Skip to content

Enable SSH compression by default with per-host control - #255

Merged
wesm merged 1 commit into
mainfrom
fix/ssh-compression
Sep 17, 2026
Merged

wesm merged 1 commit into
mainfrom
fix/ssh-compression

Conversation

@wesm

@wesm wesm commented Sep 16, 2026 •

Copy link
Copy Markdown
Member
  • Enable SSH compression by default, including for existing hosts, and add an SSH compression toggle in Settings → Hosts. This reduces text traffic on slow connections without editing ~/.ssh/config.
  • Use the same choice for terminal attachments, inventory, commands, and helper installation. Applying a change releases the host's attachments; remote sessions keep running and can be reopened. Keep project-removal safeguards in place across preference changes.
  • Pin the merged helper from kwt #152 and use its v2 execution policy in the Swift app and Rust host. The new Settings control belongs to the Swift app; the Rust host continues to follow OpenSSH configuration.
  • Update the Guide and its Settings screenshot. Compression can reduce output congestion; the patched app still needs a real-workload trial before claiming the reported typing lag is resolved.

Host settings with SSH compression enabled

@wesm
wesm deployed to sandbox-image-promotion-status September 16, 2026 18:23 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 16, 2026 18:23 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 16, 2026 18:23 — with GitHub Actions Active
@roborev-ci

roborev-ci Bot commented Sep 16, 2026

Copy link
Copy Markdown

roborev: Combined Review (590b20c)

Verdict: No findings at or above medium severity.


Reviewers: 2 done | Synthesis: codex | Total: 4m43s

@wesm
wesm deployed to sandbox-image-promotion-status September 16, 2026 21:37 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 16, 2026 21:37 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 16, 2026 21:38 — with GitHub Actions Active
@roborev-ci

roborev-ci Bot commented Sep 16, 2026

Copy link
Copy Markdown

roborev: Combined Review (0281cd1)

Verdict: No findings at or above medium severity.


Reviewers: 2 done | Synthesis: codex | Total: 4m12s

wesm added a commit to kenn-io/kwt that referenced this pull request Sep 16, 2026
- Honor `Compression yes` from the user's SSH configuration when opening managed connections. Previously kwt dropped the option, preventing text-heavy sessions from reducing traffic on slow links. Compression remains opt-in and takes effect on new connections.
- Advertise execution policy `kwt.openssh.projection.v2`; consumers that validate the policy must update with their bundled helper. Retain the deprecated Go constant `SSHProjectionPolicyV1` with its original value so existing imports compile; newly resolved routes still use v2.
- Check both `Compression yes` and `Compression no` by evaluating a temporary configuration with real OpenSSH and replaying kwt's generated arguments. This enables a congestion mitigation; it does not establish that all terminal lag is resolved.
- Companion application update: kenn-io/ghosthub#255. Merge kwt first, then update Ghosthub's pin to the merged revision.


Co-authored-by: Wes McKinney <wesm@users.noreply.github.com>
@wesm
wesm deployed to sandbox-image-promotion-status September 16, 2026 23:54 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 16, 2026 23:54 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 16, 2026 23:54 — with GitHub Actions Active
@wesm wesm changed the title Honor configured SSH compression for remote sessions Enable SSH compression by default with per-host control Sep 16, 2026
@wesm
wesm deployed to sandbox-image-promotion-status September 16, 2026 23:54 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 16, 2026 23:54 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 16, 2026 23:55 — with GitHub Actions Active
@roborev-ci

roborev-ci Bot commented Sep 17, 2026

Copy link
Copy Markdown

roborev: Combined Review (4ec6943)

Verdict: Changes require fixes for 1 finding.

High

  • rust/host/src/ssh.rs:311: The Rust SSH adapter accepts projection v2, but its deny-unknown-fields route model lacks the new compression field. Real v2 snapshots containing top-level compression will be rejected, and the resolver and lease builders cannot forward the selected compression setting. Add compression to the Rust configuration, target, and route models; validate it and pass the explicit yes/no value to both SSH resolve and SSH lease, with matching integration fixtures.

