| Commit message (Collapse) | Author | Age | Files | Lines | |
|---|---|---|---|---|---|
| * | oxish: change --generate-host-key to produce OpenSSH formatsync-hostkey-format | Hee-Suk Kim | 7 days | 1 | -4/+4 |
| | | | | | | | | | | | | | | | | Since --host-key-file now accepts OpenSSH keys, write the generated key in the same format instead of PKCS#8. This was tested locally by rm ssh_host_ed25519_key && ./target/debug/oxish-server --generate-host-key && chmod 0600 ssh_host_ed25519_key && ssh-keygen -y -f ssh_host_ed25519_key for all four paths (aws-lc, graviola) x (ssh-ed25519, ecdsa-sha2-nistp256). | ||||
| * | proto: implement openssh::encode() | Hee-Suk Kim | 7 days | 3 | -1/+94 |
| | | |||||
| * | proto: add private_key() method on SigningKey trait | Hee-Suk Kim | 7 days | 5 | -1/+41 |
| | | | | | | | | | | | | | | | | This is needed to encode the OpenSSH private key format from the SigningKey returned by generate_signing_key(). Otherwise, we would have to re-parse the PKCS#8 DER (which was already encoded when generating the key) and extract the private key from there. private_key() is currently used only in the --generate path, so not all backends necessarily need to implement it. So it has a default implementation that fails with Unspecified. Also, Curve25519SeedBin and EcPrivateKeyBin from aws-lc-rs need no extra Zeroizing wrapper, since the underlying Buffer zeroizes on drop (verified against aws-lc-rs 1.18.0). | ||||
| * | oxish: change --host-key-file to accept OpenSSH v1 format | Hee-Suk Kim | 7 days | 1 | -5/+4 |
| | | | | | | | Previously, PKCS#8 was expected for --host-key-file. This caused confusion as it contradicted the original /etc/ssh route, which expects OpenSSH v1 format. | ||||
| * | proto: add HostKeys::from_openssh_v1() | Hee-Suk Kim | 7 days | 1 | -0/+8 |
| | | |||||
| * | docs(readme): remove no-publicizing lineHEADmain | Arhan Chaudhary | 13 days | 1 | -2/+0 |
| | | |||||
| * | Add Discord badge to README | Dirkjan Ochtman | 13 days | 1 | -0/+1 |
| | | |||||
| * | oxish: make sure the session does not inherit the socket0.1.0 | Dirkjan Ochtman | 13 days | 1 | -1/+7 |
| | | |||||
| * | Handle global requests | Dirkjan Ochtman | 13 days | 2 | -1/+47 |
| | | |||||
| * | oxish: log which user store is in use | Dirkjan Ochtman | 13 days | 1 | -1/+5 |
| | | |||||
| * | oxish: reset process session | Dirkjan Ochtman | 13 days | 1 | -0/+4 |
| | | |||||
| * | proto: add unknown channel request type | Dirkjan Ochtman | 13 days | 2 | -13/+12 |
| | | |||||
| * | proto: add specific error for invalid channel types | Dirkjan Ochtman | 13 days | 2 | -6/+13 |
| | | |||||
| * | Reject auth agent channel requests | Dirkjan Ochtman | 13 days | 2 | -0/+12 |
| | | |||||
| * | Bump versions to 0.1.0 | Dirkjan Ochtman | 13 days | 5 | -13/+13 |
| | | |||||
| * | oxish: provide context when host key cannot be found | Dirkjan Ochtman | 13 days | 1 | -1/+5 |
| | | |||||
| * | proto: parse OpenSSH host key files when available | Dirkjan Ochtman | 13 days | 6 | -7/+482 |
| | | |||||
| * | proto: split out host_keys module | Dirkjan Ochtman | 13 days | 8 | -115/+120 |
| | | |||||
| * | oxish: use named type for key exchange output | Dirkjan Ochtman | 13 days | 4 | -44/+56 |
| | | |||||
| * | Show warning after non-PQ key exchange | Dirkjan Ochtman | 13 days | 7 | -8/+208 |
| | | |||||
| * | Add back curve25519-sha256 key exchange algorithm | Dirkjan Ochtman | 13 days | 5 | -6/+129 |
| | | |||||
| * | build(deps): bump clap from 4.6.4 to 4.6.6 | dependabot[bot] | 2026-08-10 | 1 | -4/+4 |
