sshd: removing a key closes its connections !480

merged merged by cmc on 2026-09-28 21:48 UTC · krz/gitbay:revoke-closes-connections into main

Discussion

cmc

Removing a key closes its connections.

  • The store announces committed revocations (RemoveSSHKey, RemoveDeployKey, SetUserDisabled on disable, DeleteUser) and answers which key ids are live (LiveSSHKeys).
  • sshd records the key and user on each connection. A revocation cuts every matching connection; a 15 s sweep catches revocations made by another process (gitbayd admin on the host).
  • Every exec and every git transport session re-reads its key: removed, moved to another account, or re-scoped takes effect on the next command. Scope and audit source come from the fresh read.
  • gitutil.Transport takes a cancel channel and kills git's process group; a push killed before pre-receive answers moves no ref.
  • e2e: an OpenSSH ControlMaster holds a receive-pack open mid-pack, the key is removed, the push dies, the master is gone and main has not moved.
  • Threat-Model, Users and Architecture pages; #256 leaves Known-Gaps; CHANGELOG.

Removing the key the current session uses cuts that session after the removal commits. System ssh mode applies the per-exec check but does not cut a running forced-command process.

First MR of the credentials stack (plan docs/plans/2026-09-27-credentials-and-sessions.md).

Closes #256