Explorar o código

docs(ssh): define trusted runtime installation prerequisites

Tianyi Cui hai 4 semanas
pai
achega
7673f90d18

+ 2 - 2
packages/ssh/ssh/README.i18n.yaml

@@ -2,5 +2,5 @@
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
 #   pnpm run verify-translation-pairing --write packages/ssh/ssh/README.md
-README.md: f186ad1103e5b1f898953a545169fef312dd005e
-README.zh.md: 5b1afaf45bdcf089a095cd66f083e4928e3833c1
+README.md: e051b9768a7b095953d414f017328e8cd1124257
+README.zh.md: bceaec1a702e477de0a1bea95a16d1ed9026deff

+ 1 - 1
packages/ssh/ssh/README.md

@@ -31,7 +31,7 @@ Compose this service with [`fs-ssh`](../fs-ssh/README.md), [`subprocess-ssh`](..
 
 Both endpoints require Linux or macOS. The local `ssh` command must support connection multiplexing and Unix-socket forwarding; the server must permit that forwarding. Configure the alias, credentials and known-host entry before startup: the service enables `BatchMode`, requires strict host-key checking, disables agent forwarding and adds no interactive authentication flow.
 
-Install the built helper and its matching runtime dependencies on the remote host. Keep Node, helper and PTC bootstrap artifacts outside a sandbox backend’s replaced temporary tree, such as bwrap’s private `/tmp`; the workspace may still be under `/tmp`. Digest verification detects an unexpected installed artifact, not a malicious SSH host.
+Install the built helper and its matching runtime dependencies on the remote host. Keep Node, helper, bootstrap and their dependencies outside the workspace and writable temporary roots. They must also remain outside a backend’s replaced temporary tree, such as bwrap’s private `/tmp`; the workspace may still be under `/tmp`. Digest verification detects an unexpected installed artifact after helper startup; it does not make writable deployment files safe to execute or authenticate a malicious SSH host.
 
 | Field | Default | Meaning |
 |---|---|---|

+ 1 - 1
packages/ssh/ssh/README.zh.md

@@ -31,7 +31,7 @@ kind: "package-reference"
 
 两端均需运行 Linux 或 macOS。本地 `ssh` 命令必须支持连接复用与 Unix 套接字转发,服务器也必须允许该转发。启动前配置主机别名、凭据与已知主机记录:本服务启用 `BatchMode`、要求严格检查主机密钥、禁用认证代理转发,且不提供交互认证流程。
 
-在远端主机安装已构建的辅助程序及其匹配的运行依赖。Node、辅助程序和 PTC 引导产物必须位于沙箱后端会替换的临时目录树之外,例如 bwrap 的私有 `/tmp`;工作区仍可位于 `/tmp` 下。摘要验证用于发现非预期的已安装产物,不用于防御恶意 SSH 主机。
+在远端主机安装已构建的辅助程序及其匹配的运行依赖。Node、辅助程序、引导程序及其依赖必须位于工作区和可写临时目录之外,也必须位于后端会替换的临时目录树之外,例如 bwrap 的私有 `/tmp`;工作区仍可位于 `/tmp` 下。摘要校验在辅助程序启动后发现非预期的已安装产物;它不能保证可写部署文件的执行安全,也不能认证恶意 SSH 主机。
 
 | 字段 | 默认值 | 含义 |
 |---|---|---|