    Reported by: codex


Reviewers: 2 done | Synthesis: codex, 5s | Total: 7m0s

wesm added a commit to kenn-io/kwt that referenced this pull request Sep 17, 2026
- Let applications choose SSH compression without editing the user's SSH configuration. `kwt ssh resolve`, `lease`, `exec`, and `copy` accept `--compression=yes|no`; the Go API accepts an optional `Compression` value. Omitting it preserves OpenSSH configuration.
- Apply overrides only to the destination. Preserve the choice through lease revalidation and include its effective value in connection identity; jump hosts keep their own settings. Isolated tests exercise real OpenSSH with both overrides against opposite configuration values.
- Companion: [Ghosthub #255](kenn-io/ghosthub#255) enables compression by default with a per-host setting. **Merge kwt first, then repin Ghosthub to the merged revision.** Compression can reduce output congestion; real-workload latency still needs a trial.


Co-authored-by: Wes McKinney <wesm@users.noreply.github.com>
@wesm
wesm deployed to sandbox-image-promotion-status September 17, 2026 00:29 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 17, 2026 00:29 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 17, 2026 00:30 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 17, 2026 00:30 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 17, 2026 00:30 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 17, 2026 00:30 — with GitHub Actions Active
@roborev-ci

roborev-ci Bot commented Sep 17, 2026

Copy link
Copy Markdown

roborev: Combined Review (8ee60a1)

Verdict: Changes require fixes for 2 findings.

High

  • rust/host/src/ssh.rs:312: The Rust route parser rejects v2 responses containing the new compression field, and Rust resolve and lease argument builders do not pass the explicit compression choice. Add and validate the v2 compression field, thread it through Rust host configuration, include --compression yes|no in resolve and lease arguments, and add coverage for a v2 response containing the field.

    Reported by: codex

Medium

  • Sources/App/KwtSSHConnectionPool.swift:743: The SSH connection pool route-equivalence check omits compression, so otherwise-identical routes with different compression choices may incorrectly share a connection. Compare compression in sameRoute and add a regression test covering opposite compression settings.

    Reported by: codex


Reviewers: 2 done | Synthesis: codex, 6s | Total: 8m49s

Text-heavy remote sessions can congest a shared SSH connection. Enable
compression by default and let each host opt out in Settings without
requiring changes to the user's OpenSSH configuration. Keep that choice
consistent across attachments and background commands while preserving
project-removal safeguards for the same machine.

- Include browser authentication in the compression helper pin
- Pin the helper that retains the SSH v1 API identifier
- Enable SSH compression from per-host settings
- Pin the merged SSH compression helper

Generated with Codex
Co-authored-by: Codex <noreply@openai.com>
@wesm
wesm force-pushed the fix/ssh-compression branch from 8ee60a1 to 3914634 Compare September 17, 2026 10:07
@wesm
wesm deployed to sandbox-image-promotion-status September 17, 2026 10:07 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 17, 2026 10:07 — with GitHub Actions Active
@wesm
wesm deployed to sandbox-image-promotion-status September 17, 2026 10:07 — with GitHub Actions Active
@roborev-ci

roborev-ci Bot commented Sep 17, 2026

Copy link
Copy Markdown

roborev: Combined Review (3914634)

Verdict: Changes require fixes for 1 finding.

High

  • rust/host/src/ssh.rs:311: The Rust route model uses deny_unknown_fields but has no compression field, so it rejects real KWT v2 resolutions; its resolve and lease argument builders also omit --compression. Propagate a defaulted compression option through Rust configuration, route parsing and validation, and both resolve and lease arguments; update fixtures with the real v2 field or defer the KWT policy/revision bump.

    Reported by: codex


Reviewers: 2 done | Synthesis: codex, 5s | Total: 8m35s

@wesm

wesm commented Sep 17, 2026

Copy link
Copy Markdown
Member Author

invalid

@wesm
wesm merged commit 20a6233 into main Sep 17, 2026
10 checks passed
@wesm
wesm deleted the fix/ssh-compression branch September 17, 2026 11:34

This branch was successfully deployed

1 active deployment
sandbox-image-promotion-status — 39146343 Deployed Sep 17, 2026 by wesm via Reconcile promotion authorization #1633
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant