A removed SSH key keeps working on connections that were already open.
Authentication caches the key ID and scope in the connection's permissions. runExec (internal/sshd/sshd.go:299) reloads the user per exec but never the key; TouchSSHKey's result is ignored. With the CLI's ControlMaster, a connection carrying many sessions is the normal case, so a compromised key stays usable after keys remove for as long as its holder keeps the connection open.
Decision: revocation is immediate.
- Revalidate key existence, owner and current scope before every exec and every git transport session.
- sshd tracks open connections per key.
keys remove,repo deploy-key removeand account disable close every connection on the affected keys, cancelling running commands, pushes included. An interrupted receive-pack updates no refs. - An e2e test: open a multiplexed connection, remove the key, confirm the next exec is refused and a long-running command is cut off.
referenced in commit 7a6343d02d by cmc: wiki: architecture and security pages
2026-09-28 04:30 UTC