Conversation
added 7 commits
September 25, 2026 03:00
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



IncludeandMatchfor OpenSSH config filesThis teaches
OpenSSHConfigtwo directives that most real~/.ssh/configfiles use today and that JSch silently ignored:
Include, which pulls infurther files, and
Match, which applies settings conditionally. The goalis that an application can load the same config an administrator maintains
for OpenSSH, including the split-out files under
~/.ssh/config.d/, and getthe same hosts, users and keys OpenSSH would.
Include
names live under
~/.ssh,~and~/expand to the current user's home,and globs are expanded per path segment, so
config.d/*/*.confworks.includes itself, directly or through another file, is rejected with an
error naming the file.
Includeinside aHostorMatchblock applies only within thatblock; one at top level applies globally.
Host,MatchorIncludewithout an argument is an errorinstead of silently continuing the previous block.
Match
all,host,originalhost,userandlocaluser, withOpenSSH's comma-separated pattern lists and
!negation, for exampleMatch host *.internal,!test.internal.Matchcondition is evaluated once per lookup, against the valuesknown at that point, so a later
HostNameorUserinside an includedfile cannot flip a decision that was already taken. This is what OpenSSH
does and it keeps evaluation order predictable.
exec, fail closed: the config isrejected with an error naming the criterion rather than being applied
with a block silently skipped or silently matched.
ConfigRepositorygains agetConfig(host, user)overload, with adefault that delegates to the old method, so
Match usercan see theusername the application passed to
getSession.Comments
Trailing comments are handled the way OpenSSH handles them: an unquoted
#that starts a word ends the value, soPort 2222 # bastiongives 2222,while
h#1and quoted text stay intact. Previously such a line silentlylost its value.
Session
A
Sessionresolves its config once, when it is created, and reuses thatresult for channels and port forwardings. Before, a second evaluation at
channel time could see a different
UserorHostNameand, for example,enable
ForwardAgentfor a channel although the session had not beenconfigured with it.
Security notes
Includereads files, so config text should come from a trusted source.JSch does not enforce OpenSSH's owner and mode checks on included files,
because embedded applications often manage config on filesystems without
POSIX permissions; the Javadoc says so and leaves the trust policy to the
caller.
Matchcriteria fail closed rather than open.Testing
recursion limits, pattern lists and negation, evaluation order across
included files, unsupported criteria, comment handling and the session's
reuse of its resolved config.
ssh -F <config> -G,and live against sshd chains whose
ProxyJumpandIdentityFilesettings come from included files and
Matchblocks.Notes for reviewers
Matchcriteria(
canonical,final,tagged,localnetwork,version), OpenSSH'spercent tokens and
${ENV}in paths, and file-and-line locations inparse errors.
ProxyJumpPR touches the same two files at unrelated places; themerge conflict between them is a Javadoc list line and a block of fields.
Development