| | | | | | | | | | | | | | | | | | Bumps [clap](https://github.com/clap-rs/clap) from 4.6.4 to 4.6.6. - [Release notes](https://github.com/clap-rs/clap/releases) - [Changelog](https://github.com/clap-rs/clap/blob/master/CHANGELOG.md) - [Commits](https://github.com/clap-rs/clap/compare/clap_complete-v4.6.4...clap_complete-v4.6.6) --- updated-dependencies: - dependency-name: clap dependency-version: 4.6.6 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> | ||||
| * | build(deps): bump data-encoding from 2.10.0 to 2.11.1 | dependabot[bot] | 2026-08-10 | 1 | -2/+2 |
| | | | | | | | | | | | | | | | Bumps [data-encoding](https://github.com/ia0/data-encoding) from 2.10.0 to 2.11.1. - [Commits](https://github.com/ia0/data-encoding/compare/v2.10.0...v2.11.1) --- updated-dependencies: - dependency-name: data-encoding dependency-version: 2.11.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> | ||||
| * | oxish: extract AuthenticationState | Dirkjan Ochtman | 2026-08-09 | 4 | -170/+231 |
| | | |||||
| * | Use more fine-grained errors for authentication | Dirkjan Ochtman | 2026-08-09 | 3 | -23/+42 |
| | | |||||
| * | oxish: fix warnings in release profiles | Dirkjan Ochtman | 2026-08-03 | 1 | -1/+4 |
| | | |||||
| * | Setup release workflow with dist0.1.0-rc.1 | Dirkjan Ochtman | 2026-08-03 | 3 | -0/+317 |
| | | |||||
| * | ci: enable cargo-semver-checks | Dirkjan Ochtman | 2026-08-03 | 1 | -0/+7 |
| | | |||||
| * | Extend Cargo metadata | Dirkjan Ochtman | 2026-08-03 | 4 | -1/+16 |
| | | |||||
| * | Bump versions to 0.1.0-rc.1 | Dirkjan Ochtman | 2026-08-03 | 5 | -13/+13 |
| | | |||||
| * | tests: tweak output | Dirkjan Ochtman | 2026-08-01 | 1 | -4/+4 |
| | | |||||
| * | tests: make handshake() fallible | Dirkjan Ochtman | 2026-08-01 | 1 | -10/+18 |
| | | |||||
| * | tests: make session_binary() fallible | Dirkjan Ochtman | 2026-08-01 | 1 | -5/+5 |
| | | |||||
| * | tests: restore test for no-spawn server | Dirkjan Ochtman | 2026-08-01 | 1 | -10/+37 |
| | | |||||
| * | tests: split rekey test out from handshake() | Dirkjan Ochtman | 2026-08-01 | 1 | -46/+34 |
| | | |||||
| * | tests: extract setup() helper | Dirkjan Ochtman | 2026-08-01 | 1 | -30/+37 |
| | | |||||
| * | tests: extract CliClient type | Dirkjan Ochtman | 2026-08-01 | 1 | -75/+99 |
| | | |||||
| * | tests: extract helper function for building the user store | Dirkjan Ochtman | 2026-08-01 | 1 | -39/+46 |
| | | |||||
| * | oxish: guard against pw_name being null | Dirkjan Ochtman | 2026-08-01 | 1 | -4/+4 |
| | | |||||
| * | Warn on clippy::undocumented_unsafe_blocks | Dirkjan Ochtman | 2026-08-01 | 3 | -0/+18 |
| | | |||||
| * | oxish: guard against null pw_dir and pw_shell values | Dirkjan Ochtman | 2026-08-01 | 1 | -3/+12 |
| | | |||||
| * | oxish: handle ERANGE from getpw calls | Dirkjan Ochtman | 2026-08-01 | 1 | -23/+40 |
| | | |||||
| * | oxish: replace custom open_dir_dir() with rustix openat() | Dirkjan Ochtman | 2026-08-01 | 1 | -17/+19 |
| | | |||||
| * | oxish: minimize pre_exec() operations in Terminal::spawn() | Dirkjan Ochtman | 2026-08-01 | 1 | -24/+18 |
| | | |||||
| * | oxish: drop logging from within pre_exec() context | Dirkjan Ochtman | 2026-08-01 | 1 | -3/+3 |
| | | |||||
| * | oxish: attach authorized_keys() to User | Dirkjan Ochtman | 2026-07-30 | 1 | -76/+77 |
| | | |||||
| * | oxish: add test for parsing fake keys | Dirkjan Ochtman | 2026-07-30 | 1 | -0/+12 |
| | | |||||
| * | proto: warn on unsafe_code | Dirkjan Ochtman | 2026-07-30 | 1 | -1/+1 |
| | | |||||
| * | Move AuthorizedKey into proto | Dirkjan Ochtman | 2026-07-30 | 6 | -167/+166 |
| | | |||||
| * | proto: isolate authentication signature encoding | Dirkjan Ochtman | 2026-07-30 | 2 | -57/+76 |
| | | |||||
