sshd: close idle connections on shutdown, and do not count a store failure as a bad key !202

merged merged by cmc on 2026-09-04 00:10 UTC · krz/gitbay:drain-idle-conns into main

Discussion

cmc

Both halves of #141, seen deploying v1.9.0.

Idle connections held the drain. A CLI keeps a shared connection open between commands, and Shutdown waited for it like a session in flight, so the restart took the full 30 s. Each connection now counts its running sessions; Shutdown closes the idle ones at once and waits only for sessions mid-command. TestShutdownClosesIdleConnections opens a control master with no session and expects the daemon to exit within seconds of SIGTERM.

A store failure was a bad key. authenticate treated any error from the key lookup as an unknown key: a failure against the limiter and a denial. A busy database during a restart could lock every client out for a minute, which is the likeliest reading of the lockout. A store error other than not-found is now a temporary refusal that counts nothing and is logged.

The CLI hints on exit 255, since ssh's own message cannot tell a bad key from a throttle.

Closes #141