed25519", "id_rsa", "id_ecdsa"} {
|
||||||
|
signer, err := loadPrivateKey(path.Join(home, ".ssh", name))
|
||||||
|
if err == nil && signer != nil {
|
||||||
|
methods = append(methods, ssh.PublicKeys(signer))
|
||||||
|
sources = append(sources, name)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
sshLog().Debug("ssh-agent dial failed", "sock", sock, "err", err)
|
sshLog().Debug("home dir unavailable for ssh keys", "err", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
home, err := os.UserHomeDir()
|
|
||||||
if err == nil {
|
|
||||||
// Probe the common default keys; any unreadable / missing file is
|
|
||||||
// silently skipped so the user never sees noise about keys they did
|
|
||||||
// not set up.
|
|
||||||
for _, name := range []string{"id_ed25519", "id_rsa", "id_ecdsa"} {
|
|
||||||
signer, err := loadPrivateKey(path.Join(home, ".ssh", name))
|
|
||||||
if err == nil && signer != nil {
|
|
||||||
methods = append(methods, ssh.PublicKeys(signer))
|
|
||||||
sources = append(sources, name)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
sshLog().Debug("home dir unavailable for ssh keys", "err", err)
|
|
||||||
}
|
|
||||||
if len(sources) == 0 {
|
if len(sources) == 0 {
|
||||||
return methods, "none", nil
|
return methods, "none", nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,230 @@
|
|||||||
|
// kerberos_uploader.go — an SSHUploader implementation that delegates to
|
||||||
|
// the system /usr/bin/ssh + /usr/bin/scp binaries so an existing Kerberos
|
||||||
|
// (GSSAPI) credential cache populated by `kinit` is reused transparently.
|
||||||
|
//
|
||||||
|
// 设计理由 (为什么不用 golang.org/x/crypto/ssh 做 Kerberos):
|
||||||
|
// - macOS 的 Kerberos 票据默认存放在 API: 类型的 credential cache 中,
|
||||||
|
// 由系统 GSSD (Heimdal) 守护进程托管. Go 生态的 gokrb5 只能读取
|
||||||
|
// FILE: 类型 ccache 与 keytab, 无法访问 API: ccache, 因此在 macOS 上
|
||||||
|
// 用纯 Go 实现 GSSAPI 认证基本不可行.
|
||||||
|
// - 系统自带的 /usr/bin/ssh 原生集成 Heimdal GSSAPI, 用户 `kinit` 之后
|
||||||
|
// 的票据可被直接复用. 把上传委托给系统 ssh/scp 是最稳妥的方案, 也与
|
||||||
|
// 用户"命令行能免密登录即可"的预期完全一致.
|
||||||
|
// - 仅在 AuthMethod == kerberos 时启用此实现; builtin 路径不受影响.
|
||||||
|
package ssh
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"context"
|
||||||
|
"fmt"
|
||||||
|
"os"
|
||||||
|
"os/exec"
|
||||||
|
"path"
|
||||||
|
"strconv"
|
||||||
|
"strings"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/mmmy/snapgo/internal/domain"
|
||||||
|
)
|
||||||
|
|
||||||
|
// systemSSHPath / systemSCPPath are the absolute paths to the macOS system
|
||||||
|
// binaries. We use absolute paths rather than relying on $PATH so a hijacked
|
||||||
|
// PATH cannot redirect us to an arbitrary binary, and because GUI apps on
|
||||||
|
// macOS often launch with a minimal PATH that omits /usr/bin entirely.
|
||||||
|
const (
|
||||||
|
systemSSHPath = "/usr/bin/ssh"
|
||||||
|
systemSCPPath = "/usr/bin/scp"
|
||||||
|
)
|
||||||
|
|
||||||
|
// KerberosUploader satisfies application.SSHUploader by shelling out to the
|
||||||
|
// system scp binary with GSSAPI authentication enabled.
|
||||||
|
type KerberosUploader struct {
|
||||||
|
cfg domain.SSHConfig
|
||||||
|
}
|
||||||
|
|
||||||
|
// NewKerberosUploader returns an uploader that delegates to system scp.
|
||||||
|
func NewKerberosUploader(cfg domain.SSHConfig) *KerberosUploader {
|
||||||
|
return &KerberosUploader{cfg: cfg}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Upload writes data to remoteRelPath (relative to the remote $HOME) by
|
||||||
|
// staging it in a local temp file and invoking system scp once.
|
||||||
|
//
|
||||||
|
// We stage to a temp file because scp transfers files, not stdin; piping a
|
||||||
|
// stream would require the more fragile `scp -t` sink protocol that we only
|
||||||
|
// use for the in-process client. A temp file is simpler and robust.
