Documentation
¶
Overview ¶
Package remotessh is WB's single remote-call boundary: it builds the OpenSSH invocation, resolves the local ssh executable, and bounds what a remote response can make WB hold in memory.
Every element of a built argument list is either fixed or comes from validated WB configuration. Caller data never becomes part of the remote command, because OpenSSH joins the remote arguments into one string that the remote login shell then parses; the only safe channel for a request is standard input, which the remote WB entry point reads and validates exactly as it validates its own command line.
Index ¶
Constants ¶
const ( // ExecutableName is the local SSH client WB invokes. ExecutableName = "ssh" // ConnectTimeoutSeconds bounds connection establishment, so an unreachable // host fails in seconds rather than hanging a supervisor. ConnectTimeoutSeconds = 10 // DefaultWBCommand is the remote command name used when a target configures // no exact path. DefaultWBCommand = "wb" // MaxDiagnosticBytes bounds the remote stderr WB is willing to quote back. MaxDiagnosticBytes = 1024 )
Variables ¶
This section is empty.
Functions ¶
func Build ¶
Build returns the argv for one remote WB call. host and user must already have passed the caller's validation; remote is the fixed remote command line, whose first element is the remote wb executable.
func Resolve ¶
Resolve looks up and validates the local ssh executable. A result that is not an absolute, clean, regular, executable file is refused rather than handed to exec, so a PATH entry cannot substitute something else.
func SanitizeDiagnostic ¶
SanitizeDiagnostic renders remote stderr as one bounded, control-character-free line safe to include in a local error message.
Types ¶
type LimitedBuffer ¶
type LimitedBuffer struct {
// contains filtered or unexported fields
}
LimitedBuffer accumulates output up to a byte limit and records whether the limit was reached, so a remote response can never make WB hold unbounded memory and an over-limit response is reported rather than truncated silently.
func NewLimitedBuffer ¶
func NewLimitedBuffer(limit int) *LimitedBuffer
NewLimitedBuffer returns a buffer that accepts up to limit bytes and reports every write as successful, so the writer is never blocked or failed by the bound itself.
func (*LimitedBuffer) Bytes ¶
func (b *LimitedBuffer) Bytes() []byte
Bytes returns what was retained.
func (*LimitedBuffer) Exceeded ¶
func (b *LimitedBuffer) Exceeded() bool
Exceeded reports whether output past the limit was discarded.