mirror of
https://github.com/saphid/frame-control.git
synced 2026-10-06 03:00:18 +02:00
Windows: fix ssh config ACL, link-local IPv6, and setup under python -I
- ~/.ssh/config writes swapped in a temp file that inherited the .ssh folder's ACL; Windows' OpenSSH refuses one granting another account (even a deleted one) more than read: "Bad owner or permissions". Writes now give the file an owner-only ACL (frame_host.make_private), and the server repairs a refused config once per run and retries. - frame_link.probe named a link-local IPv6 zone with if_indextoname, which on Windows is "ethernet_32769"; Windows' ssh can't resolve that, so a headset found at fe80:: showed as "can't find the Frame". Use the zone number there. - frame_connect.py imports frame_host (since #60), but the app runs it with python -I, which leaves its folder off sys.path: Set Up Connection exited with ModuleNotFoundError. Add the folder, as server.py does. Verified on a Windows 11 VM against OpenSSH_for_Windows 9.5p2: the old write reproduces the reported error with an orphan SID's Modify ACE; the new write, repair and server retry all leave a config ssh accepts; ssh to %ethernet_32769 fails to resolve while %5 connects. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
a4031db052
commit
07f44f9082
6 files changed
+264
-6
No files matched your search
@@ -278,6 +278,42 @@ def clipboard_text():
|
||||
raise HostError("Can't read the clipboard")
|
||||
|
||||
|
||||
# What Windows' OpenSSH says when it refuses ~/.ssh/config (or a key) for its ACL.
|
||||
BAD_PERMISSIONS = "Bad owner or permissions on "
|
||||
|
||||
|
||||
def make_private(path):
|
||||
"""Leave only this user able to open PATH, as ssh insists for ~/.ssh/config.
|
||||
Windows: an ACL of just this user, SYSTEM and Administrators, inherited nothing.
|
||||
A file written into ~/.ssh otherwise takes the folder's ACL, and Windows' OpenSSH
|
||||
refuses it if that grants anyone else, even an account deleted long ago
|
||||
("Bad owner or permissions"). Best effort: -> False if it couldn't."""
|
||||
if not WINDOWS:
|
||||
try:
|
||||
os.chmod(path, 0o600)
|
||||
return True
|
||||
except OSError:
|
||||
return False
|
||||
me = os.environ.get("USERNAME", "")
|
||||
try: # "desktop\me","S-1-5-21-..."
|
||||
# Bytes: the account name is in the console's code page, the SID is ASCII.
|
||||
out = subprocess.run(["whoami", "/user", "/fo", "csv", "/nh"], capture_output=True,
|
||||
stdin=subprocess.DEVNULL, timeout=10).stdout
|
||||
sid = out.decode("ascii", "replace").strip().rsplit(",", 1)[-1].strip('"')
|
||||
if sid.startswith("S-1-"):
|
||||
me = "*" + sid
|
||||
except (OSError, subprocess.TimeoutExpired):
|
||||
pass
|
||||
if not me:
|
||||
return False
|
||||
try:
|
||||
return subprocess.run(["icacls", str(path), "/inheritance:r", "/grant:r", f"{me}:F",
|
||||
"*S-1-5-18:F", "*S-1-5-32-544:F"], capture_output=True,
|
||||
stdin=subprocess.DEVNULL, timeout=10).returncode == 0
|
||||
except (OSError, subprocess.TimeoutExpired):
|
||||
return False
|
||||
|
||||
|
||||
def ssh_hostname(alias):
|
||||
"""The real host name an ssh alias points at (`ssh -G`), for non-SSH clients like RDP."""
|
||||
try:
|
||||
|
||||
Reference in new issue
Block a user