Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update relevant channel request callbacks to return a bool #348

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

belak
Copy link
Contributor

@belak belak commented Sep 19, 2024

This is a breaking change (as it changes a trait), but it tweaks channel request callbacks to return a bool rather than requiring the user to manually call session.channel_success or session.channel_failure. Also, IIRC, the protocol docs specify that the request channel should continue to be serviced even when a session is started, so it makes sense to require users to spin off a background task and return the status.

Alternatively this could be done as a non-breaking change by making the server implementation call session.channel_failure after a channel request is handled.

I do understand there are valid reasons to deny this, but it seemed like an easy place for a user to make a mistake, and I wanted to see how hard this would be to change.

This has the added advantage of changing the defaults of a number of request callbacks to more-secure defaults (deny), and makes it impossible for a user to miss responding to callbacks which require responses. Even if this PR is not accepted, that change should probably be implemented - I would be happy to submit that separately if you'd prefer.

Note that this does not handle sending responses for all requests, only channel requests listed in RFC4254 as having a "want reply" param rather than just "false", even though it may be more correct to respond to malformed requests which have improperly set that byte to "true" even though the RFC specifies "false".

EDIT: with the combination of the channel message stream and the handlers, this should continue to work as expected, at least with sftp, but that's only because it uses .into_stream() which only handles data and doesn't require a reply. I'm not certain the "correct" way to handle this - the channel is definitely useful because it allows you to get an impl AsyncRead / impl AsyncWrite, but it definitely complicates this.

If you have any advice I'd love to hear it.

This is a breaking change, but it tweaks channel request callbacks to
return a bool rather than requiring the user to manually call
`session.channel_success` or `session.channel_failure`.

This has the added advantage of changing the defaults of a number of
request callbacks to more-secure defaults (deny), and makes it
impossible for a user to miss responding to callbacks which require
responses.

Note that this does *not* handle sending responses for all requests,
only channel requests listed in RFC4254 as having a "want reply" param
rather than just "false", even though it may be more correct to respond
to malformed requests which have improperly set that byte to "true" even
though the RFC specifies "false".
@belak belak force-pushed the belak/simpler-channel-replies branch from 4242b34 to 144f58a Compare September 19, 2024 15:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant