Skip to main content

Module ssh

Module ssh 

Source
Expand description

SSH direct-tunnel transport (russh port of the legacy tunnel runtime).

Topology per connection: mysql_async always connects to a LOCAL loopback endpoint; every local TCP connection is bridged onto a fresh direct_tcpip channel of ONE multiplexed SSH session to the bastion, which forwards to the MySQL host/port as seen FROM the bastion. Host keys are verified against known_hosts through the strict/lenient policy engine — mismatches and revoked keys are rejected in every mode; only genuinely unknown hosts may be accepted under lenient.

Hardening (#4A): concurrent first users of the same tunnel coalesce on ONE establishment; every tunnel carries a monotonic GENERATION that also keys the MySQL pool, so a reused loopback port can never splice an old pool onto a new transport (ABA); retirement follows a fixed order (drain → evict pools → stop listener → wind down channel tasks → disconnect the session); the cache is LRU and bounded; keepalive is tunable for half-open detection; the tunnel cache key binds the config revision, the SSH credential generation, and the known_hosts content, so rotating any of them invalidates the cached session. Test-mode rules apply to the bastion endpoint before any socket is opened.

Structs§

TunnelLease
A lease on a tunnel: the loopback endpoint for mysql_async plus the transport GENERATION. The generation participates in the MySQL pool key, so a pool can never outlive its tunnel and get spliced onto a later transport that reuses the same ephemeral port.

Enums§

SshError

Constants§

CHANNEL_OPEN_TIMEOUT
Deadline for opening a single forwarded channel (a stale/half-open session must fail the local connection promptly, not hang it).
MAX_TUNNELS
Maximum distinct tunnels kept in the process-wide cache (LRU).
SSH_CONNECT_TIMEOUT
Deadline for establishing the SSH session (connect + KEX + auth).

Functions§

invalidate_all
Drop every cached tunnel and retire each one in order (tests).
keepalive_interval
Keepalive interval. Default 30 s; tunable (1..=300) via SEQUEL_MCP_SSH_KEEPALIVE_SECS — an operational knob that also lets the half-open tests run with a realistic detection budget.
tunnel_connection_names
Connection-name fragments of the live tunnel keys (LRU tests).
tunnel_count
Number of live tunnels (diagnostics/tests).
tunnel_endpoint
Return a lease on a (reused or freshly established) SSH tunnel for conn_name’s SSH config, forwarding to target_host:target_port as reachable from the bastion. Concurrent first callers coalesce on one establishment. The lease’s generation MUST be carried into the MySQL pool key (verified_pool(.., tunnel_generation)).
tunnel_live_tasks
Live forwarder tasks across all tunnels (drain assertions).