v2.11.0
Minor Changes
-
#229
87817a0Thanks @tufantunc! -sftp-upload's approval prompt and audit record now describe what it does, not only where it does it:sftp:upload --overwrite --bytes=142 --sha256=<32 hex> /etc/crontab.The tool has always replaced an existing file at that path unconditionally, while its sibling
sftp-upload-filerefuses unless you passoverwrite: trueand spells--overwriteinto its own string.sftp-uploadnamed a destination and no effect, and said nothing at all about the bytes — it takes its content as an argument rather than naming a local file — so two different uploads to one path produced one string. One thing for the approver to decide, one entry for an approval grant to key on, one indistinguishable audit record.No behaviour change: the same uploads still succeed and still replace.
If you write your own
[policy].denylist, check it. Patterns are matched against the whole approved string, and that string changed. A rule anchored on the path still works — the path deliberately comes last — but a rule anchored on the whole string, such as^sftp:upload /root/.*$, silently stops matching and the refusal degrades to an approval prompt with no warning. Anchor on the path segment instead. The same applies to a Rego rule matching the fullinput.resource.command. Minor rather than patch for this reason: a denylist that refused yesterday can prompt today.Approval grants are per-process and in-memory, so an upgrade clears them regardless; there is nothing to re-approve that a restart would not have re-asked anyway.
-
#227
0d56e9aThanks @mthamil107! -run-command,read-command,privileged-commandand both session types now sendAI_AGENT=ssh-mcpto the host, so an operator can tell an agent's session from a person's. The variable appears in the session only on a host whosesshd_confighasAcceptEnv AI_AGENT; everywhere else the session is unchanged.The request itself goes to every host regardless, so a host you do not control learns that an agent is driving. The new profile field
announceAgent = falseturns it off per host. Minor rather than patch because of that field: it is new configuration, and a release that adds one is not a fix.