From 318bc3b84fbeac07a058ff384aee5fba6cacb732 Mon Sep 17 00:00:00 2001 From: saphid <4596216+saphid@users.noreply.github.com> Date: Mon, 28 Sep 2026 21:49:43 +1000 Subject: [PATCH] Devices: make the pin folder before ssh saves a first-seen key into it Co-Authored-By: Claude Opus 5.5 (1M context) --- tests/test_link.py | 1 + ui/frame_link.py | 5 ++++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/tests/test_link.py b/tests/test_link.py index a5265f3..d0f9185 100644 --- a/tests/test_link.py +++ b/tests/test_link.py @@ -155,6 +155,7 @@ class Connecting(unittest.TestCase): self.assertIn(f"Port={self.port}", opts) master = [c for c in self.calls() if "ControlMaster=yes" in c][-1] self.assertIn("StrictHostKeyChecking=accept-new", master) # first connection: nothing pinned yet + self.assertTrue(fd.known_hosts(d["id"]).parent.is_dir()) # where ssh saves the key it accepts # It learned: localhost works on this network. learned = {a["host"]: a for a in self.reg.get(d["id"])["addresses"]} self.assertEqual(learned["localhost"]["networks"], ["n-test"]) diff --git a/ui/frame_link.py b/ui/frame_link.py index 7359abe..cdb5ac9 100644 --- a/ui/frame_link.py +++ b/ui/frame_link.py @@ -666,8 +666,11 @@ class Link: extra = ["-o", "StrictHostKeyChecking=yes"] else: # First connection since this headset was added: trust what it shows - # (as Set Up Connection does), and pin it from now on. + # (as Set Up Connection does), and pin it from now on. ssh won't create + # the folder its known_hosts file goes in. extra = ["-o", "StrictHostKeyChecking=accept-new"] + pins = frame_devices.known_hosts(device["id"]).parent + pins.mkdir(**({} if frame_host.WINDOWS else {"mode": 0o700}), parents=True, exist_ok=True) if self.control: # No ConnectTimeout: with it, OpenSSH's master takes ~5s to open its socket. argv = [*self.mux_base, *opts, *extra, "-v", "-o", "ControlMaster=yes", "-o", "ServerAliveInterval=5",