Repository navigation
fix: survive the host's ssh agent and the bar's PATH - #140
Draft
jzetterman wants to merge 2 commits into
Draft
jzetterman wants to merge 2 commits into
jzetterman wants to merge 2 commits into
Conversation
ssh offers agent-held keys before on-disk ones no matter what order they appear in, and IdentitiesOnly only limits which keys may be offered, not the order they are tried. So on a machine whose ssh_config pins an agent-held key for the Mac, `ssh -i blip_ed25519` never gets to offer the dedicated key. Two consequences, and the second one is the reason this is a fix and not a tidy-up: blip-setup's confinement check reads the resulting normal shell as "not confined" and aborts with "dedicated key did not confine as expected", pointing the user at a Mac whose authorized_keys is already correct. blip-shim hits the same thing at runtime. The forced command lives on the dedicated key's authorized_keys line, so authenticating with the other key silently bypasses it and the bridge runs with a full shell instead of blip-dispatch. The confinement SECURITY.md describes stops applying, with nothing visible to say so. blip-bridged, added upstream since, builds the same ssh command for its `imsg serve` channel and has the same hole. Pass IdentityAgent=none in all three, which costs nothing because the dedicated key is read from disk and never lives in an agent. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NPZgnvM2YpZjvkeZuismQP Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XNiq5jKqtnDCZpmotePMPf
Quickshell inherits the graphical session environment, which never sources a shell rc. A bun installed by bun's own script into ~/.bun/bin is therefore on the user's interactive PATH and absent from the bar's, so blip-setup's prerequisite check passes while every widget action fails to start. That failure is near silent. A process that cannot start returns no useful status, so the icon falls back to "Mac unreachable" and blames the Mac. The bridge, the key, and the Mac permissions can all be perfect. Check bun a second time against the PATH the bar will actually use, read from a running quickshell when there is one and from the systemd user environment otherwise. On a mismatch, print the ready-made ln command, choosing a link directory already on that PATH. Also correct the widget's own message, which said to install bun with pacman. Bun was installed every time this fired, so that advice sent people the wrong way. Recommend a symlink over a second install, since two copies are free to drift to different versions. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NPZgnvM2YpZjvkeZuismQP
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Two fixes for hosts whose own setup gets in Blip's way.
-o IdentityAgent=none. That coversblip-shim, the confinement check inblip-setup, and theimsg servechannel inblip-bridged.blip-setupnow checks thatbunis on the PATH the bar sees, not only on the PATH of the shell that runs setup. If it isn't, setup stops and prints the symlink that fixes it. The bar's "cannot startbun" error now names the same cause.Why
The agent wins over
-i. ssh offers keys held in an agent before keys read from disk, whatever the order in the config.IdentitiesOnly=yeslimits which keys ssh may offer. It does not change that order. So if the user'sssh_confignames an agent-held key for the Mac, that key authenticates first, andblip_ed25519is never offered. I hit this on my own machine:blip-setupgets a normal shell back, decides the key is not confined, and aborts with "dedicated key did not confine as expected". The Mac'sauthorized_keyswas correct the whole time.blip-bridgedhit the same thing, and nothing tells you. The forced command lives on the dedicated key's line, so a session that logs in with the everyday key skipsblip-dispatchand runs the bridge with a full shell. The confinement from SECURITY.md finding blip-check: probe every Contacts source, not just glob()[0] #2 no longer applies.The dedicated key is always read from disk and never lives in an agent, so turning the agent off for these calls costs nothing.
bun on the wrong PATH. Quickshell inherits the graphical session's environment, which never reads
~/.zshrcor~/.bashrc. bun's own installer puts bun in~/.bun/binand adds it to the shell rc. So setup passes, and every widget action then fails to start. The icon says the Mac is unreachable over a bridge that works fine. Setup readsPATHfrom the running Quickshell process, or fromsystemctl --user show-environmentwhen the bar isn't running, and checks for bun there.How it was verified
bun testis green: 750 tests, 0 failures, run locallyci.ymlpasses locally (21 files), as does CI'sshellcheck -S warningcommandtest_the_dedicated_key_channel_refuses_agent_keysinbridge/linux/test_bridged.py. It failed before theblip-bridgedchange and passes after. All 37blip-bridgedtests pass.Invariants touched: the dedicated-key confinement in docs/SECURITY.md finding #2. The rule itself doesn't change. These fixes make the code keep it on hosts that run an ssh agent.
🤖 Generated with Claude Code
https://claude.ai/code/session_01XNiq5jKqtnDCZpmotePMPf