Expand description
SSH direct-tunnel transport (russh port of the legacy tunnel runtime).
Topology per connection: mysql_async always connects to a LOCAL
loopback endpoint; every local TCP connection is bridged onto a fresh
direct_tcpip channel of ONE multiplexed SSH session to the bastion,
which forwards to the MySQL host/port as seen FROM the bastion.
Host keys are verified against known_hosts through the strict/lenient
policy engine — mismatches and revoked keys are rejected in every
mode; only genuinely unknown hosts may be accepted under lenient.
Hardening (#4A): concurrent first users of the same tunnel coalesce on ONE establishment; every tunnel carries a monotonic GENERATION that also keys the MySQL pool, so a reused loopback port can never splice an old pool onto a new transport (ABA); retirement follows a fixed order (drain → evict pools → stop listener → wind down channel tasks → disconnect the session); the cache is LRU and bounded; keepalive is tunable for half-open detection; the tunnel cache key binds the config revision, the SSH credential generation, and the known_hosts content, so rotating any of them invalidates the cached session. Test-mode rules apply to the bastion endpoint before any socket is opened.
Structs§
- Tunnel
Lease - A lease on a tunnel: the loopback endpoint for
mysql_asyncplus the transport GENERATION. The generation participates in the MySQL pool key, so a pool can never outlive its tunnel and get spliced onto a later transport that reuses the same ephemeral port.
Enums§
Constants§
- CHANNEL_
OPEN_ TIMEOUT - Deadline for opening a single forwarded channel (a stale/half-open session must fail the local connection promptly, not hang it).
- MAX_
TUNNELS - Maximum distinct tunnels kept in the process-wide cache (LRU).
- SSH_
CONNECT_ TIMEOUT - Deadline for establishing the SSH session (connect + KEX + auth).
Functions§
- invalidate_
all - Drop every cached tunnel and retire each one in order (tests).
- keepalive_
interval - Keepalive interval. Default 30 s; tunable (1..=300) via
SEQUEL_MCP_SSH_KEEPALIVE_SECS— an operational knob that also lets the half-open tests run with a realistic detection budget. - tunnel_
connection_ names - Connection-name fragments of the live tunnel keys (LRU tests).
- tunnel_
count - Number of live tunnels (diagnostics/tests).
- tunnel_
endpoint - Return a lease on a (reused or freshly established) SSH tunnel for
conn_name’s SSH config, forwarding totarget_host:target_portas reachable from the bastion. Concurrent first callers coalesce on one establishment. The lease’s generation MUST be carried into the MySQL pool key (verified_pool(.., tunnel_generation)). - tunnel_
live_ tasks - Live forwarder tasks across all tunnels (drain assertions).