Repository navigation
test(security): SshTunnelManager suite with an in-memory SSH fake - #1097
Merged
Merged
Conversation
) Make the tunnel's TCP connector and SSH client builder injectable and cover loopback binding, ephemeral ports, byte forwarding, password / private-key / passphrase / jump-host authentication, secret scrubbing, host-key pinning, ref-counting, dropped-connection replacement, keep-alive and shutdown. Fixes found on the way: credentials passed for a reused tunnel were not cleared, a replaced session left its loopback listener open, handles of a replaced session could release the session that took its place, and app shutdown did not close open tunnels.
…test-hang' into issue/1041-ssh-tunnel-manager-tests
…test-hang' into issue/1041-ssh-tunnel-manager-tests
2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A test suite for
SshTunnelManager(#1031) that needs no SSH server, plus four fixes that writing it exposed.Test seam.
SshTunnelManagernow takes its TCP connector and SSH client builder as injectable functions (SshTunnelManager.forTesting, default behavior unchanged).test/support/fake_ssh.dartprovides an in-memory server and client: it presents a host key, checks host-key trust, then password or public-key authentication, counts keep-alive pings, and echoes forwarded connections. Only the tunnel's own loopback listener is a real socket.ssh_tunnel_manager_test.dart127.0.0.1, is not reachable through any non-loopback local IPv4 address, each target gets its own free port, bytes written to the local port reach the remote target and come back.SshAuthenticationException, client closed), unreachable bastion, jump host (dialed first, bastion reached through it, jump password with fallback to the main password), Ed25519 and RSA keys, passphrase-protected keys, wrong passphrase, garbage key, key read fromprivateKeyPath, server rejecting the key. Keys are generated withssh-keygenat test time (no private keys in the repo); those tests skip when it is unavailable.formatFingerprintis the SHA-256 hex digest, a pinned fingerprint matches (also colon-separated and upper-case), a changed key raisesSshHostKeyMismatchExceptionbefore any password is sent and closes the client (and the jump host client), no pin means first-use trust.testSshConnection: disabled, empty host / user, success with fingerprint and closed client, bad credentials.release, separate sessions per target, a dropped SSH connection is replaced,closeAll, release aftercloseAll, app shutdown, keep-alive pings start and stop (and a zero interval disables them).Fixes in the manager
disconnectAllExternalServices(app shutdown / lifecycle cleanup) never closed SSH tunnels; it now callsSshTunnelManager.instance.closeAll()after disconnecting the services.Notes
Closes #1041