SSH config writes are not idempotent, and tests write fixture hosts into the user's real ~/.ssh/config (164 duplicate blocks observed)
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 52/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- python
- Área
- networking, testing
Línea de trabajo
Localiza la ruta de escritura de la configuración SSH y las pruebas que crean el fixture my_cluster; verifica primero qué pruebas pueden acceder a ~/.ssh/config. Se considera completado cuando las escrituras repetidas no crean bloques de host duplicados, las entradas generadas están aisladas de forma segura o se pueden reemplazar, y las pruebas usan una configuración temporal mientras conservan las entradas reales del usuario.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
clustrix appends entries to the user's real ~/.ssh/config without deduplicating, and it writes test-fixture hosts into that personal config. On my machine this accumulated to 164 identical placeholder blocks.
Evidence
Measured on a real user config (macOS, ~/.ssh/config):
total lines: 1202
total Host entries: 172
Frequency by host (real hostnames redacted):
164 Host my_cluster <- test fixture, repeated 164x
1 Host <gpu-host-alias>
1 Host <slurm-host-alias>
1 Host test_cli
1 Host test_cleanup
1 Host <slurm-host-alias-2>
1 Host <slurm-host>
1 Host <slurm-host-alias-3>
1 Host <institution-domain>
Every duplicate block is byte-identical and self-labelled:
# Clustrix auto-generated entry for my_cluster
Host my_cluster
HostName cluster.example.com
User testuser
IdentityFile ~/.ssh/id_ed25519_clustrix_testuser_my_cluster
IdentitiesOnly yes
cluster.example.com / testuser is a test fixture, not a real host. After removing only the my_cluster blocks, the file went from 1202 lines / 172 Host entries to 52 lines / 8 Host entries, with every genuine entry preserved.
Two distinct bugs
- No deduplication on write. Each run appends a new block for a host that already has one. Nothing detects or replaces the existing entry, so the file grows without bound across runs.
- Tests write to the real user config.
my_cluster→cluster.example.com/testuseris fixture data. A test suite should never mutate~/.ssh/config; it should write to a temp file and point SSH at it via-F/ssh_configpath injection.
Impact
- The user's personal SSH config becomes unmanageable (1202 lines of which ~96% is generated noise).
- Real entries get buried among fixtures, making the file hard to audit.
- Functionally the duplicates are inert — OpenSSH takes the first match for a given
Hostpattern — so this is a hygiene and trust problem rather than a broken-connection problem. But it means clustrix silently rewrites a security-relevant file in the user's home directory.
Suggested fixes
- Make config writes idempotent: look for an existing block for the same
Hostalias and replace it in place, rather than appending. - Delimit generated regions with explicit markers (e.g.
# >>> clustrix managed >>>/# <<< clustrix managed <<<) so the tool can rewrite only its own section and users can see what it owns. - Consider writing to a dedicated
~/.ssh/clustrix_configand having users add a singleInclude clustrix_configline, so clustrix never touches the main file. - In the test suite, redirect all SSH-config writes to a
tmp_pathfixture. No test should be able to modify~/.ssh/config. - Optionally ship a
clustrix ssh-config --prunecommand to clean up configs already affected.
Environment
- clustrix installed from source (repo
master) - macOS, OpenSSH client
- Lenguaje dominante
- Python
- Estrellas
- 10
- Forks
- 4
- Merge medio
- 15 h 10 min
- PR fusionados (30 d)
- 2
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ContextLab/clustrix
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
ContextLab/clustrix#170 ·
-
enhancement epic
Dificultad 5/5 Más de una semana Aptitud para principiantes 20/100
ContextLab/clustrix#160 ·
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
ContextLab/clustrix#155 · 1 comentario ·
-
enhancement
Dificultad 5/5 Más de una semana Aptitud para principiantes 42/100
ContextLab/clustrix#151 · 5 comentarios ·
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
ContextLab/clustrix#146 · 2 comentarios ·
Todos los issues de ContextLab/clustrix
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
anthropics/skills#1811 · 1 comentario ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
speaches-ai/speaches#678 ·
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
datalayer/mcp-compose#42 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
conda-forge/spacy-feedstock#177 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
UKGovernmentBEIS/inspect_evals#2523 ·