Skip to content

wolfsshd: document whole-keyword config matching - #1301

Open
ejohnstown wants to merge 1 commit into
wolfSSL:masterfrom
ejohnstown:cleanup-3
Open

ejohnstown wants to merge 1 commit into
wolfSSL:masterfrom
ejohnstown:cleanup-3

Conversation

@ejohnstown

@ejohnstown ejohnstown commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

ParseConfigLine() only accepts a keyword that ends at whitespace or end of line. Document why, and pin both arms in the config unit test.

  • comment at the matching loop: an OpenSSH "HostKeyAlgorithms" line would otherwise match "HostKey" and abort startup
  • test that line on its own, and that a bare keyword still matches

Copilot AI balanced review requested due to automatic review settings October 7, 2026 23:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The new test documentation incorrectly identifies the value produced by the former prefix match.

1 open finding
What changed in this PR

Documents whole-keyword configuration matching and adds regression coverage.

Changes:

  • Explains keyword-boundary matching.
  • Tests HostKeyAlgorithms and bare-keyword behavior.
File Description
apps/​wolfsshd/​configuration.c Documents matching behavior.
apps/​wolfsshd/​test/​test_configuration.c Adds regression scenarios.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread apps/wolfsshd/test/test_configuration.c Outdated

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #1301

Scan targets checked: wolfssh-src, wolfssh-bugs
Coverage: 1 of 2 in-scope changed file(s) opened by the reviewer; not opened: apps/wolfsshd/test/test_configuration.c

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

ParseConfigLine() takes an options[] entry only when the keyword ends
at whitespace or the end of the line. Record what that check defends
against at the loop and pin the two arms it has. Without it an OpenSSH
"HostKeyAlgorithms" line matches "HostKey" and takes "Algorithms" as
the host key file, aborting startup.

- extend the existing prefix-match comment in test_ParseConfigLine()
  rather than open a second one; the synthetic vectors under it already
  cover the whitespace arm
- pin the end-of-line arm on the error code, not just on failure: only
  a matched keyword reaches HandleStrictModes and returns
  WS_BAD_ARGUMENT, so the check holds on every build flavor
- assert the OpenSSH spelling on its own, where the assertion survives
  HostKeyAlgorithms becoming a supported keyword

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #1301

Scan targets checked: none
Unchanged since last review (not re-run): wolfssh-src, wolfssh-bugs

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants