Files
OpenShell/docs/about
Oliver Calder 994750e3a1 feat(snap): vendor ssh in openshell snap and remove ssh-keys interface (#2280)
Previously, the openshell snap used the ssh-keys interface to get access
to the host's ssh binary, which is used for sandbox connect/exec/forward.
However, ssh-keys is a privileged interface which also grants access to
the public and private ssh keys on the host. As such, it required manual
connection in order to be used.

This weakened the security sandbox of the snap, and hurt the UX of
installing it.

This commit changes this by removing the `ssh-keys` interface and
instead vendoring the `ssh` binary within the snap.

This is safe because OpenShell always invokes the `ssh` binary with
`StrictHostKeyChecking=no`, `UserKnownHostsFile=/dev/null`, and
`GlobalKnownHostsFile=/dev/null`, and never uses any host credentials or
ssh configuration. Openshell only ever access to `~/.ssh/config` to
write OpenShell-managed aliases, and this can safely live within the
snap sandbox, rather than leaking into the host environment.

Signed-off-by: Oliver Calder <oliver.calder@canonical.com>
2026-07-15 03:05:33 +00:00
..