fix(agent): create SSH server configuration per connection (#2451)

This commit is contained in:
user01010111
2026-09-29 12:22:48 +13:00
committed by GitHub
parent 921ded1af0
commit 130365f5d3
2 changed files with 125 additions and 11 deletions

View File

@@ -57,21 +57,11 @@ func (a *Agent) StartServer(opts ServerOptions) error {
}
defer ln.Close()
// base config (limit to allowed algorithms)
config := &gossh.ServerConfig{
ServerVersion: fmt.Sprintf("SSH-2.0-%s_%s", beszel.AppName, beszel.Version),
}
config.KeyExchanges = common.DefaultKeyExchanges
config.MACs = common.DefaultMACs
config.Ciphers = common.DefaultCiphers
// set default handler
ssh.Handle(a.handleSession)
a.server = &ssh.Server{
ServerConfigCallback: func(ctx ssh.Context) *gossh.ServerConfig {
return config
},
ServerConfigCallback: newSSHServerConfig,
// check public key(s)
PublicKeyHandler: func(ctx ssh.Context, key ssh.PublicKey) bool {
remoteAddr := ctx.RemoteAddr()
@@ -96,6 +86,19 @@ func (a *Agent) StartServer(opts ServerOptions) error {
return a.server.Serve(ln)
}
// newSSHServerConfig returns a separate config for each connection because
// gliderlabs adds host keys and connection-specific callbacks to it.
func newSSHServerConfig(ssh.Context) *gossh.ServerConfig {
return &gossh.ServerConfig{
Config: gossh.Config{
KeyExchanges: common.DefaultKeyExchanges,
MACs: common.DefaultMACs,
Ciphers: common.DefaultCiphers,
},
ServerVersion: fmt.Sprintf("SSH-2.0-%s_%s", beszel.AppName, beszel.Version),
}
}
// getHubVersion extracts the hub version from the SSH client version string
// for a given session. Returns a zero version if parsing fails.
func (a *Agent) getHubVersion(sessionCtx ssh.Context) semver.Version {