Files
FastSync/tests
TapTap f75a69f96a fix(ssh): reject option-injection destinations (C1)
A remote destination's user@host token is passed to ssh in option
position, so a host beginning with '-' (e.g. -oProxyCommand=...) was
parsed by ssh as an option, allowing arbitrary command execution.

- config_parse_ssh_dest now validates the user@host prefix and returns
  -1 (with a clear logged error) for an empty host or a user/host that
  starts with '-'; config_parse_transport_dest propagates the failure.
- transport_ssh.c's parse_remote_dest applies the same validation as
  defense-in-depth, and ssh_build_client_argv inserts a '--'
  end-of-options marker before the destination token.
- Unit tests cover -oProxyCommand=... / -prefixed hosts / empty host
  rejection and the argv shape.
2026-09-14 16:08:56 +02:00
..
2026-06-10 16:58:35 +02:00
2026-06-10 16:58:35 +02:00
2026-06-10 16:58:35 +02:00
2026-08-16 09:37:28 +02:00
2026-06-10 16:58:35 +02:00
2026-06-10 16:58:35 +02:00
2026-08-16 09:37:28 +02:00