|
||||||
|
func (u *KerberosUploader) Upload(ctx context.Context, remoteRelPath string, data []byte, mode os.FileMode) error {
|
||||||
|
start := time.Now()
|
||||||
|
cleaned := normaliseRemotePath(remoteRelPath)
|
||||||
|
if cleaned == "" {
|
||||||
|
return fmt.Errorf("ssh(kerberos): remote path is empty")
|
||||||
|
}
|
||||||
|
sshLog().Info("kerberos uploader start",
|
||||||
|
"host", u.cfg.Host, "user", u.cfg.User, "port", u.cfg.Port,
|
||||||
|
"remote_path", cleaned, "size", len(data))
|
||||||
|
|
||||||
|
// 1. Ensure the remote directory tree exists. scp itself will not create
|
||||||
|
// intermediate directories, so we run a remote `mkdir -p` first.
|
||||||
|
dir, _ := path.Split(cleaned)
|
||||||
|
dir = strings.Trim(dir, "/")
|
||||||
|
if dir != "" {
|
||||||
|
if err := u.runRemoteMkdir(ctx, dir); err != nil {
|
||||||
|
sshLog().Error("kerberos uploader mkdir failed",
|
||||||
|
"dir", dir, "elapsed", time.Since(start), "err", err)
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// 2. Stage the payload to a local temp file for scp to read.
|
||||||
|
tmp, err := os.CreateTemp("", "snapgo-scp-*.png")
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("ssh(kerberos): create temp: %w", err)
|
||||||
|
}
|
||||||
|
tmpPath := tmp.Name()
|
||||||
|
defer os.Remove(tmpPath)
|
||||||
|
if _, err := tmp.Write(data); err != nil {
|
||||||
|
_ = tmp.Close()
|
||||||
|
return fmt.Errorf("ssh(kerberos): write temp: %w", err)
|
||||||
|
}
|
||||||
|
if err := tmp.Close(); err != nil {
|
||||||
|
return fmt.Errorf("ssh(kerberos): close temp: %w", err)
|
||||||
|
}
|
||||||
|
if err := os.Chmod(tmpPath, mode.Perm()); err != nil {
|
||||||
|
sshLog().Debug("kerberos uploader chmod temp failed", "err", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// 3. scp the temp file to "user@host:cleaned" (cleaned is relative to
|
||||||
|
// $HOME, which scp interprets correctly for a remote login shell).
|
||||||
|
remoteTarget := fmt.Sprintf("%s@%s:%s", u.cfg.User, u.cfg.Host, cleaned)
|
||||||
|
args := append(u.commonSCPArgs(), tmpPath, remoteTarget)
|
||||||
|
if err := u.runCommand(ctx, systemSCPPath, args); err != nil {
|
||||||
|
sshLog().Error("kerberos uploader scp failed",
|
||||||
|
"remote_path", cleaned, "elapsed", time.Since(start), "err", err)
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
sshLog().Info("kerberos uploader done",
|
||||||
|
"remote_path", cleaned, "size", len(data), "total_elapsed", time.Since(start))
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// runRemoteMkdir runs `mkdir -p ~/<dir>` on the remote host via system ssh.
|
||||||
|
func (u *KerberosUploader) runRemoteMkdir(ctx context.Context, dir string) error {
|
||||||
|
remote := fmt.Sprintf("%s@%s", u.cfg.User, u.cfg.Host)
|
||||||
|
// Quote the directory so spaces / metacharacters cannot break the shell
|
||||||
|
// command. dir is already normalised (no leading ~ or /).
|
||||||
|
cmd := "mkdir -p " + shellQuote("./"+dir)
|
||||||
|
args := append(u.commonSSHArgs(), remote, cmd)
|
||||||
|
return u.runCommand(ctx, systemSSHPath, args)
|
||||||
|
}
|
||||||
|
|
||||||
|
// commonSSHArgs builds the shared option set that enables GSSAPI auth and
|
||||||
|
// disables interactive prompts (we want a hard failure, never a hang waiting
|
||||||
|
// for a password the GUI cannot answer).
|
||||||
|
func (u *KerberosUploader) commonSSHArgs() []string {
|
||||||
|
port := u.cfg.Port
|
||||||
|
if port <= 0 {
|
||||||
|
port = 22
|
||||||
|
}
|
||||||
|
timeout := u.cfg.ConnectTimeoutSecs
|
||||||
|
if timeout <= 0 {
|
||||||
|
timeout = 10
|
||||||
|
}
|
||||||
|
args := []string{
|
||||||
|
"-p", strconv.Itoa(port),
|
||||||
|
"-o", "GSSAPIAuthentication=yes",
|
||||||
|
"-o", "GSSAPIDelegateCredentials=no",
|
||||||
|
"-o", "PreferredAuthentications=gssapi-with-mic,gssapi-keyex",
|
||||||
|
"-o", "PubkeyAuthentication=no",
|
||||||
|
"-o", "PasswordAuthentication=no",
|
||||||
|
"-o", "KbdInteractiveAuthentication=no",
|
||||||
|
"-o", "BatchMode=yes",
|
||||||
|
"-o", "ConnectTimeout=" + strconv.Itoa(timeout),
|
||||||
|
}
|
||||||
|
args = append(args, u.hostKeyArgs()...)
