Make the host ~/.ssh mount opt-in (SQUAREBOX_MOUNT_SSH) - #176
Merged
Merged
Conversation
Without an SSH agent, install.sh mounted the host's whole ~/.ssh directory, private keys included, read-only into the Box. Native PowerShell always mounted it when present. AI assistants can run unattended in the Box, so neither adapter mounts the directory by default any more. - Bash agent forwarding, with its read-only config/known_hosts mounts, is unchanged. - SQUAREBOX_MOUNT_SSH=1 (both adapters) or -MountSsh (PowerShell) restores the read-only directory mount when no agent is forwarded. 0 turns it off. Any other value fails with exit 64 before any lifecycle mutation. - Without an agent or the opt-in, install prints how to enable the mount or use an agent. - The choice is persisted as MOUNT_SSH in the Install identity, which ADR 0007 requires to be a new format. Writers emit FORMAT=2. All four readers and the Windows migration script also accept FORMAT=1 without MOUNT_SSH, read it as 0, and republish it as FORMAT=2. ADR 0010 records the decision. - Schema, verifier, and shared fixtures cover both formats. The lifecycle test asserts the default has no .ssh directory mount, the opt-in adds the mount and survives a rebuild, an agent still wins, =0 opts out, invalid values are rejected, and FORMAT=1 is upgraded. - SECURITY.md, README, CLAUDE.md, CONTEXT.md, the UAT checklist, and the v1.3.0 migration guide are updated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # docs/releases/v1.3.0.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
AI assistants can run unattended inside the Box (the
*-yoloaliases), so the Box no longer gets your SSH private-key files by default.config/known_hosts~/.sshmounted read-only.sshexists.sshalways mounted read-onlyHow to opt in: set
SQUAREBOX_MOUNT_SSH=1(works on both adapters) or pass.\install.ps1 -MountSsh. SettingSQUAREBOX_MOUNT_SSH=0or passing-MountSsh:$falseturns it back off. Any other value fails with exit 64 before anything is changed. An available agent still takes priority over the opt-in.Install identity schema: FORMAT 2
The choice is saved as
MOUNT_SSH=0|1ininstall-state, so later rebuilds reuse it. ADR 0007 says adding a field requires a new format, so this PR introducesFORMAT=2in a backward-compatible way:install.sh,install.ps1) emitFORMAT=2, withMOUNT_SSHappended afterHOME_VOLUME_ADOPTED.install.sh,uninstall.sh,install.ps1,uninstall.ps1) andmigrate-windows-adapter.ps1accept two formats:FORMAT=2, whereMOUNT_SSHis required.FORMAT=1, whereMOUNT_SSHmust be absent and is read as0.FORMAT=1file asFORMAT=2.install-state-schema.jsongains"format": 2andreadable_formats, and theknown-formats-onlyrule replacesformat-1-only. The verifier now also checks the format and flag handling in each adapter.Trade-off: releases before v1.3 reject
FORMAT=2state (fail closed). An optional field inside format 1 would have had the same effect, because old readers also reject unknown fields.Tests
tests/fixtures/install-state-cases.json: 10 new cases, run against both the Bash and PowerShell adapters (27 total). They cover:FORMAT=1withoutMOUNT_SSHaccepted, with LF and with CRLF line endingsFORMAT=1withMOUNT_SSHrejectedFORMAT=2missingMOUNT_SSHrejectedFORMAT=3andFORMAT=0rejectedtests/test-lifecycle-install-state.sh: a new block checks the runtime calls recorded by the mock:.sshdirectory mount, prints the note, and writesMOUNT_SSH=0.MOUNT_SSH=1, and a plain rebuild keeps it.configandknown_hostsare mounted but not the directory.=0turns the opt-in off.FORMAT=1file is upgraded on rebuild, anduninstall.shacceptsFORMAT=1.tests/test-lifecycle-powershell.ps1: new source-contract checks for:The migration test now starts from a
FORMAT=1file and checks it is published asFORMAT=2withMOUNT_SSH=0.Results: the full host suite passed 19/19 both with and without
pwsh(PowerShell 7.6.6 for the native run).Docs
uat-checklist.mddocs/releases/v1.3.0.md: migration note covering the behavior change on the next rebuild and how to keep the old behaviorCHANGELOG.md is intentionally untouched.
🤖 Generated with Claude Code