|
||||||
|
return args
|
||||||
|
}
|
||||||
|
|
||||||
|
// commonSCPArgs mirrors commonSSHArgs but uses scp's uppercase -P port flag.
|
||||||
|
func (u *KerberosUploader) commonSCPArgs() []string {
|
||||||
|
port := u.cfg.Port
|
||||||
|
if port <= 0 {
|
||||||
|
port = 22
|
||||||
|
}
|
||||||
|
timeout := u.cfg.ConnectTimeoutSecs
|
||||||
|
if timeout <= 0 {
|
||||||
|
timeout = 10
|
||||||
|
}
|
||||||
|
args := []string{
|
||||||
|
"-P", strconv.Itoa(port),
|
||||||
|
"-o", "GSSAPIAuthentication=yes",
|
||||||
|
"-o", "GSSAPIDelegateCredentials=no",
|
||||||
|
"-o", "PreferredAuthentications=gssapi-with-mic,gssapi-keyex",
|
||||||
|
"-o", "PubkeyAuthentication=no",
|
||||||
|
"-o", "PasswordAuthentication=no",
|
||||||
|
"-o", "KbdInteractiveAuthentication=no",
|
||||||
|
"-o", "BatchMode=yes",
|
||||||
|
"-o", "ConnectTimeout=" + strconv.Itoa(timeout),
|
||||||
|
}
|
||||||
|
args = append(args, u.hostKeyArgs()...)
|
||||||
|
return args
|
||||||
|
}
|
||||||
|
|
||||||
|
// hostKeyArgs maps StrictHostKey onto OpenSSH's StrictHostKeyChecking option,
|
||||||
|
// keeping behaviour consistent with the in-process client.
|
||||||
|
func (u *KerberosUploader) hostKeyArgs() []string {
|
||||||
|
if u.cfg.StrictHostKey {
|
||||||
|
if u.cfg.KnownHostsPath != "" {
|
||||||
|
return []string{
|
||||||
|
"-o", "StrictHostKeyChecking=yes",
|
||||||
|
"-o", "UserKnownHostsFile=" + u.cfg.KnownHostsPath,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return []string{"-o", "StrictHostKeyChecking=yes"}
|
||||||
|
}
|
||||||
|
// Non-strict: accept new keys automatically but still record them. This
|
||||||
|
// mirrors the in-process InsecureIgnoreHostKey trade-off the UI warns of.
|
||||||
|
return []string{"-o", "StrictHostKeyChecking=accept-new"}
|
||||||
|
}
|
||||||
|
|
||||||
|
// runCommand executes the given binary, capturing combined stderr so a
|
||||||
|
// failure surfaces the remote/OpenSSH diagnostic instead of a bare exit code.
|
||||||
|
func (u *KerberosUploader) runCommand(ctx context.Context, bin string, args []string) error {
|
||||||
|
cmd := exec.CommandContext(ctx, bin, args...)
|
||||||
|
var stderr bytes.Buffer
|
||||||
|
cmd.Stderr = &stderr
|
||||||
|
sshLog().Debug("kerberos exec", "bin", bin, "args", strings.Join(args, " "))
|
||||||
|
if err := cmd.Run(); err != nil {
|
||||||
|
msg := strings.TrimSpace(stderr.String())
|
||||||
|
if msg == "" {
|
||||||
|
msg = err.Error()
|
||||||
|
}
|
||||||
|
return fmt.Errorf("%s failed: %s", path.Base(bin), msg)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestKerberosConnection probes the remote host with system ssh, surfacing a
|
||||||
|
// clear hint when no valid ticket is present.
|
||||||
|
func TestKerberosConnection(ctx context.Context, cfg domain.SSHConfig) error {
|
||||||
|
sshLog().Info("kerberos test connection start",
|
||||||
|
"host", cfg.Host, "user", cfg.User, "port", cfg.Port)
|
||||||
|
u := &KerberosUploader{cfg: cfg}
|
||||||
|
remote := fmt.Sprintf("%s@%s", cfg.User, cfg.Host)
|
||||||
|
args := append(u.commonSSHArgs(), remote, "true")
|
||||||
|
if err := u.runCommand(ctx, systemSSHPath, args); err != nil {
|
||||||
|
// Detect the most common cause: no/expired Kerberos ticket.
|
||||||
|
if !hasKerberosTicket(ctx) {
|
||||||
|
return fmt.Errorf("no valid Kerberos ticket found — run `kinit %s@BYTEDANCE.COM` first (%w)", cfg.User, err)
|
||||||
|
}
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
sshLog().Info("kerberos test connection ok")
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// hasKerberosTicket reports whether `klist -s` indicates a valid ticket.
|
||||||
|
// `klist -s` exits 0 when a valid TGT exists, non-zero otherwise.
|
||||||
|
func hasKerberosTicket(ctx context.Context) bool {
|
||||||
|
cmd := exec.CommandContext(ctx, "/usr/bin/klist", "-s")
|
||||||
|
return cmd.Run() == nil
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user